Compute Networking, Backup and Operational Settings
Compute operations questions test App Service networking, certificates, backup, deployment slots, scaling settings, container networking, and VM operational dependencies.
How to study for AZ-104
Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.
Core concepts
Concept 1
Compute Networking, Backup and Operational Settings questions reward operational Azure administration judgment rather than simple service-name recall.
Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.
Concept 2
The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.
Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.
Concept 3
Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.
Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.
Risk pitfalls and guardrails
Using Azure Policy when the question asks who is allowed to perform an action.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Assuming backup exists before checking vault, policy, retention, and restore validation.
Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.
Memory anchors
App Networking
App Service networking settings control inbound, outbound, VNet integration, and private access patterns.
VNet Integration
VNet integration lets an app reach resources in a virtual network.
Private App Access
Private access patterns reduce public exposure for application resources.
Scaling Rule
Scaling rules adjust capacity based on metric, schedule, or demand.
Backup Schedule
A backup schedule defines how often supported app or VM data is protected.
Slot Swap
A slot swap exchanges deployment slots to promote a tested app version.
Container Revision
A container app revision represents an immutable version of app configuration and image.
Managed Identity
Managed identity lets compute resources access Azure services without stored credentials.
Certificate Binding
Certificate binding attaches a TLS certificate to an application endpoint.
Operational Dependency
Operational dependencies include identity, networking, storage, certificates, and monitoring.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A partner firewall allowlists an App Service app's current outbound addresses. The app is moved to another plan and connections fail. What should have been considered?
An App Service app needs one predictable public source IP for outbound internet calls. Which design should be evaluated?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
