Topic module

Containers and Azure App Service

This topic covers Azure Container Registry, Azure Container Instances, Azure Container Apps, container sizing and scaling, App Service plans, scaling, TLS, custom domains, backup, networking, and deployment slots.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-104

Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.

Core concepts

Concept 1

Containers and Azure App Service questions reward operational Azure administration judgment rather than simple service-name recall.

Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.

Concept 2

The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.

Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.

Concept 3

Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.

Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.

Risk pitfalls and guardrails

Using Azure Policy when the question asks who is allowed to perform an action.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Assuming backup exists before checking vault, policy, retention, and restore validation.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Memory anchors

Container Registry

Azure Container Registry stores and manages container images.

Container Instances

Azure Container Instances runs containers without managing orchestration infrastructure.

Container Apps

Azure Container Apps runs containerized apps with managed scaling and app-focused features.

Container Scaling

Container scaling adjusts replicas or resources to meet demand.

App Service Plan

An App Service plan defines compute resources for App Service apps.

App Service

Azure App Service hosts web apps and APIs on a managed platform.

TLS Certificate

TLS certificates protect custom-domain HTTPS traffic for apps.

Custom Domain

A custom domain maps a friendly DNS name to an App Service app.

Deployment Slot

A deployment slot provides a separate app environment for staged releases.

App Backup

App Service backup protects app content and selected configuration.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

An Azure Container Instances group must pull a private image from Azure Container Registry without storing registry passwords. Which design is best?

A developer can authenticate to an ACR resource but receives authorization denied when pushing an image. Which role should be reviewed?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.