Week 4— Manage Azure Identities and Governance · Implement and Manage Storage · Deploy and Manage Azure Compute · Implement and Manage Virtual Networking · Monitor and Maintain Azure Resources
10 days- Study →
Manage Azure Identities and Governance
Identity and governance is the foundation of AZ-104. The RBAC scope hierarchy and the difference between Azure AD roles and Azure RBAC roles cause the most confusion — get these right before exam day.
📅 Days 27–28🎯 ~38 questions/day⚖ 24% of exam- ✓Azure AD objects: users, groups, service principals, and managed identities.
- ✓RBAC: built-in roles (Owner, Contributor, Reader), custom roles, and scope hierarchy.
- ✓Management groups, subscriptions, resource groups, and how policy inheritance flows down.
- Study →
Implement and Manage Storage
This domain covers Azure storage accounts, Blob, Files, Queue, Table, and Disk storage. The exam tests your ability to choose account types, configure replication and access tiers, secure data with SAS and Azure AD, and manage lifecycle policies. Expect scenario-based questions on CLI, PowerShell, and portal implementations, plus troubleshooting connectivity and performance issues.
📅 Days 27–28🎯 ~39 questions/day⚖ 19% of exam- ✓Configure storage account replication, access tiers, and lifecycle management policies.
- ✓Generate and secure shared access signatures (SAS) with stored access policies.
- ✓Implement Azure Files shares and sync with Azure File Sync.
- Study →
Deploy and Manage Azure Compute
This domain covers provisioning and managing Azure virtual machines, scale sets, containers, and App Service, plus their networking, storage, and availability configuration. The exam tests it through scenario questions where you choose VM sizes, disks, availability options, ARM/Bicep or CLI/PowerShell deployment methods, and diagnose scaling, connectivity, or configuration failures across compute workloads.
📅 Days 27–28🎯 ~31 questions/day⚖ 24% of exam- ✓Selecting VM sizes, disk types, and availability sets versus Availability Zones for SLA and redundancy
- ✓Deploying and configuring VM Scale Sets, including autoscale rules and instance management
- ✓Configuring Azure App Service plans, deployment slots, and container-based web app hosting
- Study →
Implement and Manage Virtual Networking
This domain covers Azure virtual networks, subnets, IP addressing, network security groups, routing, peering, private endpoints, and name resolution. The exam tests these through scenario-based questions requiring you to configure, secure, and troubleshoot connectivity using the portal, CLI, or PowerShell. Expect tasks on NSG rules, UDRs, VNet peering, and Azure DNS.
📅 Days 27–28🎯 ~49 questions/day⚖ 19% of exam- ✓Create and configure VNets, subnets, and IP addressing including service endpoints.
- ✓Configure NSG rules and application security groups to filter traffic.
- ✓Implement VNet peering, user-defined routes, and Azure DNS zones.
- Study →
Monitor and Maintain Azure Resources
This AZ-104 domain covers keeping Azure workloads healthy: Azure Monitor metrics and logs, Log Analytics workspaces, KQL queries, alerts and action groups, Application Insights, Network Watcher, and backup/recovery via Recovery Services vaults. The exam tests these through scenario questions asking you to select the right monitoring tool, alert configuration, diagnostic setting, or recovery action for a stated requirement.
📅 Days 27–28🎯 ~49 questions/day⚖ 14% of exam- ✓Configuring Azure Monitor diagnostic settings to route resource logs to Log Analytics, Storage, or Event Hubs
- ✓Writing KQL queries in Log Analytics to filter, summarize, and aggregate Azure activity and resource logs
- ✓Creating metric and log search alerts with action groups, plus interpreting alert processing rules