Lesson 25 / 25

Azure Revision and Interview Questions

Recall the key Azure services and decisions under exam or interview pressure.

Cheat sheet

Hierarchy: Entra tenant → management groups → subscriptions → resource groups → resources. Identity: Entra ID for authentication, Azure RBAC (principal + role + scope, inherited downward) for authorisation, managed identities instead of secrets. Compute: VMs/scale sets (full control), App Service (web PaaS, slots), Container Apps (serverless containers), AKS (managed Kubernetes), Functions (event-driven). Messaging: Service Bus (commands), Event Grid (discrete events, push), Event Hubs (streams). Data: Blob tiers Hot/Cool/Cold/Archive; LRS/ZRS/GRS/GZRS; Azure SQL, PostgreSQL Flexible, Cosmos DB (partition key, five consistency levels). Network: VNets, NSGs (low number first), non-transitive peering, private endpoints with privatelink DNS, Load Balancer / App Gateway / Front Door / Traffic Manager. Ops: Bicep + what-if, OIDC pipelines, Azure Monitor + KQL, Key Vault, Policy, Defender, budgets.

Common interview questions

Practise answering each in two or three sentences with a trade-off.

1. Resource group vs subscription: what is each boundary for?
2. Owner vs Contributor vs User Access Administrator?
3. System-assigned vs user-assigned managed identity: when each?
4. App Service vs Container Apps vs AKS for a new API?
5. Service Bus vs Event Grid vs Event Hubs, with an example each.
6. LRS vs ZRS vs GZRS: what failure does each survive?
7. How do you choose a Cosmos DB partition key?
8. Private endpoint vs service endpoint; why does DNS matter?
9. Front Door vs Application Gateway?
10. How would you deploy from GitHub to Azure without secrets?

Answer with the decision, then the reason

Interviewers want judgement, not a list of product names. Start with "I would use Container Apps" and follow with the requirement it satisfies and the alternative you rejected.

Quick check: A Contributor on a resource group tries to give a teammate access to it. What happens?

  • It succeeds because Contributor has full access
  • It succeeds only for Reader access
  • It fails because roles cannot be scoped to resource groups
  • It fails because Contributor cannot manage role assignments
Answer

It fails because Contributor cannot manage role assignments — Contributor can manage resources but not access; granting roles needs Owner, User Access Administrator or a role with role-assignment permissions.