Prev Next

Java / Azure Virtual Machines (VMs) Interview questions

Last updated

1. What is an Azure Virtual Machine? 2. What are the main components of an Azure VM? 3. What are the VM size families in Azure? 4. What are the types of disks available for Azure VMs? 5. What is the temporary disk in an Azure VM? 6. What is a managed disk in Azure? 7. What is an Availability Set in Azure? 8. What are Availability Zones in Azure? 9. What is a Virtual Machine Scale Set? 10. How do you create an Azure VM using Azure CLI? 11. What is a Network Security Group in Azure? 12. What are the pricing options for Azure VMs? 13. What are Azure Reserved VM Instances? 14. What are Azure Spot VMs? 15. What is Azure Bastion? 16. What are the IP address types for Azure VMs? 17. How do you connect to Windows and Linux Azure VMs? 18. What are VM extensions in Azure? 19. What is Azure Hybrid Benefit? 20. What are the power states of an Azure VM? 21. What is a managed identity for an Azure VM? 22. What is Azure Backup for VMs? 23. What is the Azure Instance Metadata Service? 24. What is the difference between stopped and deallocated VMs? 25. What is the difference between Availability Sets and Availability Zones? 26. How does disk caching work on Azure VMs? 27. How do you resize an Azure VM? 28. How does autoscaling work in VM Scale Sets? 29. What is the difference between Uniform and Flexible orchestration modes? 30. How does Azure Load Balancer distribute traffic to VMs? 31. What is the difference between generalized and specialized images? 32. How do you use Azure Compute Gallery for VM images? 33. What are proximity placement groups? 34. What happens during Azure planned maintenance on a VM? 35. What happens when an Azure Spot VM is evicted? 36. How does accelerated networking work? 37. What is the difference between server-side encryption and Azure Disk Encryption? 38. What is the difference between Trusted Launch and Confidential VMs? 39. How does Just-In-Time VM access work? 40. How do you patch Azure VMs with Azure Update Manager? 41. How do you monitor Azure VMs? 42. How do cloud-init and custom data work on Azure VMs? 43. How do SLAs differ for single VMs, Availability Sets and Zones? 44. When would you choose VMs over App Service or AKS? 45. When should you use Azure Dedicated Host? 46. How does Azure Site Recovery protect VMs? 47. What is the difference between a disk snapshot and Azure Backup? 48. How do you troubleshoot an Azure VM unreachable over RDP? 49. How can you optimize Azure VM costs? 50. How do you move an Azure VM to another region?

1. What is an Azure Virtual Machine?

An Azure Virtual Machine is an on-demand IaaS compute resource that runs a full Windows or Linux operating system on Microsoft's Hyper-V based infrastructure. You pick the image, size, disks and network settings, and Azure takes care of the physical hardware, the hypervisor and the datacenter.

Because you own everything from the guest OS upward (patching, runtimes, security settings, applications), a VM gives the most control among Azure compute options. The flip side is more operational work than PaaS services such as App Service.

Typical uses are lift-and-shift of existing servers, software with OS-level dependencies, dev/test environments, self-managed databases and high-performance workloads.

Take quiz
Which part of an Azure VM does Microsoft manage for you?
Guest OS patching
Application configuration
Guest firewall rules
The physical hardware and hypervisor
Azure Virtual Machines belong to which cloud service model?
IaaS
PaaS
SaaS
FaaS

2. What are the main components of an Azure VM?

An Azure VM is not one object but a set of linked resources: the VM itself (size, image, OS profile), at least one OS disk, optional data disks, a network interface placed in a subnet, and usually a network security group.

Component Role
VM size Defines vCPUs, memory, max disks and network bandwidth
OS disk Holds the operating system; created from an image
Data disk Persistent storage for applications and data
NIC Connects the VM to a VNet subnet and carries its private IP
Public IP (optional) Gives inbound/outbound internet reachability
NSG (optional) Allows or denies traffic by 5-tuple rules

All of these live in a resource group, and deleting the VM does not automatically delete its disks, NIC or IP unless you set the delete option.

Take quiz
Which resource attaches a VM to a subnet?
Network security group
Network interface (NIC)
Public IP address
Route table
Is a public IP address mandatory for an Azure VM?
Yes, otherwise the VM cannot start
Yes, but only for Linux VMs
No, a VM can run with only a private IP
Yes, only for VMs larger than 4 vCPUs

3. What are the VM size families in Azure?

Azure groups VM sizes into families by workload profile: general purpose, compute optimized, memory optimized, storage optimized, GPU and HPC.

Family Series examples Best for
General purpose B, D, DC Web servers, small databases, dev/test
Compute optimized F Batch processing, gaming servers, CPU-bound apps
Memory optimized E, M In-memory databases, SAP HANA, large caches
Storage optimized L Big data, NoSQL, high disk throughput
GPU N Rendering, ML training and inference
HPC H Simulation, fluid dynamics, tightly coupled MPI

Names follow a pattern. In Standard_D4s_v5, D is the family, 4 is the vCPU count, s means premium storage support and v5 is the hardware generation.

Take quiz
Which family fits an in-memory database such as SAP HANA?
Compute optimized (F series)
Storage optimized (L series)
GPU (N series)
Memory optimized (E/M series)
In the size name Standard_D4s_v5, what does the number 4 represent?
The vCPU count
Memory in GB
Maximum number of data disks
The hardware generation

4. What are the types of disks available for Azure VMs?

Azure managed disks come in five types, ordered here from highest to lowest performance: Ultra Disk, Premium SSD v2, Premium SSD, Standard SSD and Standard HDD.

Disk type Typical use
Ultra Disk Transaction-heavy databases needing the highest IOPS and lowest latency
Premium SSD v2 Production workloads where capacity, IOPS and throughput are tuned separately
Premium SSD Production and performance-sensitive VMs
Standard SSD Web servers, lightly used enterprise apps, dev/test
Standard HDD Backups and infrequently accessed data

Premium and Ultra disks require VM sizes that support premium storage, which is the s in many size names.

Take quiz
Which disk type suits backups and rarely accessed data at the lowest cost?
Ultra Disk
Standard HDD
Premium SSD
Premium SSD v2
Which disk offers the highest IOPS and lowest latency for transaction-heavy databases?
Standard SSD
Standard HDD
Ultra Disk
Premium SSD

5. What is the temporary disk in an Azure VM?

The temporary disk is local storage on the physical host that runs your VM. It is meant for scratch data such as page files, swap and caches, not for anything you cannot afford to lose.

Its contents survive a normal reboot but are wiped when the VM is redeployed, resized to a different host, deallocated and restarted elsewhere, or moved during maintenance. On Windows it appears as D:; on Linux it is usually mounted at /mnt.

Not every size has one. Sizes such as Ddsv5 include a temp disk while Dsv5 does not, so check the size before relying on it. Never put application data or databases on it.

Take quiz
Where is the temporary disk of an Azure VM physically located?
In a storage account in the paired region
On a managed disk replicated three times
In an Azure Files share
On local storage of the host server
On a typical Linux Azure VM, where is the temporary disk mounted?
/mnt
/tmpdisk
/var/azure
/data

6. What is a managed disk in Azure?

A managed disk is a block storage volume whose underlying storage account, placement and replication are handled by Azure. You only choose the type, size and performance tier; you never see or manage a storage account.

Benefits over the older unmanaged disks include simpler scaling, better availability when used with availability sets, support for snapshots and images, Azure RBAC on each disk, and server-side encryption by default.

Managed disks support LRS (three copies in one datacenter) and, for some disk types, ZRS (copies across zones). Geo-redundant options are not offered, so cross-region protection needs Azure Backup or Site Recovery.

Take quiz
What does Azure manage for you when you use managed disks?
The file system inside the guest OS
The underlying storage accounts and their placement
The disk partitioning scheme
The backup schedule
Which redundancy option spreads a managed disk across availability zones?
LRS
GRS
ZRS
RA-GRS

7. What is an Availability Set in Azure?

An Availability Set is a logical grouping that spreads VMs across separate hardware inside one datacenter so a single rack failure or maintenance event does not take down every VM.

It does this with two concepts. Fault domains are groups sharing a power source and network switch (up to 3 in most regions). Update domains are groups rebooted together during planned maintenance (5 by default, up to 20).

Put each tier of an application (for example two web VMs and two database VMs) in its own availability set and front the web tier with a load balancer. The service is free; you pay only for the VMs. It protects against hardware faults, but not against a whole datacenter outage.

Take quiz
What do fault domains in an availability set represent?
Groups of VMs rebooted together during maintenance
Separate Azure regions
Separate subscriptions
Groups of VMs sharing one power source and network switch
What is the maximum number of update domains in an availability set?
20
3
10 per region pair
40

8. What are Availability Zones in Azure?

Availability Zones are physically separate datacenters within one Azure region, each with independent power, cooling and networking. Zone-enabled regions have at least three zones.

You can pin a VM to a specific zone, or deploy several VMs across zones so that the loss of an entire datacenter leaves the others running. Zone-redundant services such as Standard Load Balancer and ZRS disks extend this protection.

Zones sit closer together than regions, so latency between them is low enough for synchronous replication. Cross-zone data transfer may be billed on some services, so check pricing.

Take quiz
What is an Availability Zone?
A logical grouping of VMs on one rack
A physically separate datacenter inside a region with its own power, cooling and networking
A pair of Azure regions
A special subnet type
What is the minimum number of zones in a zone-enabled Azure region?
2
4
3
5

9. What is a Virtual Machine Scale Set?

A Virtual Machine Scale Set (VMSS) lets you create and manage a group of load-balanced VMs from a single definition, with the instance count growing or shrinking automatically based on demand or a schedule.

You define the image, size, networking and extensions once. Azure keeps the instances consistent, replaces unhealthy ones and can spread them across fault domains and zones. A scale set can hold up to 1,000 instances.

Autoscale rules come from Azure Monitor autoscale, for example adding two instances when average CPU stays above 70% for 10 minutes. Scale sets suit stateless web tiers, batch jobs and containerized worker pools.

Take quiz
What is the main purpose of a Virtual Machine Scale Set?
To store VM images
To encrypt OS disks
To peer virtual networks
To run and autoscale a group of load-balanced VMs from one definition
Which service supplies the autoscale rules for scale sets?
Azure Monitor autoscale
Azure Advisor
Azure Policy
Azure Automation runbooks

10. How do you create an Azure VM using Azure CLI?

Create a resource group first, then run az vm create with the image, size and admin credentials. The CLI builds the NIC, VNet, public IP and NSG for you if you do not supply existing ones.

az group create --name rg-demo --location eastus

az vm create \
  --resource-group rg-demo \
  --name vm01 \
  --image Ubuntu2204 \
  --size Standard_B2s \
  --admin-username azureuser \
  --generate-ssh-keys

az vm open-port --resource-group rg-demo --name vm01 --port 80

--generate-ssh-keys creates a key pair under ~/.ssh if none exists, and az vm open-port adds an NSG rule. For Windows, use a Windows image alias and --admin-password instead of SSH keys.

Take quiz
Which parameter makes az vm create generate an SSH key pair for a Linux VM?
--create-key
--generate-ssh-keys
--ssh-auto
--new-keypair
Which command opens TCP port 80 on an existing VM?
az vm allow --port 80
az network open --vm --80
az vm open-port --port 80
az vm firewall add 80

11. What is a Network Security Group in Azure?

A Network Security Group (NSG) is a stateful packet filter that allows or denies inbound and outbound traffic to Azure resources using rules based on source, source port, destination, destination port and protocol.

Rules carry a priority from 100 to 4096; the lowest number is evaluated first and processing stops at the first match. You can attach an NSG to a subnet, a NIC, or both, in which case traffic must pass both.

Default rule Direction Effect
AllowVnetInBound Inbound Allows traffic from within the VNet
AllowAzureLoadBalancerInBound Inbound Allows load balancer health probes
DenyAllInBound Inbound Blocks everything else
AllowInternetOutBound Outbound Allows outbound internet traffic

Take quiz
What priority range can custom NSG rules use?
1 to 1000
0 to 65535
1 to 100
100 to 4096
Which default inbound rule allows traffic between resources in the same VNet?
AllowVnetInBound
AllowInternetInBound
AllowSubnetLocal
DenyAllInBound

12. What are the pricing options for Azure VMs?

Azure bills VM compute per second, and you can lower the rate by committing, using spare capacity or reusing licenses. Disks, public IPs and bandwidth are billed separately.

Option How it saves money
Pay-as-you-go No commitment; full list rate
Reserved Instances 1 or 3 year commitment to a VM size and region
Savings plan for compute Hourly spend commitment that flexes across sizes and regions
Spot VMs Deep discount for interruptible capacity
Hybrid Benefit Bring existing Windows Server or SQL licenses
Dev/Test pricing Reduced rates for non-production subscriptions

Most production estates mix them: reservations for the steady baseline, pay-as-you-go for spikes and Spot for batch work.

Take quiz
Which pricing option gives the deepest discount for interruptible workloads?
Pay-as-you-go
Spot VMs
Reserved Instances
Hybrid Benefit
Which commitment terms are available for Azure reservations?
1 month or 6 months
5 years only
1 year or 3 years
Any term from 1 to 12 months

13. What are Azure Reserved VM Instances?

Reserved VM Instances are a pre-purchase of VM compute capacity for a 1 or 3 year term in exchange for a discount of up to roughly 70% against pay-as-you-go, depending on size, region and term.

The discount applies only to the compute portion of the bill. Storage, networking and, for Windows VMs, the license are billed separately unless covered by Hybrid Benefit. The reservation is matched automatically to running VMs that fit its scope (a subscription, a resource group or shared across a billing scope).

With instance size flexibility, the discount can apply to other sizes in the same size series, so resizing within a series does not waste the reservation. Reservations suit steady workloads that run around the clock; use a savings plan if your sizes and regions change often.

Take quiz
What does a VM reservation discount cover?
Disks and bandwidth as well
Only the OS license
Only storage transactions
The compute portion of the VM cost
What does instance size flexibility allow?
The discount to apply to other sizes in the same series
The discount to apply to any VM family
Only the exact purchased size to be discounted
Applying the discount to Spot VMs only

14. What are Azure Spot VMs?

Spot VMs run on Azure's unused capacity at a steep discount, sometimes up to 90% below pay-as-you-go. The catch is that Azure can take the capacity back, evicting your VM at short notice.

Eviction happens when Azure needs the capacity or when the Spot price exceeds your maximum price. You get roughly 30 seconds of warning through Scheduled Events in the Instance Metadata Service. Spot VMs carry no SLA.

Good fits are fault-tolerant, restartable workloads: batch processing, CI build agents, rendering and dev/test. Avoid them for single-instance production services or databases without replicas.

Take quiz
How much advance notice does Azure give before evicting a Spot VM?
5 minutes
About 30 seconds
2 hours
No notice at all
Which workload suits Spot VMs best?
A single production domain controller
A primary SQL database with no replica
Fault-tolerant batch processing
A customer-facing payment gateway

15. What is Azure Bastion?

Azure Bastion is a managed PaaS service that gives you RDP and SSH access to VMs through the Azure portal (or native client) over TLS on port 443, so the VMs need no public IP and no open management ports.

You deploy it into a dedicated subnet named AzureBastionSubnet (at least /26) in the VNet. Bastion then reaches VMs over their private IPs, and it works with peered VNets too.

Compared with a jump box, there is no VM to patch or harden, and the service is hardened against port scanning. SKUs (Developer, Basic, Standard, Premium) add features such as native client support, file transfer and session recording.

Take quiz
What must the Azure Bastion subnet be named?
BastionSubnet
GatewaySubnet
AzureFirewallSubnet
AzureBastionSubnet
Does a VM need a public IP to be reached through Bastion?
No, Bastion connects over the VM's private IP
Yes, a Standard SKU public IP
Yes, but only for Windows VMs
Yes, plus an open port 3389

16. What are the IP address types for Azure VMs?

An Azure VM can have private and public IP addresses, both attached to its NIC's IP configuration.

Type Allocation Notes
Private IP Dynamic or static Taken from the subnet range; stays with the NIC
Public IP (Standard SKU) Static only Zone-redundant by default; secure by default, needs an NSG to allow traffic
Public IP (Basic SKU) Dynamic or static Retired in September 2025, so use Standard for new work

A dynamic private IP is only released when the NIC is deleted, but setting it to static guarantees the address for things like DNS servers and domain controllers.

Take quiz
Which public IP SKU is always statically allocated?
Basic
Standard
Dynamic
Premium
How do you keep a VM's private IP address fixed?
Attach a public IP
Add an NSG rule
Set the NIC IP configuration to static
Enable accelerated networking

17. How do you connect to Windows and Linux Azure VMs?

Windows VMs are reached with RDP (TCP 3389) and Linux VMs with SSH (TCP 22). Both can be used directly over a public IP, over a private network such as VPN or ExpressRoute, or through Azure Bastion.

Method Needs network path to VM? Typical use
RDP / SSH over IP Yes Day-to-day administration
Azure Bastion Yes, private Secure access without public IP
Run Command No (uses VM agent) Run a script without logging in
Serial Console No Fix broken networking or boot problems

For production, avoid exposing 3389 or 22 to the internet. Use Bastion, Just-In-Time access or a VPN, and prefer SSH keys over passwords on Linux.

Take quiz
What is the default port for RDP?
22
5985
443
3389
Which method helps when the VM's networking is completely broken?
Serial Console
RDP over public IP
SSH with keys
Azure Bastion

18. What are VM extensions in Azure?

VM extensions are small packages that run inside a VM after deployment to configure it, install software or enable monitoring. They are installed and run by the Azure VM Agent.

Common ones are the Custom Script Extension (runs a script from storage or inline), Azure Monitor Agent, the Desired State Configuration extension, Azure Disk Encryption and the antimalware extension.

az vm extension set \
  --resource-group rg-demo --vm-name vm01 \
  --publisher Microsoft.Azure.Extensions --name CustomScript \
  --settings '{"commandToExecute":"apt-get update && apt-get install -y nginx"}'

If the VM Agent is stopped or missing, extensions fail to provision, so check the agent status first when troubleshooting.

Take quiz
What must be running in the VM for extensions to work?
Hyper-V integration tools only
The Azure VM Agent
An Azure Arc agent
A Log Analytics workspace
Which extension runs a script on the VM after deployment?
Diagnostics extension
Antimalware extension
Custom Script Extension
Network Watcher extension

19. What is Azure Hybrid Benefit?

Azure Hybrid Benefit lets you apply existing on-premises licenses to Azure workloads so you pay only the base compute rate instead of a rate that includes the license.

It covers Windows Server and SQL Server licenses that have Software Assurance or a qualifying subscription, and also supports Red Hat and SUSE Linux subscriptions. For Windows Server VMs the saving can reach around 40%, and it stacks with reservations for larger discounts.

You enable it per VM (the license type setting in the portal or --license-type Windows_Server in the CLI). Keep your license records in order, because you are responsible for being compliant.

Take quiz
Hybrid Benefit for Windows Server requires:
A reserved instance purchase
An ExpressRoute circuit
A Spot VM
Eligible licenses with Software Assurance or a qualifying subscription
What does Hybrid Benefit remove from the VM bill?
The Windows license portion of the hourly rate
Disk charges
Bandwidth charges
Support plan fees

20. What are the power states of an Azure VM?

An Azure VM moves through Starting, Running, Stopping, Stopped, Deallocating and Deallocated. The distinction between Stopped and Deallocated matters because only a deallocated VM stops compute billing.

flowchart LR
  A[Starting] --> B[Running]
  B --> C[Stopping]
  C --> D["Stopped - still allocated"]
  B --> E[Deallocating]
  D --> E
  E --> F[Deallocated]
  F --> A
  D --> A

Shutting down from inside the guest OS leaves the VM in Stopped (allocated). Using Stop in the portal, or az vm deallocate, releases the compute resources.

Take quiz
In which state does compute billing stop?
Stopped (allocated)
Deallocated
Stopping
Running
Which state does the portal show after you shut down from inside the guest OS?
Deallocated
Failed
Stopped (allocated)
Hibernated

21. What is a managed identity for an Azure VM?

A managed identity is an identity in Microsoft Entra ID that Azure creates and manages for your VM, so applications on the VM can get tokens to access other Azure resources without any stored credentials.

There are two kinds. A system-assigned identity is tied to one VM and deleted with it. A user-assigned identity is a standalone resource that can be attached to many VMs.

You grant the identity an Azure RBAC role (for example Key Vault Secrets User or Storage Blob Data Reader). Code on the VM then requests a token from the Instance Metadata Service, which removes passwords and connection secrets from config files.

Take quiz
What is the main benefit of a managed identity?
It rotates SSH keys on the OS disk
It replaces NSGs
It gives the VM unlimited subscription access
Apps obtain Entra ID tokens without storing credentials
Which identity type can be shared by several VMs?
User-assigned managed identity
System-assigned managed identity
A guest user account
Local administrator account

22. What is Azure Backup for VMs?

Azure Backup protects Azure VMs by taking scheduled, policy-driven backups of all their disks and storing recovery points in a Recovery Services vault.

On the first run it installs a backup extension. Each job takes a snapshot, which allows fast instant restore from the snapshot tier, and then transfers the data to the vault. Windows VMs get application-consistent backups through VSS; Linux uses pre/post scripts for that.

  • Create new VM from a recovery point
  • Replace existing disks on the original VM
  • Restore disks and build the VM yourself
  • File recovery by mounting the recovery point

Retention is defined in the policy (daily, weekly, monthly, yearly), and vault data can be replicated with GRS for regional protection.

Take quiz
Where are Azure VM backup recovery points stored?
On the temporary disk
In a Recovery Services vault
In a Key Vault
In an Azure Files share in the VM's resource group
Which restore option brings back the disks only so you can build the VM yourself?
Replace existing
File recovery
Restore disks
Instant failover

23. What is the Azure Instance Metadata Service?

The Instance Metadata Service (IMDS) is a REST endpoint available inside every Azure VM at the non-routable address 169.254.169.254. It returns information about the running instance and issues managed identity tokens.

curl -H "Metadata:true" \
  "http://169.254.169.254/metadata/instance?api-version=2021-02-01" 

  • /metadata/instance for VM size, region, zone, network and tags
  • /metadata/identity/oauth2/token for managed identity tokens
  • /metadata/scheduledevents for maintenance and Spot eviction notices

The request must include the Metadata: true header, which helps block simple server-side request forgery. The service is reachable only from within the VM.

Take quiz
What is the IMDS IP address?
10.0.0.1
168.63.129.16
127.0.0.1
169.254.169.254
Which header must IMDS requests include?
Metadata: true
Authorization: Bearer
x-ms-version
X-Azure-IMDS

24. What is the difference between stopped and deallocated VMs?

A stopped VM has been shut down but still holds its hardware allocation, so you keep paying for compute. A deallocated VM has released that hardware, so compute billing stops and only storage is charged.

Aspect Stopped (allocated) Deallocated
How you get there Shutdown from inside the OS, or az vm stop Portal Stop, az vm deallocate
Compute billing Continues Stops
Disks billed Yes Yes
Dynamic public IP Kept May be released (Basic SKU)
Temp disk data Kept Lost
Restart speed Faster, same host May land on a different host

The CLI trap is that az vm stop does not deallocate. Use az vm deallocate if the goal is to save money.

Take quiz
A VM stopped from inside the OS still:
Releases hardware and stops billing
Holds its compute allocation and incurs compute charges
Deletes its OS disk
Loses its private IP
Which CLI command deallocates a VM?
az vm stop
az vm halt
az vm deallocate
az vm suspend

25. What is the difference between Availability Sets and Availability Zones?

Both spread VMs to survive failures, but an Availability Set spreads them across racks inside one datacenter, while Availability Zones spread them across separate datacenters in a region.

Aspect Availability Set Availability Zones
Failure scope covered Rack, server, planned maintenance Whole datacenter outage
Mechanism Fault and update domains Physically separate zones
VM SLA (2+ VMs) 99.95% 99.99%
Extra cost None Possible cross-zone data transfer charges
Availability All regions Only zone-enabled regions

A VM cannot be in both an availability set and a zone. If the region supports zones, choose zones for new designs; use availability sets where zones are unavailable.

Take quiz
Which option protects against the failure of a whole datacenter?
Availability Set
Update domains
Fault domains
Availability Zones
What are the VM SLAs for Availability Sets versus Availability Zones (two or more VMs)?
99.95% and 99.99%
99.99% and 99.95%
99.9% and 99.99%
99.5% and 99.9%

26. How does disk caching work on Azure VMs?

Azure VMs can use host-level caching, where reads (and optionally writes) are served from the host's local memory and SSD before hitting remote storage. Each disk has a host caching setting: None, ReadOnly or ReadWrite.

Mode Default for Best for
ReadWrite OS disks OS volumes; risk of data loss on a crash if the app is not cache-aware
ReadOnly - Read-heavy data such as database data files
None Data disks Write-heavy workloads such as transaction logs

A common SQL Server pattern is ReadOnly on data file disks and None on log disks. Ultra Disks and Premium SSD v2 do not support host caching, because they are already designed for very low latency.

Take quiz
Which caching mode is recommended for SQL Server log disks?
ReadWrite
None
ReadOnly
Write-through
Which disk types do not support host caching?
Premium SSD
Standard SSD
Ultra Disk and Premium SSD v2
Standard HDD OS disks

27. How do you resize an Azure VM?

Resizing changes the VM size to a different vCPU, memory and bandwidth profile. In the portal use Size, or use az vm resize in the CLI. A restart happens as part of the change.

az vm list-vm-resize-options -g rg-demo -n vm01 -o table
az vm deallocate -g rg-demo -n vm01
az vm resize -g rg-demo -n vm01 --size Standard_D4s_v5
az vm start -g rg-demo -n vm01

If the new size is available on the current hardware cluster, Azure just reboots the VM. If not, you must deallocate first so Azure can place it on another cluster, which also wipes the temporary disk.

Check the limits before you resize: the number of data disks, premium storage support, VM generation (Gen1 or Gen2), accelerated networking support and regional quota.

Take quiz
Why might you have to deallocate a VM before resizing?
Resizing deletes the OS disk
The NSG blocks resize operations
Windows licenses must be reactivated
The target size may live on a different hardware cluster
What happens to temp disk data when a resize moves the VM to a new host?
It is lost
It is preserved
It is copied to a data disk
It is backed up to the vault

28. How does autoscaling work in VM Scale Sets?

Autoscale uses Azure Monitor autoscale settings attached to the scale set. A profile defines the minimum, maximum and default instance counts, and rules inside it add or remove instances.

  • Metric-based rules: for example, scale out by 2 when average CPU is above 70% for 10 minutes, scale in by 1 below 30%.
  • Schedule-based profiles: fixed capacity at certain times, such as business hours.
  • Predictive autoscale: uses CPU history to scale out ahead of a recurring load.

A cooldown period after each action prevents flapping, where the set scales out and in repeatedly. Always keep the scale-in threshold well below the scale-out threshold. Scale-in policy (Default, NewestVM, OldestVM) decides which instances are removed first.

Take quiz
What is the purpose of the autoscale cooldown period?
To warm up the disks
To avoid flapping by waiting after a scale action
To speed up VM boot
To reduce licensing cost
Which autoscale approach changes capacity at fixed times without relying on a metric?
A metric-based rule
Predictive autoscale
A schedule-based profile
Manual scale

29. What is the difference between Uniform and Flexible orchestration modes?

In Uniform mode a scale set creates identical instances from one model. In Flexible mode the set orchestrates regular Azure VMs, which can differ in size and configuration, while still giving you scale-out, zone spreading and fault domain control.

Aspect Uniform Flexible
Instance types All identical Can mix sizes and Spot/regular
Instances as resources Scale set internal instances Standard, individually managed VMs
Fault domain spreading Fixed behaviour Configurable (platformFaultDomainCount)
Typical use Stateless large-scale compute, legacy designs Most new workloads, HA across zones

Microsoft recommends Flexible orchestration for new deployments. Keep Uniform for existing designs that rely on features not yet carried over.

Take quiz
Which orchestration mode lets you mix different VM sizes in one scale set?
Uniform
Both equally
Neither
Flexible
Which orchestration mode does Microsoft recommend for new deployments?
Flexible
Uniform
Classic
Single placement

30. How does Azure Load Balancer distribute traffic to VMs?

Azure Load Balancer works at layer 4 (TCP/UDP). By default it uses a five-tuple hash of source IP, source port, destination IP, destination port and protocol to pick a healthy backend VM for each new flow.

flowchart LR
  C[Client] --> F["Frontend IP"]
  F --> R{Load balancing rule}
  R --> V1["VM 1 - healthy"]
  R --> V2["VM 2 - healthy"]
  R -.->|probe failed| V3["VM 3 - removed"]

Health probes (TCP, HTTP or HTTPS) check each VM, and a failed probe takes it out of rotation until it recovers. You can switch to source IP affinity (2-tuple or 3-tuple) if clients need to stick to one VM.

Standard SKU is zone-redundant and secure by default, so you need an NSG that permits the traffic. For layer 7 routing such as URL paths or TLS offload, use Application Gateway instead.

Take quiz
At which OSI layer does Azure Load Balancer operate?
Layer 7
Layer 4
Layer 3 only
Layer 2
What removes a backend VM from the load balancer rotation?
A high CPU alert
An NSG deny rule
A failed health probe
A VM tag change

31. What is the difference between generalized and specialized images?

A generalized image has machine-specific data (hostname, users, SIDs, SSH host keys) stripped out so it can be used to create many unique VMs. A specialized image is an exact copy of a VM, identity included, and is used to clone or restore that machine.

Aspect Generalized Specialized
Preparation Sysprep (Windows) or waagent -deprovision (Linux) None required
First boot Runs provisioning, asks for admin credentials Boots as the original machine
Best for Golden images for many VMs Cloning, backup restore, migration of one server

Generalizing is one-way for the source VM, which becomes unusable afterwards, so take a copy first if you still need it.

Take quiz
Which tool is used to generalize a Windows VM?
dism /cleanup
gpupdate
robocopy
Sysprep
Which image type keeps the original hostname and user accounts?
Specialized
Generalized
Marketplace
Community

Azure Compute Gallery stores, versions and shares VM images. You organize them as a gallery, which holds image definitions (OS type, publisher/offer/SKU, generalized or specialized), which in turn hold image versions.

az sig create -g rg-img --gallery-name myGallery
az sig image-definition create -g rg-img --gallery-name myGallery \
  --gallery-image-definition web-base --publisher Contoso --offer web --sku base \
  --os-type Linux --os-state Generalized
az sig image-version create \
  --resource-group rg-img --gallery-name myGallery \
  --gallery-image-definition web-base --gallery-image-version 1.0.0 \
  --managed-image /subscriptions/<id>/resourceGroups/rg-img/providers/Microsoft.Compute/images/web-img \
  --target-regions eastus westeurope

Image versions can replicate to multiple regions for faster, more reliable deployments, and access is controlled with Azure RBAC. You can also share across subscriptions and tenants. Scale sets and VMs reference a specific version or latest.

33. What are proximity placement groups?

A proximity placement group (PPG) is a logical grouping that asks Azure to place its VMs physically close together, ideally in the same datacenter, to minimize network latency between them.

They help latency-sensitive tiers such as an application server talking to its database in chatty, low-latency patterns, or tightly coupled HPC jobs. PPGs work with standalone VMs, availability sets and scale sets within one region.

The trade-off is flexibility. Tighter placement raises the chance of allocation failures, especially when you add VMs later or use scarce sizes. Deploy all VMs in the group in a single request, start with the most constrained size, and avoid using a PPG together with multi-zone spreading because the two goals conflict.

Take quiz
What is the main goal of a proximity placement group?
Spread VMs across fault domains
Reduce licensing cost
Encrypt traffic between VMs
Minimize latency by placing VMs physically close together
What is a common drawback of proximity placement groups?
Higher chance of allocation failures
Higher network latency
No support for managed disks
A lower VM SLA

34. What happens during Azure planned maintenance on a VM?

Azure regularly updates the host platform. Most updates are memory-preserving: the VM is paused for a few seconds (typically 10 or less) and resumes without a reboot. A smaller set requires a reboot or a move to a new host.

  • Azure notifies you in advance for events that need a reboot or redeployment.
  • VMs in an availability set are updated one update domain at a time, with a 30-minute pause between domains.
  • Scheduled Events in IMDS let the VM see upcoming events and react, for example by draining connections.
  • Maintenance configurations let you control timing on Dedicated Hosts and isolated VM sizes.

Plan for restarts by running at least two instances behind a load balancer, and make sure applications start cleanly after a reboot.

Take quiz
Which feature lets a VM see upcoming maintenance events?
Azure Advisor
Scheduled Events in the Instance Metadata Service
Cost Management
NSG flow logs
How long does a memory-preserving update typically pause a VM?
30 minutes
Several hours
A few seconds (about 10 or less)
It never pauses

35. What happens when an Azure Spot VM is evicted?

Azure sends a Preempt notice through Scheduled Events about 30 seconds ahead, then stops the VM. What happens next depends on the eviction policy you chose at creation.

Policy Result You keep paying for
Deallocate (default) VM is stopped and deallocated; can be restarted when capacity returns Disks
Delete VM and its attached disks are removed Nothing

Eviction is triggered by capacity needs or by the Spot price passing your maximum. Setting the max price to -1 means you will pay up to the regular on-demand price, so you are evicted only for capacity reasons.

Handle it in the app: poll the scheduled events endpoint, checkpoint work and keep jobs restartable.

Take quiz
Which eviction policy keeps the VM's disks after eviction?
Delete
Terminate
Snapshot
Deallocate
What does a Spot max price of -1 mean?
You pay up to the on-demand price and are evicted only for capacity
The VM is free
The VM is evicted immediately
The price is capped at 10% of on-demand

36. How does accelerated networking work?

Accelerated networking uses SR-IOV to give the VM direct access to the physical network card, bypassing the host's virtual switch for most traffic. Packets go straight between the VM and the NIC's virtual function.

The result is lower latency, less jitter and lower CPU use for networking, which matters for high-throughput or chatty workloads. On Linux the VM sees both a synthetic NIC and a Mellanox virtual function that are bonded together.

az network nic create -g rg-demo -n nic01 --vnet-name vnet1 --subnet app \
  --accelerated-networking true

It is supported on most general purpose and compute optimized sizes with at least 2 vCPUs, and on supported OS images. You can enable it on an existing NIC while the VM is deallocated.

Take quiz
Which technology underlies accelerated networking?
NAT gateway
SR-IOV
VXLAN offload only
ExpressRoute FastPath
What is the main benefit of accelerated networking?
Larger OS disks
More vCPUs per VM
Lower latency, jitter and CPU usage for network traffic
Free public IP addresses

37. What is the difference between server-side encryption and Azure Disk Encryption?

Server-side encryption (SSE) encrypts managed disk data at rest in the storage service and is on by default. Azure Disk Encryption (ADE) encrypts volumes inside the guest OS using BitLocker on Windows or DM-Crypt on Linux, with keys held in Key Vault.

Aspect SSE ADE Encryption at host
Where it happens Storage service Inside guest OS On the VM host
Keys Platform or customer-managed Key Vault Platform or customer-managed
Covers temp disk and cache No Temp disk (OS dependent) Yes, end to end
Default Yes No No

For stronger coverage, enable encryption at host, which encrypts temp disks and caches before data leaves the host. Microsoft has announced a retirement plan for ADE, so check current guidance before choosing it for new builds.

Take quiz
Which option encrypts temp disks and caches end to end on the host?
SSE with platform-managed keys
Snapshot encryption
NSG encryption
Encryption at host
Where does Azure Disk Encryption perform the encryption?
Inside the guest OS with BitLocker or DM-Crypt
Only in the storage service
In the hypervisor firmware
On the load balancer

38. What is the difference between Trusted Launch and Confidential VMs?

Trusted Launch protects the VM's boot chain against rootkits and bootkits. Confidential VMs go further and encrypt memory in hardware, protecting data in use from the host, hypervisor and even Azure operators.

Aspect Trusted Launch Confidential VMs
Protects against Boot-level malware and tampering Host-level access to memory and CPU state
Core tech Secure Boot, vTPM, boot integrity monitoring AMD SEV-SNP or Intel TDX hardware encryption, plus attestation
VM generation Gen 2 only Gen 2 only
Sizes Many mainstream sizes Specific families such as DCasv5 and ECasv5

Pick Trusted Launch as a sensible default for Gen 2 VMs and Confidential VMs for regulated data or multiparty computation where even the cloud operator must be excluded.

Take quiz
Which option protects data in use by encrypting memory in hardware?
Trusted Launch
Confidential VMs
Availability Sets
Azure Disk Encryption
Trusted Launch is available for which VM generation?
Generation 1
Either generation
Generation 2
Classic VMs

39. How does Just-In-Time VM access work?

Just-In-Time (JIT) VM access in Microsoft Defender for Cloud keeps management ports (such as 22, 3389, 5985 and 5986) closed by default and opens them only for an approved user, source IP and time window.

  1. JIT adds a deny rule to the NSG (or Azure Firewall) for the chosen ports.
  2. A user requests access, choosing the port, their IP and a duration (up to 24 hours).
  3. If RBAC allows it, Defender adds a temporary allow rule with higher priority.
  4. When the time expires, the allow rule is removed and the port is closed again.

Every request is logged, so you get an audit trail. JIT requires Defender for Servers Plan 2 and the VM must be protected by an NSG or firewall.

Take quiz
Which service provides Just-In-Time VM access?
Azure Policy
Azure Bastion
Azure Monitor
Microsoft Defender for Cloud
How does JIT control access to management ports?
It keeps a deny rule in the NSG and adds temporary allow rules on request
It stops the VM until requested
It deletes the public IP
It only changes the Windows firewall

40. How do you patch Azure VMs with Azure Update Manager?

Azure Update Manager assesses missing updates and installs them on Azure VMs and Azure Arc-enabled servers, on a schedule or on demand, without needing an Automation account.

  1. Enable periodic assessment so it checks for missing patches regularly.
  2. Create a maintenance configuration that defines the schedule, update classifications and any KB inclusions or exclusions.
  3. Assign VMs to the configuration, directly or through dynamic scopes based on tags and locations.
  4. Review compliance and run history in the portal.

The VM patch mode matters too. AutomaticByPlatform lets Azure orchestrate patching with availability-aware safe deployment, ImageDefault uses the OS's own settings and Manual leaves you in control. It replaces the older Automation Update Management solution.

Take quiz
What defines when Update Manager installs patches?
An availability set
A maintenance configuration
A disk encryption set
An action group
Besides Azure VMs, which servers can Update Manager patch?
Only Windows Azure VMs
Only Linux Azure VMs
Azure Arc-enabled servers
Only containers

41. How do you monitor Azure VMs?

Azure gives you host-level metrics out of the box and richer guest-level data once you install the Azure Monitor Agent (AMA).

Layer What you get Needs agent?
Platform metrics CPU %, network, disk operations No
Guest metrics and logs Memory, per-process data, event logs, syslog Yes, AMA with Data Collection Rules
VM insights Performance charts and dependency map Yes, AMA (and dependency agent)
Boot diagnostics Screenshot and serial log No

Memory is not visible from the host, so you need the agent for it. Send data to a Log Analytics workspace, build alert rules on metrics or log queries, and route notifications with action groups. The old Log Analytics (MMA) agent was retired in August 2024, so use AMA.

Take quiz
Which metric is not available from platform metrics without an agent?
CPU percentage
Network in/out
Disk operations
Memory usage
Which agent replaced the legacy Log Analytics (MMA) agent?
Azure Monitor Agent
Dependency agent only
Diagnostics extension
Defender agent

42. How do cloud-init and custom data work on Azure VMs?

Custom data is a blob of up to 64 KB that you pass at VM creation. On Linux images with cloud-init, Azure delivers it and cloud-init runs it during first boot, so you can install packages and write files without logging in.

#cloud-config
package_upgrade: true
packages:
  - nginx
runcmd:
  - systemctl enable --now nginx

az vm create -g rg-demo -n web01 --image Ubuntu2204 \
  --custom-data cloud-init.txt --generate-ssh-keys

It runs only at initial provisioning, not on later reboots. On Windows, custom data is just written to a file and not executed automatically. Do not put secrets in it, since it can be read from within the VM.

Take quiz
What is the maximum size of custom data?
4 KB
64 KB
256 KB
1 MB
When does cloud-init run the supplied configuration?
On every reboot
Every hour
During the first boot provisioning
Only on resize

43. How do SLAs differ for single VMs, Availability Sets and Zones?

The VM SLA depends on how you deploy. A single VM using premium storage for all disks gets 99.9%. Two or more VMs in an availability set get 99.95%, and two or more across zones get 99.99%.

Deployment Monthly uptime SLA
Single VM, Premium SSD or Ultra disks 99.9%
Single VM, Standard SSD 99.5%
Single VM, Standard HDD 95%
2+ VMs in an Availability Set 99.95%
2+ VMs across Availability Zones 99.99%

Spot VMs have no SLA. Note that the SLA covers VM connectivity, not your application, so design the app tier and data layer for the same level.

Take quiz
What is the SLA for a single VM using premium SSD for all disks?
99.95%
99.99%
99.5%
99.9%
Which deployment can reach a 99.99% VM SLA?
Two or more VMs across availability zones
Two VMs in one availability set
A single VM with Premium SSD
A single VM with Standard HDD

44. When would you choose VMs over App Service or AKS?

Choose VMs when you need control of the operating system: custom drivers, installed software, specific kernels, licensing tied to a machine, or lift-and-shift of an app that cannot be changed.

Need VMs App Service AKS
OS-level control Full None Node-level only
Ops effort High (patching, scaling) Low Medium to high
Best fit Legacy and custom workloads Web apps and APIs Many containerized microservices
Scaling Scale sets Built-in Pods and nodes

If the app is a standard web app, App Service removes most operational work. If it is containerized and needs orchestration, AKS fits. Many teams run a mix, with VMs for the legacy parts.

Take quiz
Which option is needed for OS-level custom software installation?
App Service
Virtual Machines
Azure Functions
Logic Apps
Which option is best for orchestrating many containers?
A single VM
App Service Free tier
AKS
Azure Bastion

45. When should you use Azure Dedicated Host?

Use Azure Dedicated Host when you need a physical server used only by your organization, typically for compliance or licensing reasons.

  • Isolation: no other customer's VMs share the hardware.
  • Licensing: bring per-core or per-socket licenses (Windows Server, SQL Server) and use them with visibility of the physical host.
  • Maintenance control: choose when platform updates apply, using maintenance configurations.
  • Placement control: host groups spread hosts across fault domains and zones.

You pay for the entire host regardless of how many VMs run on it, so it only pays off at reasonable utilization. Each host supports one VM series and size family. If you only need isolation without managing hosts, consider isolated VM sizes.

Take quiz
What does Azure Dedicated Host provide?
A discounted shared host
A reserved VM price
Free license keys
A physical server used only by your organization
What are you billed for with Dedicated Host?
The whole host, regardless of how many VMs run
Only the running VMs
Only the OS disks
Only outbound data

46. How does Azure Site Recovery protect VMs?

Azure Site Recovery (ASR) continuously replicates a VM's disks to a target region, so you can fail over to a ready copy if the source region has an outage.

flowchart LR
  A["Source VM in region 1"] -->|Mobility service sends changes| B["Cache storage account"]
  B --> C["Replica disks in region 2"]
  C --> D{Failover}
  D --> E["VM created in region 2"]
  E --> F["Reprotect and failback"]

Changes are tracked and sent through a cache storage account in the source region. Crash-consistent recovery points are created every 5 minutes, and app-consistent points on a schedule you set. A recovery plan orders the failover of multiple VMs and runs scripts.

Use test failover to rehearse in an isolated network without affecting production. After the incident you can reprotect and fail back.

Take quiz
What does ASR replicate?
Only VM tags
VM disk changes continuously to a target region
Only the OS disk nightly
Weekly snapshots
Which ASR feature lets you rehearse DR without affecting production?
Commit
Reprotect
Test failover
Planned failover

47. What is the difference between a disk snapshot and Azure Backup?

A snapshot is a one-time, read-only, point-in-time copy of a single managed disk. Azure Backup is a managed service that automates scheduled, policy-based backups of the whole VM with retention and application consistency.

Aspect Disk snapshot Azure Backup
Scope One disk Whole VM, all disks
Scheduling Manual or scripted Policy-driven
Retention management You delete them Automatic by policy
App-consistent No Yes (VSS on Windows)
Storage location Resource group, same region Recovery Services vault, optional GRS

Snapshots suit a quick rollback before a risky change. For real data protection use Azure Backup, because a snapshot kept in the same region is lost together with the region.

Take quiz
A managed disk snapshot is:
A full VM backup with retention policy
Cross-region replication
A VM image
A point-in-time read-only copy of a single disk
Which option supports scheduled retention and app-consistent backups?
Azure Backup
Disk snapshot
Compute Gallery
Temporary disk

48. How do you troubleshoot an Azure VM unreachable over RDP?

Work from the outside in: confirm the VM is healthy, then the network path, then the guest OS.

  1. Check the VM is Running and review Resource Health and boot diagnostics (screenshot) for a stuck boot.
  2. Confirm the public IP or Bastion path, and that you are connecting to the right address.
  3. Use Network Watcher IP flow verify and Effective security rules to see whether an NSG blocks TCP 3389.
  4. Use Connection troubleshoot to test the path from a source to the VM.
  5. Run Test-NetConnection from another VM and check the guest firewall.
  6. Use Run Command to check the TermService service and RDP registry settings.
  7. Use Reset password / Reset configuration (VMAccess) to repair RDP settings and credentials.
  8. As a last resort, redeploy to a new host, or attach the OS disk to a rescue VM with az vm repair.

Serial Console is the fallback when the network is not working at all.

Take quiz
Which Network Watcher tool checks whether an NSG would allow a specific packet?
Packet capture
IP flow verify
Topology
Traffic Analytics
Which feature can repair RDP settings and reset credentials without network access to the guest?
Load balancer health probes
NSG flow logs
Reset password / Reset configuration (VMAccess)
Azure Advisor

49. How can you optimize Azure VM costs?

Start by removing waste, then right-size, then commit. The order matters, because reserving a VM that should have been smaller locks in the waste.

  1. Right-size using Azure Advisor recommendations and CPU and memory metrics.
  2. Deallocate dev/test VMs when idle, with auto-shutdown schedules (stopped but allocated VMs still bill).
  3. Delete orphans: unattached disks, idle public IPs and old snapshots.
  4. Use Reservations or a savings plan for steady workloads.
  5. Apply Hybrid Benefit for eligible Windows, SQL, Red Hat and SUSE licenses.
  6. Use Spot VMs for fault-tolerant batch jobs.
  7. Choose the right disk tier and consider burstable B-series for light, spiky workloads.
  8. Use autoscale and set budgets, tags and alerts in Cost Management.
Take quiz
Which tool provides VM right-sizing recommendations?
Azure Policy
Network Watcher
Service Health
Azure Advisor
Why deallocate dev VMs overnight?
Compute charges stop, though disks are still billed
All charges stop
The disks are deleted
Licenses are refunded

50. How do you move an Azure VM to another region?

The supported way is Azure Resource Mover, which replicates the VM's disks to the target region and recreates the VM and its dependencies there, with minimal downtime.

flowchart LR
  A["Add resources"] --> B["Validate dependencies"]
  B --> C[Prepare]
  C --> D["Initiate move"]
  D --> E{Commit or discard}
  E --> F["Delete source"]
  1. Add the VM and let Resource Mover include dependencies (VNet, NIC, NSG, public IP, disks).
  2. Validate dependencies and fix any blockers, such as unsupported items or quota.
  3. Prepare to start replicating disks to the target region.
  4. Initiate move to create the VM in the target region.
  5. Commit to finish the move or discard to roll back, then delete source resources if no longer needed.

Public IP addresses change, so update DNS. Check that the target region supports the VM size and that you have quota. You can also use Site Recovery or copy a snapshot and rebuild the VM manually.

Take quiz
Which service orchestrates moving Azure VMs between regions?
Azure Traffic Manager
Azure Resource Mover
Azure Front Door
Azure Advisor
Which step finalizes the move and keeps the target resources?
Prepare
Validate
Commit
Initiate move
«
»

Comments & Discussions