Java / Azure Virtual Machines (VMs) Interview questions
Last updated
1. What is an Azure Virtual Machine?
An Azure Virtual Machine is an on-demand IaaS compute resource that runs a full Windows or Linux operating system on Microsoft's Hyper-V based infrastructure. You pick the image, size, disks and network settings, and Azure takes care of the physical hardware, the hypervisor and the datacenter.
Because you own everything from the guest OS upward (patching, runtimes, security settings, applications), a VM gives the most control among Azure compute options. The flip side is more operational work than PaaS services such as App Service.
Typical uses are lift-and-shift of existing servers, software with OS-level dependencies, dev/test environments, self-managed databases and high-performance workloads.
Take quiz
Guest OS patching
Application configuration
Guest firewall rules
The physical hardware and hypervisor
IaaS
PaaS
SaaS
FaaS
2. What are the main components of an Azure VM?
An Azure VM is not one object but a set of linked resources: the VM itself (size, image, OS profile), at least one OS disk, optional data disks, a network interface placed in a subnet, and usually a network security group.
| Component | Role |
| VM size | Defines vCPUs, memory, max disks and network bandwidth |
| OS disk | Holds the operating system; created from an image |
| Data disk | Persistent storage for applications and data |
| NIC | Connects the VM to a VNet subnet and carries its private IP |
| Public IP (optional) | Gives inbound/outbound internet reachability |
| NSG (optional) | Allows or denies traffic by 5-tuple rules |
All of these live in a resource group, and deleting the VM does not automatically delete its disks, NIC or IP unless you set the delete option.
Take quiz
Network security group
Network interface (NIC)
Public IP address
Route table
Yes, otherwise the VM cannot start
Yes, but only for Linux VMs
No, a VM can run with only a private IP
Yes, only for VMs larger than 4 vCPUs
3. What are the VM size families in Azure?
Azure groups VM sizes into families by workload profile: general purpose, compute optimized, memory optimized, storage optimized, GPU and HPC.
| Family | Series examples | Best for |
| General purpose | B, D, DC | Web servers, small databases, dev/test |
| Compute optimized | F | Batch processing, gaming servers, CPU-bound apps |
| Memory optimized | E, M | In-memory databases, SAP HANA, large caches |
| Storage optimized | L | Big data, NoSQL, high disk throughput |
| GPU | N | Rendering, ML training and inference |
| HPC | H | Simulation, fluid dynamics, tightly coupled MPI |
Names follow a pattern. In Standard_D4s_v5, D is the family, 4 is the vCPU count, s means premium storage support and v5 is the hardware generation.
Take quiz
Compute optimized (F series)
Storage optimized (L series)
GPU (N series)
Memory optimized (E/M series)
The vCPU count
Memory in GB
Maximum number of data disks
The hardware generation
4. What are the types of disks available for Azure VMs?
Azure managed disks come in five types, ordered here from highest to lowest performance: Ultra Disk, Premium SSD v2, Premium SSD, Standard SSD and Standard HDD.
| Disk type | Typical use |
| Ultra Disk | Transaction-heavy databases needing the highest IOPS and lowest latency |
| Premium SSD v2 | Production workloads where capacity, IOPS and throughput are tuned separately |
| Premium SSD | Production and performance-sensitive VMs |
| Standard SSD | Web servers, lightly used enterprise apps, dev/test |
| Standard HDD | Backups and infrequently accessed data |
Premium and Ultra disks require VM sizes that support premium storage, which is the s in many size names.
Take quiz
Ultra Disk
Standard HDD
Premium SSD
Premium SSD v2
Standard SSD
Standard HDD
Ultra Disk
Premium SSD
5. What is the temporary disk in an Azure VM?
The temporary disk is local storage on the physical host that runs your VM. It is meant for scratch data such as page files, swap and caches, not for anything you cannot afford to lose.
Its contents survive a normal reboot but are wiped when the VM is redeployed, resized to a different host, deallocated and restarted elsewhere, or moved during maintenance. On Windows it appears as D:; on Linux it is usually mounted at /mnt.
Not every size has one. Sizes such as Ddsv5 include a temp disk while Dsv5 does not, so check the size before relying on it. Never put application data or databases on it.
Take quiz
In a storage account in the paired region
On a managed disk replicated three times
In an Azure Files share
On local storage of the host server
/mnt
/tmpdisk
/var/azure
/data
6. What is a managed disk in Azure?
A managed disk is a block storage volume whose underlying storage account, placement and replication are handled by Azure. You only choose the type, size and performance tier; you never see or manage a storage account.
Benefits over the older unmanaged disks include simpler scaling, better availability when used with availability sets, support for snapshots and images, Azure RBAC on each disk, and server-side encryption by default.
Managed disks support LRS (three copies in one datacenter) and, for some disk types, ZRS (copies across zones). Geo-redundant options are not offered, so cross-region protection needs Azure Backup or Site Recovery.
Take quiz
The file system inside the guest OS
The underlying storage accounts and their placement
The disk partitioning scheme
The backup schedule
LRS
GRS
ZRS
RA-GRS
7. What is an Availability Set in Azure?
An Availability Set is a logical grouping that spreads VMs across separate hardware inside one datacenter so a single rack failure or maintenance event does not take down every VM.
It does this with two concepts. Fault domains are groups sharing a power source and network switch (up to 3 in most regions). Update domains are groups rebooted together during planned maintenance (5 by default, up to 20).
Put each tier of an application (for example two web VMs and two database VMs) in its own availability set and front the web tier with a load balancer. The service is free; you pay only for the VMs. It protects against hardware faults, but not against a whole datacenter outage.
Take quiz
Groups of VMs rebooted together during maintenance
Separate Azure regions
Separate subscriptions
Groups of VMs sharing one power source and network switch
20
3
10 per region pair
40
8. What are Availability Zones in Azure?
Availability Zones are physically separate datacenters within one Azure region, each with independent power, cooling and networking. Zone-enabled regions have at least three zones.
You can pin a VM to a specific zone, or deploy several VMs across zones so that the loss of an entire datacenter leaves the others running. Zone-redundant services such as Standard Load Balancer and ZRS disks extend this protection.
Zones sit closer together than regions, so latency between them is low enough for synchronous replication. Cross-zone data transfer may be billed on some services, so check pricing.
Take quiz
A logical grouping of VMs on one rack
A physically separate datacenter inside a region with its own power, cooling and networking
A pair of Azure regions
A special subnet type
2
4
3
5
9. What is a Virtual Machine Scale Set?
A Virtual Machine Scale Set (VMSS) lets you create and manage a group of load-balanced VMs from a single definition, with the instance count growing or shrinking automatically based on demand or a schedule.
You define the image, size, networking and extensions once. Azure keeps the instances consistent, replaces unhealthy ones and can spread them across fault domains and zones. A scale set can hold up to 1,000 instances.
Autoscale rules come from Azure Monitor autoscale, for example adding two instances when average CPU stays above 70% for 10 minutes. Scale sets suit stateless web tiers, batch jobs and containerized worker pools.
Take quiz
To store VM images
To encrypt OS disks
To peer virtual networks
To run and autoscale a group of load-balanced VMs from one definition
Azure Monitor autoscale
Azure Advisor
Azure Policy
Azure Automation runbooks
10. How do you create an Azure VM using Azure CLI?
Create a resource group first, then run az vm create with the image, size and admin credentials. The CLI builds the NIC, VNet, public IP and NSG for you if you do not supply existing ones.
az group create --name rg-demo --location eastus az vm create \ --resource-group rg-demo \ --name vm01 \ --image Ubuntu2204 \ --size Standard_B2s \ --admin-username azureuser \ --generate-ssh-keys az vm open-port --resource-group rg-demo --name vm01 --port 80
--generate-ssh-keys creates a key pair under ~/.ssh if none exists, and az vm open-port adds an NSG rule. For Windows, use a Windows image alias and --admin-password instead of SSH keys.
Take quiz
--create-key
--generate-ssh-keys
--ssh-auto
--new-keypair
az vm allow --port 80
az network open --vm --80
az vm open-port --port 80
az vm firewall add 80
11. What is a Network Security Group in Azure?
A Network Security Group (NSG) is a stateful packet filter that allows or denies inbound and outbound traffic to Azure resources using rules based on source, source port, destination, destination port and protocol.
Rules carry a priority from 100 to 4096; the lowest number is evaluated first and processing stops at the first match. You can attach an NSG to a subnet, a NIC, or both, in which case traffic must pass both.
| Default rule | Direction | Effect |
| AllowVnetInBound | Inbound | Allows traffic from within the VNet |
| AllowAzureLoadBalancerInBound | Inbound | Allows load balancer health probes |
| DenyAllInBound | Inbound | Blocks everything else |
| AllowInternetOutBound | Outbound | Allows outbound internet traffic |
Take quiz
1 to 1000
0 to 65535
1 to 100
100 to 4096
AllowVnetInBound
AllowInternetInBound
AllowSubnetLocal
DenyAllInBound
12. What are the pricing options for Azure VMs?
Azure bills VM compute per second, and you can lower the rate by committing, using spare capacity or reusing licenses. Disks, public IPs and bandwidth are billed separately.
| Option | How it saves money |
| Pay-as-you-go | No commitment; full list rate |
| Reserved Instances | 1 or 3 year commitment to a VM size and region |
| Savings plan for compute | Hourly spend commitment that flexes across sizes and regions |
| Spot VMs | Deep discount for interruptible capacity |
| Hybrid Benefit | Bring existing Windows Server or SQL licenses |
| Dev/Test pricing | Reduced rates for non-production subscriptions |
Most production estates mix them: reservations for the steady baseline, pay-as-you-go for spikes and Spot for batch work.
Take quiz
Pay-as-you-go
Spot VMs
Reserved Instances
Hybrid Benefit
1 month or 6 months
5 years only
1 year or 3 years
Any term from 1 to 12 months
13. What are Azure Reserved VM Instances?
Reserved VM Instances are a pre-purchase of VM compute capacity for a 1 or 3 year term in exchange for a discount of up to roughly 70% against pay-as-you-go, depending on size, region and term.
The discount applies only to the compute portion of the bill. Storage, networking and, for Windows VMs, the license are billed separately unless covered by Hybrid Benefit. The reservation is matched automatically to running VMs that fit its scope (a subscription, a resource group or shared across a billing scope).
With instance size flexibility, the discount can apply to other sizes in the same size series, so resizing within a series does not waste the reservation. Reservations suit steady workloads that run around the clock; use a savings plan if your sizes and regions change often.
Take quiz
Disks and bandwidth as well
Only the OS license
Only storage transactions
The compute portion of the VM cost
The discount to apply to other sizes in the same series
The discount to apply to any VM family
Only the exact purchased size to be discounted
Applying the discount to Spot VMs only
14. What are Azure Spot VMs?
Spot VMs run on Azure's unused capacity at a steep discount, sometimes up to 90% below pay-as-you-go. The catch is that Azure can take the capacity back, evicting your VM at short notice.
Eviction happens when Azure needs the capacity or when the Spot price exceeds your maximum price. You get roughly 30 seconds of warning through Scheduled Events in the Instance Metadata Service. Spot VMs carry no SLA.
Good fits are fault-tolerant, restartable workloads: batch processing, CI build agents, rendering and dev/test. Avoid them for single-instance production services or databases without replicas.
Take quiz
5 minutes
About 30 seconds
2 hours
No notice at all
A single production domain controller
A primary SQL database with no replica
Fault-tolerant batch processing
A customer-facing payment gateway
15. What is Azure Bastion?
Azure Bastion is a managed PaaS service that gives you RDP and SSH access to VMs through the Azure portal (or native client) over TLS on port 443, so the VMs need no public IP and no open management ports.
You deploy it into a dedicated subnet named AzureBastionSubnet (at least /26) in the VNet. Bastion then reaches VMs over their private IPs, and it works with peered VNets too.
Compared with a jump box, there is no VM to patch or harden, and the service is hardened against port scanning. SKUs (Developer, Basic, Standard, Premium) add features such as native client support, file transfer and session recording.
Take quiz
BastionSubnet
GatewaySubnet
AzureFirewallSubnet
AzureBastionSubnet
No, Bastion connects over the VM's private IP
Yes, a Standard SKU public IP
Yes, but only for Windows VMs
Yes, plus an open port 3389
16. What are the IP address types for Azure VMs?
An Azure VM can have private and public IP addresses, both attached to its NIC's IP configuration.
| Type | Allocation | Notes |
| Private IP | Dynamic or static | Taken from the subnet range; stays with the NIC |
| Public IP (Standard SKU) | Static only | Zone-redundant by default; secure by default, needs an NSG to allow traffic |
| Public IP (Basic SKU) | Dynamic or static | Retired in September 2025, so use Standard for new work |
A dynamic private IP is only released when the NIC is deleted, but setting it to static guarantees the address for things like DNS servers and domain controllers.
Take quiz
Basic
Standard
Dynamic
Premium
Attach a public IP
Add an NSG rule
Set the NIC IP configuration to static
Enable accelerated networking
17. How do you connect to Windows and Linux Azure VMs?
Windows VMs are reached with RDP (TCP 3389) and Linux VMs with SSH (TCP 22). Both can be used directly over a public IP, over a private network such as VPN or ExpressRoute, or through Azure Bastion.
| Method | Needs network path to VM? | Typical use |
| RDP / SSH over IP | Yes | Day-to-day administration |
| Azure Bastion | Yes, private | Secure access without public IP |
| Run Command | No (uses VM agent) | Run a script without logging in |
| Serial Console | No | Fix broken networking or boot problems |
For production, avoid exposing 3389 or 22 to the internet. Use Bastion, Just-In-Time access or a VPN, and prefer SSH keys over passwords on Linux.
Take quiz
22
5985
443
3389
Serial Console
RDP over public IP
SSH with keys
Azure Bastion
18. What are VM extensions in Azure?
VM extensions are small packages that run inside a VM after deployment to configure it, install software or enable monitoring. They are installed and run by the Azure VM Agent.
Common ones are the Custom Script Extension (runs a script from storage or inline), Azure Monitor Agent, the Desired State Configuration extension, Azure Disk Encryption and the antimalware extension.
az vm extension set \ --resource-group rg-demo --vm-name vm01 \ --publisher Microsoft.Azure.Extensions --name CustomScript \ --settings '{"commandToExecute":"apt-get update && apt-get install -y nginx"}'
If the VM Agent is stopped or missing, extensions fail to provision, so check the agent status first when troubleshooting.
Take quiz
Hyper-V integration tools only
The Azure VM Agent
An Azure Arc agent
A Log Analytics workspace
Diagnostics extension
Antimalware extension
Custom Script Extension
Network Watcher extension
19. What is Azure Hybrid Benefit?
Azure Hybrid Benefit lets you apply existing on-premises licenses to Azure workloads so you pay only the base compute rate instead of a rate that includes the license.
It covers Windows Server and SQL Server licenses that have Software Assurance or a qualifying subscription, and also supports Red Hat and SUSE Linux subscriptions. For Windows Server VMs the saving can reach around 40%, and it stacks with reservations for larger discounts.
You enable it per VM (the license type setting in the portal or --license-type Windows_Server in the CLI). Keep your license records in order, because you are responsible for being compliant.
Take quiz
A reserved instance purchase
An ExpressRoute circuit
A Spot VM
Eligible licenses with Software Assurance or a qualifying subscription
The Windows license portion of the hourly rate
Disk charges
Bandwidth charges
Support plan fees
20. What are the power states of an Azure VM?
An Azure VM moves through Starting, Running, Stopping, Stopped, Deallocating and Deallocated. The distinction between Stopped and Deallocated matters because only a deallocated VM stops compute billing.
flowchart LR A[Starting] --> B[Running] B --> C[Stopping] C --> D["Stopped - still allocated"] B --> E[Deallocating] D --> E E --> F[Deallocated] F --> A D --> A
Shutting down from inside the guest OS leaves the VM in Stopped (allocated). Using Stop in the portal, or az vm deallocate, releases the compute resources.
Take quiz
Stopped (allocated)
Deallocated
Stopping
Running
Deallocated
Failed
Stopped (allocated)
Hibernated
21. What is a managed identity for an Azure VM?
A managed identity is an identity in Microsoft Entra ID that Azure creates and manages for your VM, so applications on the VM can get tokens to access other Azure resources without any stored credentials.
There are two kinds. A system-assigned identity is tied to one VM and deleted with it. A user-assigned identity is a standalone resource that can be attached to many VMs.
You grant the identity an Azure RBAC role (for example Key Vault Secrets User or Storage Blob Data Reader). Code on the VM then requests a token from the Instance Metadata Service, which removes passwords and connection secrets from config files.
Take quiz
It rotates SSH keys on the OS disk
It replaces NSGs
It gives the VM unlimited subscription access
Apps obtain Entra ID tokens without storing credentials
User-assigned managed identity
System-assigned managed identity
A guest user account
Local administrator account
22. What is Azure Backup for VMs?
Azure Backup protects Azure VMs by taking scheduled, policy-driven backups of all their disks and storing recovery points in a Recovery Services vault.
On the first run it installs a backup extension. Each job takes a snapshot, which allows fast instant restore from the snapshot tier, and then transfers the data to the vault. Windows VMs get application-consistent backups through VSS; Linux uses pre/post scripts for that.
- Create new VM from a recovery point
- Replace existing disks on the original VM
- Restore disks and build the VM yourself
- File recovery by mounting the recovery point
Retention is defined in the policy (daily, weekly, monthly, yearly), and vault data can be replicated with GRS for regional protection.
Take quiz
On the temporary disk
In a Recovery Services vault
In a Key Vault
In an Azure Files share in the VM's resource group
Replace existing
File recovery
Restore disks
Instant failover
23. What is the Azure Instance Metadata Service?
The Instance Metadata Service (IMDS) is a REST endpoint available inside every Azure VM at the non-routable address 169.254.169.254. It returns information about the running instance and issues managed identity tokens.
curl -H "Metadata:true" \ "http://169.254.169.254/metadata/instance?api-version=2021-02-01"
/metadata/instancefor VM size, region, zone, network and tags/metadata/identity/oauth2/tokenfor managed identity tokens/metadata/scheduledeventsfor maintenance and Spot eviction notices
The request must include the Metadata: true header, which helps block simple server-side request forgery. The service is reachable only from within the VM.
Take quiz
10.0.0.1
168.63.129.16
127.0.0.1
169.254.169.254
Metadata: true
Authorization: Bearer
x-ms-version
X-Azure-IMDS
24. What is the difference between stopped and deallocated VMs?
A stopped VM has been shut down but still holds its hardware allocation, so you keep paying for compute. A deallocated VM has released that hardware, so compute billing stops and only storage is charged.
| Aspect | Stopped (allocated) | Deallocated |
| How you get there | Shutdown from inside the OS, or az vm stop |
Portal Stop, az vm deallocate |
| Compute billing | Continues | Stops |
| Disks billed | Yes | Yes |
| Dynamic public IP | Kept | May be released (Basic SKU) |
| Temp disk data | Kept | Lost |
| Restart speed | Faster, same host | May land on a different host |
The CLI trap is that az vm stop does not deallocate. Use az vm deallocate if the goal is to save money.
Take quiz
Releases hardware and stops billing
Holds its compute allocation and incurs compute charges
Deletes its OS disk
Loses its private IP
az vm stop
az vm halt
az vm deallocate
az vm suspend
25. What is the difference between Availability Sets and Availability Zones?
Both spread VMs to survive failures, but an Availability Set spreads them across racks inside one datacenter, while Availability Zones spread them across separate datacenters in a region.
| Aspect | Availability Set | Availability Zones |
| Failure scope covered | Rack, server, planned maintenance | Whole datacenter outage |
| Mechanism | Fault and update domains | Physically separate zones |
| VM SLA (2+ VMs) | 99.95% | 99.99% |
| Extra cost | None | Possible cross-zone data transfer charges |
| Availability | All regions | Only zone-enabled regions |
A VM cannot be in both an availability set and a zone. If the region supports zones, choose zones for new designs; use availability sets where zones are unavailable.
Take quiz
Availability Set
Update domains
Fault domains
Availability Zones
99.95% and 99.99%
99.99% and 99.95%
99.9% and 99.99%
99.5% and 99.9%
26. How does disk caching work on Azure VMs?
Azure VMs can use host-level caching, where reads (and optionally writes) are served from the host's local memory and SSD before hitting remote storage. Each disk has a host caching setting: None, ReadOnly or ReadWrite.
| Mode | Default for | Best for |
| ReadWrite | OS disks | OS volumes; risk of data loss on a crash if the app is not cache-aware |
| ReadOnly | - | Read-heavy data such as database data files |
| None | Data disks | Write-heavy workloads such as transaction logs |
A common SQL Server pattern is ReadOnly on data file disks and None on log disks. Ultra Disks and Premium SSD v2 do not support host caching, because they are already designed for very low latency.
Take quiz
ReadWrite
None
ReadOnly
Write-through
Premium SSD
Standard SSD
Ultra Disk and Premium SSD v2
Standard HDD OS disks
27. How do you resize an Azure VM?
Resizing changes the VM size to a different vCPU, memory and bandwidth profile. In the portal use Size, or use az vm resize in the CLI. A restart happens as part of the change.
az vm list-vm-resize-options -g rg-demo -n vm01 -o table az vm deallocate -g rg-demo -n vm01 az vm resize -g rg-demo -n vm01 --size Standard_D4s_v5 az vm start -g rg-demo -n vm01
If the new size is available on the current hardware cluster, Azure just reboots the VM. If not, you must deallocate first so Azure can place it on another cluster, which also wipes the temporary disk.
Check the limits before you resize: the number of data disks, premium storage support, VM generation (Gen1 or Gen2), accelerated networking support and regional quota.
Take quiz
Resizing deletes the OS disk
The NSG blocks resize operations
Windows licenses must be reactivated
The target size may live on a different hardware cluster
It is lost
It is preserved
It is copied to a data disk
It is backed up to the vault
28. How does autoscaling work in VM Scale Sets?
Autoscale uses Azure Monitor autoscale settings attached to the scale set. A profile defines the minimum, maximum and default instance counts, and rules inside it add or remove instances.
- Metric-based rules: for example, scale out by 2 when average CPU is above 70% for 10 minutes, scale in by 1 below 30%.
- Schedule-based profiles: fixed capacity at certain times, such as business hours.
- Predictive autoscale: uses CPU history to scale out ahead of a recurring load.
A cooldown period after each action prevents flapping, where the set scales out and in repeatedly. Always keep the scale-in threshold well below the scale-out threshold. Scale-in policy (Default, NewestVM, OldestVM) decides which instances are removed first.
Take quiz
To warm up the disks
To avoid flapping by waiting after a scale action
To speed up VM boot
To reduce licensing cost
A metric-based rule
Predictive autoscale
A schedule-based profile
Manual scale
29. What is the difference between Uniform and Flexible orchestration modes?
In Uniform mode a scale set creates identical instances from one model. In Flexible mode the set orchestrates regular Azure VMs, which can differ in size and configuration, while still giving you scale-out, zone spreading and fault domain control.
| Aspect | Uniform | Flexible |
| Instance types | All identical | Can mix sizes and Spot/regular |
| Instances as resources | Scale set internal instances | Standard, individually managed VMs |
| Fault domain spreading | Fixed behaviour | Configurable (platformFaultDomainCount) |
| Typical use | Stateless large-scale compute, legacy designs | Most new workloads, HA across zones |
Microsoft recommends Flexible orchestration for new deployments. Keep Uniform for existing designs that rely on features not yet carried over.
Take quiz
Uniform
Both equally
Neither
Flexible
Flexible
Uniform
Classic
Single placement
30. How does Azure Load Balancer distribute traffic to VMs?
Azure Load Balancer works at layer 4 (TCP/UDP). By default it uses a five-tuple hash of source IP, source port, destination IP, destination port and protocol to pick a healthy backend VM for each new flow.
flowchart LR
C[Client] --> F["Frontend IP"]
F --> R{Load balancing rule}
R --> V1["VM 1 - healthy"]
R --> V2["VM 2 - healthy"]
R -.->|probe failed| V3["VM 3 - removed"]
Health probes (TCP, HTTP or HTTPS) check each VM, and a failed probe takes it out of rotation until it recovers. You can switch to source IP affinity (2-tuple or 3-tuple) if clients need to stick to one VM.
Standard SKU is zone-redundant and secure by default, so you need an NSG that permits the traffic. For layer 7 routing such as URL paths or TLS offload, use Application Gateway instead.
Take quiz
Layer 7
Layer 4
Layer 3 only
Layer 2
A high CPU alert
An NSG deny rule
A failed health probe
A VM tag change
31. What is the difference between generalized and specialized images?
A generalized image has machine-specific data (hostname, users, SIDs, SSH host keys) stripped out so it can be used to create many unique VMs. A specialized image is an exact copy of a VM, identity included, and is used to clone or restore that machine.
| Aspect | Generalized | Specialized |
| Preparation | Sysprep (Windows) or waagent -deprovision (Linux) |
None required |
| First boot | Runs provisioning, asks for admin credentials | Boots as the original machine |
| Best for | Golden images for many VMs | Cloning, backup restore, migration of one server |
Generalizing is one-way for the source VM, which becomes unusable afterwards, so take a copy first if you still need it.
Take quiz
dism /cleanup
gpupdate
robocopy
Sysprep
Specialized
Generalized
Marketplace
Community
32. How do you use Azure Compute Gallery for VM images?
Azure Compute Gallery stores, versions and shares VM images. You organize them as a gallery, which holds image definitions (OS type, publisher/offer/SKU, generalized or specialized), which in turn hold image versions.
az sig create -g rg-img --gallery-name myGallery az sig image-definition create -g rg-img --gallery-name myGallery \ --gallery-image-definition web-base --publisher Contoso --offer web --sku base \ --os-type Linux --os-state Generalized az sig image-version create \ --resource-group rg-img --gallery-name myGallery \ --gallery-image-definition web-base --gallery-image-version 1.0.0 \ --managed-image /subscriptions/<id>/resourceGroups/rg-img/providers/Microsoft.Compute/images/web-img \ --target-regions eastus westeurope
Image versions can replicate to multiple regions for faster, more reliable deployments, and access is controlled with Azure RBAC. You can also share across subscriptions and tenants. Scale sets and VMs reference a specific version or latest.
Take quiz
Image version, gallery, image definition
Gallery, image definition, image version
Image definition, image version, gallery
Gallery, image version, image definition
The regions where it replicates
The disk snapshots it contains
OS type, state and publisher/offer/SKU metadata
The NSG rules it applies
33. What are proximity placement groups?
A proximity placement group (PPG) is a logical grouping that asks Azure to place its VMs physically close together, ideally in the same datacenter, to minimize network latency between them.
They help latency-sensitive tiers such as an application server talking to its database in chatty, low-latency patterns, or tightly coupled HPC jobs. PPGs work with standalone VMs, availability sets and scale sets within one region.
The trade-off is flexibility. Tighter placement raises the chance of allocation failures, especially when you add VMs later or use scarce sizes. Deploy all VMs in the group in a single request, start with the most constrained size, and avoid using a PPG together with multi-zone spreading because the two goals conflict.
Take quiz
Spread VMs across fault domains
Reduce licensing cost
Encrypt traffic between VMs
Minimize latency by placing VMs physically close together
Higher chance of allocation failures
Higher network latency
No support for managed disks
A lower VM SLA
34. What happens during Azure planned maintenance on a VM?
Azure regularly updates the host platform. Most updates are memory-preserving: the VM is paused for a few seconds (typically 10 or less) and resumes without a reboot. A smaller set requires a reboot or a move to a new host.
- Azure notifies you in advance for events that need a reboot or redeployment.
- VMs in an availability set are updated one update domain at a time, with a 30-minute pause between domains.
- Scheduled Events in IMDS let the VM see upcoming events and react, for example by draining connections.
- Maintenance configurations let you control timing on Dedicated Hosts and isolated VM sizes.
Plan for restarts by running at least two instances behind a load balancer, and make sure applications start cleanly after a reboot.
Take quiz
Azure Advisor
Scheduled Events in the Instance Metadata Service
Cost Management
NSG flow logs
30 minutes
Several hours
A few seconds (about 10 or less)
It never pauses
35. What happens when an Azure Spot VM is evicted?
Azure sends a Preempt notice through Scheduled Events about 30 seconds ahead, then stops the VM. What happens next depends on the eviction policy you chose at creation.
| Policy | Result | You keep paying for |
| Deallocate (default) | VM is stopped and deallocated; can be restarted when capacity returns | Disks |
| Delete | VM and its attached disks are removed | Nothing |
Eviction is triggered by capacity needs or by the Spot price passing your maximum. Setting the max price to -1 means you will pay up to the regular on-demand price, so you are evicted only for capacity reasons.
Handle it in the app: poll the scheduled events endpoint, checkpoint work and keep jobs restartable.
Take quiz
Delete
Terminate
Snapshot
Deallocate
You pay up to the on-demand price and are evicted only for capacity
The VM is free
The VM is evicted immediately
The price is capped at 10% of on-demand
36. How does accelerated networking work?
Accelerated networking uses SR-IOV to give the VM direct access to the physical network card, bypassing the host's virtual switch for most traffic. Packets go straight between the VM and the NIC's virtual function.
The result is lower latency, less jitter and lower CPU use for networking, which matters for high-throughput or chatty workloads. On Linux the VM sees both a synthetic NIC and a Mellanox virtual function that are bonded together.
az network nic create -g rg-demo -n nic01 --vnet-name vnet1 --subnet app \ --accelerated-networking true
It is supported on most general purpose and compute optimized sizes with at least 2 vCPUs, and on supported OS images. You can enable it on an existing NIC while the VM is deallocated.
Take quiz
NAT gateway
SR-IOV
VXLAN offload only
ExpressRoute FastPath
Larger OS disks
More vCPUs per VM
Lower latency, jitter and CPU usage for network traffic
Free public IP addresses
37. What is the difference between server-side encryption and Azure Disk Encryption?
Server-side encryption (SSE) encrypts managed disk data at rest in the storage service and is on by default. Azure Disk Encryption (ADE) encrypts volumes inside the guest OS using BitLocker on Windows or DM-Crypt on Linux, with keys held in Key Vault.
| Aspect | SSE | ADE | Encryption at host |
| Where it happens | Storage service | Inside guest OS | On the VM host |
| Keys | Platform or customer-managed | Key Vault | Platform or customer-managed |
| Covers temp disk and cache | No | Temp disk (OS dependent) | Yes, end to end |
| Default | Yes | No | No |
For stronger coverage, enable encryption at host, which encrypts temp disks and caches before data leaves the host. Microsoft has announced a retirement plan for ADE, so check current guidance before choosing it for new builds.
Take quiz
SSE with platform-managed keys
Snapshot encryption
NSG encryption
Encryption at host
Inside the guest OS with BitLocker or DM-Crypt
Only in the storage service
In the hypervisor firmware
On the load balancer
38. What is the difference between Trusted Launch and Confidential VMs?
Trusted Launch protects the VM's boot chain against rootkits and bootkits. Confidential VMs go further and encrypt memory in hardware, protecting data in use from the host, hypervisor and even Azure operators.
| Aspect | Trusted Launch | Confidential VMs |
| Protects against | Boot-level malware and tampering | Host-level access to memory and CPU state |
| Core tech | Secure Boot, vTPM, boot integrity monitoring | AMD SEV-SNP or Intel TDX hardware encryption, plus attestation |
| VM generation | Gen 2 only | Gen 2 only |
| Sizes | Many mainstream sizes | Specific families such as DCasv5 and ECasv5 |
Pick Trusted Launch as a sensible default for Gen 2 VMs and Confidential VMs for regulated data or multiparty computation where even the cloud operator must be excluded.
Take quiz
Trusted Launch
Confidential VMs
Availability Sets
Azure Disk Encryption
Generation 1
Either generation
Generation 2
Classic VMs
39. How does Just-In-Time VM access work?
Just-In-Time (JIT) VM access in Microsoft Defender for Cloud keeps management ports (such as 22, 3389, 5985 and 5986) closed by default and opens them only for an approved user, source IP and time window.
- JIT adds a deny rule to the NSG (or Azure Firewall) for the chosen ports.
- A user requests access, choosing the port, their IP and a duration (up to 24 hours).
- If RBAC allows it, Defender adds a temporary allow rule with higher priority.
- When the time expires, the allow rule is removed and the port is closed again.
Every request is logged, so you get an audit trail. JIT requires Defender for Servers Plan 2 and the VM must be protected by an NSG or firewall.
Take quiz
Azure Policy
Azure Bastion
Azure Monitor
Microsoft Defender for Cloud
It keeps a deny rule in the NSG and adds temporary allow rules on request
It stops the VM until requested
It deletes the public IP
It only changes the Windows firewall
40. How do you patch Azure VMs with Azure Update Manager?
Azure Update Manager assesses missing updates and installs them on Azure VMs and Azure Arc-enabled servers, on a schedule or on demand, without needing an Automation account.
- Enable periodic assessment so it checks for missing patches regularly.
- Create a maintenance configuration that defines the schedule, update classifications and any KB inclusions or exclusions.
- Assign VMs to the configuration, directly or through dynamic scopes based on tags and locations.
- Review compliance and run history in the portal.
The VM patch mode matters too. AutomaticByPlatform lets Azure orchestrate patching with availability-aware safe deployment, ImageDefault uses the OS's own settings and Manual leaves you in control. It replaces the older Automation Update Management solution.
Take quiz
An availability set
A maintenance configuration
A disk encryption set
An action group
Only Windows Azure VMs
Only Linux Azure VMs
Azure Arc-enabled servers
Only containers
41. How do you monitor Azure VMs?
Azure gives you host-level metrics out of the box and richer guest-level data once you install the Azure Monitor Agent (AMA).
| Layer | What you get | Needs agent? |
| Platform metrics | CPU %, network, disk operations | No |
| Guest metrics and logs | Memory, per-process data, event logs, syslog | Yes, AMA with Data Collection Rules |
| VM insights | Performance charts and dependency map | Yes, AMA (and dependency agent) |
| Boot diagnostics | Screenshot and serial log | No |
Memory is not visible from the host, so you need the agent for it. Send data to a Log Analytics workspace, build alert rules on metrics or log queries, and route notifications with action groups. The old Log Analytics (MMA) agent was retired in August 2024, so use AMA.
Take quiz
CPU percentage
Network in/out
Disk operations
Memory usage
Azure Monitor Agent
Dependency agent only
Diagnostics extension
Defender agent
42. How do cloud-init and custom data work on Azure VMs?
Custom data is a blob of up to 64 KB that you pass at VM creation. On Linux images with cloud-init, Azure delivers it and cloud-init runs it during first boot, so you can install packages and write files without logging in.
#cloud-config package_upgrade: true packages: - nginx runcmd: - systemctl enable --now nginx
az vm create -g rg-demo -n web01 --image Ubuntu2204 \ --custom-data cloud-init.txt --generate-ssh-keys
It runs only at initial provisioning, not on later reboots. On Windows, custom data is just written to a file and not executed automatically. Do not put secrets in it, since it can be read from within the VM.
Take quiz
4 KB
64 KB
256 KB
1 MB
On every reboot
Every hour
During the first boot provisioning
Only on resize
43. How do SLAs differ for single VMs, Availability Sets and Zones?
The VM SLA depends on how you deploy. A single VM using premium storage for all disks gets 99.9%. Two or more VMs in an availability set get 99.95%, and two or more across zones get 99.99%.
| Deployment | Monthly uptime SLA |
| Single VM, Premium SSD or Ultra disks | 99.9% |
| Single VM, Standard SSD | 99.5% |
| Single VM, Standard HDD | 95% |
| 2+ VMs in an Availability Set | 99.95% |
| 2+ VMs across Availability Zones | 99.99% |
Spot VMs have no SLA. Note that the SLA covers VM connectivity, not your application, so design the app tier and data layer for the same level.
Take quiz
99.95%
99.99%
99.5%
99.9%
Two or more VMs across availability zones
Two VMs in one availability set
A single VM with Premium SSD
A single VM with Standard HDD
44. When would you choose VMs over App Service or AKS?
Choose VMs when you need control of the operating system: custom drivers, installed software, specific kernels, licensing tied to a machine, or lift-and-shift of an app that cannot be changed.
| Need | VMs | App Service | AKS |
| OS-level control | Full | None | Node-level only |
| Ops effort | High (patching, scaling) | Low | Medium to high |
| Best fit | Legacy and custom workloads | Web apps and APIs | Many containerized microservices |
| Scaling | Scale sets | Built-in | Pods and nodes |
If the app is a standard web app, App Service removes most operational work. If it is containerized and needs orchestration, AKS fits. Many teams run a mix, with VMs for the legacy parts.
Take quiz
App Service
Virtual Machines
Azure Functions
Logic Apps
A single VM
App Service Free tier
AKS
Azure Bastion
45. When should you use Azure Dedicated Host?
Use Azure Dedicated Host when you need a physical server used only by your organization, typically for compliance or licensing reasons.
- Isolation: no other customer's VMs share the hardware.
- Licensing: bring per-core or per-socket licenses (Windows Server, SQL Server) and use them with visibility of the physical host.
- Maintenance control: choose when platform updates apply, using maintenance configurations.
- Placement control: host groups spread hosts across fault domains and zones.
You pay for the entire host regardless of how many VMs run on it, so it only pays off at reasonable utilization. Each host supports one VM series and size family. If you only need isolation without managing hosts, consider isolated VM sizes.
Take quiz
A discounted shared host
A reserved VM price
Free license keys
A physical server used only by your organization
The whole host, regardless of how many VMs run
Only the running VMs
Only the OS disks
Only outbound data
46. How does Azure Site Recovery protect VMs?
Azure Site Recovery (ASR) continuously replicates a VM's disks to a target region, so you can fail over to a ready copy if the source region has an outage.
flowchart LR
A["Source VM in region 1"] -->|Mobility service sends changes| B["Cache storage account"]
B --> C["Replica disks in region 2"]
C --> D{Failover}
D --> E["VM created in region 2"]
E --> F["Reprotect and failback"]
Changes are tracked and sent through a cache storage account in the source region. Crash-consistent recovery points are created every 5 minutes, and app-consistent points on a schedule you set. A recovery plan orders the failover of multiple VMs and runs scripts.
Use test failover to rehearse in an isolated network without affecting production. After the incident you can reprotect and fail back.
Take quiz
Only VM tags
VM disk changes continuously to a target region
Only the OS disk nightly
Weekly snapshots
Commit
Reprotect
Test failover
Planned failover
47. What is the difference between a disk snapshot and Azure Backup?
A snapshot is a one-time, read-only, point-in-time copy of a single managed disk. Azure Backup is a managed service that automates scheduled, policy-based backups of the whole VM with retention and application consistency.
| Aspect | Disk snapshot | Azure Backup |
| Scope | One disk | Whole VM, all disks |
| Scheduling | Manual or scripted | Policy-driven |
| Retention management | You delete them | Automatic by policy |
| App-consistent | No | Yes (VSS on Windows) |
| Storage location | Resource group, same region | Recovery Services vault, optional GRS |
Snapshots suit a quick rollback before a risky change. For real data protection use Azure Backup, because a snapshot kept in the same region is lost together with the region.
Take quiz
A full VM backup with retention policy
Cross-region replication
A VM image
A point-in-time read-only copy of a single disk
Azure Backup
Disk snapshot
Compute Gallery
Temporary disk
48. How do you troubleshoot an Azure VM unreachable over RDP?
Work from the outside in: confirm the VM is healthy, then the network path, then the guest OS.
- Check the VM is Running and review Resource Health and boot diagnostics (screenshot) for a stuck boot.
- Confirm the public IP or Bastion path, and that you are connecting to the right address.
- Use Network Watcher IP flow verify and Effective security rules to see whether an NSG blocks TCP 3389.
- Use Connection troubleshoot to test the path from a source to the VM.
- Run
Test-NetConnectionfrom another VM and check the guest firewall. - Use Run Command to check the TermService service and RDP registry settings.
- Use Reset password / Reset configuration (VMAccess) to repair RDP settings and credentials.
- As a last resort, redeploy to a new host, or attach the OS disk to a rescue VM with
az vm repair.
Serial Console is the fallback when the network is not working at all.
Take quiz
Packet capture
IP flow verify
Topology
Traffic Analytics
Load balancer health probes
NSG flow logs
Reset password / Reset configuration (VMAccess)
Azure Advisor
49. How can you optimize Azure VM costs?
Start by removing waste, then right-size, then commit. The order matters, because reserving a VM that should have been smaller locks in the waste.
- Right-size using Azure Advisor recommendations and CPU and memory metrics.
- Deallocate dev/test VMs when idle, with auto-shutdown schedules (stopped but allocated VMs still bill).
- Delete orphans: unattached disks, idle public IPs and old snapshots.
- Use Reservations or a savings plan for steady workloads.
- Apply Hybrid Benefit for eligible Windows, SQL, Red Hat and SUSE licenses.
- Use Spot VMs for fault-tolerant batch jobs.
- Choose the right disk tier and consider burstable B-series for light, spiky workloads.
- Use autoscale and set budgets, tags and alerts in Cost Management.
Take quiz
Azure Policy
Network Watcher
Service Health
Azure Advisor
Compute charges stop, though disks are still billed
All charges stop
The disks are deleted
Licenses are refunded
50. How do you move an Azure VM to another region?
The supported way is Azure Resource Mover, which replicates the VM's disks to the target region and recreates the VM and its dependencies there, with minimal downtime.
flowchart LR
A["Add resources"] --> B["Validate dependencies"]
B --> C[Prepare]
C --> D["Initiate move"]
D --> E{Commit or discard}
E --> F["Delete source"]
- Add the VM and let Resource Mover include dependencies (VNet, NIC, NSG, public IP, disks).
- Validate dependencies and fix any blockers, such as unsupported items or quota.
- Prepare to start replicating disks to the target region.
- Initiate move to create the VM in the target region.
- Commit to finish the move or discard to roll back, then delete source resources if no longer needed.
Public IP addresses change, so update DNS. Check that the target region supports the VM size and that you have quota. You can also use Site Recovery or copy a snapshot and rebuild the VM manually.