Containerized Solutions on Azure
20-25%of exam
AI Solutions with Data Services
25-30%of exam
Connect and Consume Azure Services
20-25%of exam
Secure, Monitor, Troubleshoot
20-25%of exam
Quick Facts
- Exam
- AI-200
- Credential
- Azure AI Cloud Developer Associate
- Time
- 120 min
- Pass
- 700 of 1000
- Score type
- Scaled, not 70%
- Questions
- Not published by Microsoft
- Level
- Associate
- Language
- English only
- Fee
- Varies by country
- Renewal
- Free yearly assessment
- Retake
- 24 hours, then 14 days
- Blueprint
- Apr 15 2026
Container Apps Defaults
No rule: HTTP, 0 to 10
Container Apps vs AKS
Container Apps
- Serverless, no cluster
- KEDA built in
- Scales to zero
AKS
- Full Kubernetes control
- Manifests and kubectl
- You manage nodes
Managed vs full control
Compute Picker
- Need full cluster control→AKS(Manifests, kubectl)
- Containers without Kubernetes→Container Apps(Serverless)
- Single web container→App Service(PaaS)
- Event-driven code only→Azure Functions(Serverless)
- Run to completion→Container Apps job(Batch)
- Build without local Docker→az acr build(ACR Tasks)
- Blue-green or canary→Multiple revision mode(Traffic split)
- Scale on queue depth→KEDA custom rule(Service Bus)
Container Registry
- ACR
- Private image registry
- az acr build
- Builds image in cloudNo Docker
- ACR Tasks
- Automated cloud builds
- Base image trigger
- Rebuilds on patch
- AcrPull
- Role that pulls images
- Admin account
- Shared password, keep disabled
- Premium tier
- Geo-replication, private endpoints
- Image digest
- Immutable content hash
- Image tag
- Mutable pointer
Single vs Multiple Revision
Single
- Default mode
- New revision takes all
- No traffic split
Multiple
- Several revisions active
- Weighted traffic split
- Blue-green and canary
Splitting traffic needs multiple
App Service Containers
- WEBSITES_PORT
- Port the container listens
- App settings
- Injected as environment variables
- Key Vault reference
- Secret resolved at startup
- Managed identity pull
- Keyless registry access
- Deployment slot
- Stage, then swap
- Slot setting
- Stays with its slot
- Always On
- Stops idle unload
- Health check
- Removes unhealthy instances
Template vs Configuration Scope
Template
- Image, env, resources
- Scale rules
- Creates new revision
Configuration
- Ingress, secrets, registry
- Revision mode
- Applies to all
New revision vs global
Container Apps
- Environment
- Network and logging boundary
- Revision
- Immutable app snapshot
- Template change
- Creates a new revision
- Configuration change
- Applies to all revisions
- Ingress
- External or internal
- Dapr sidecar
- Pub/sub, state, bindings
- Jobs
- Run to completion
- Secrets
- Referenced by environment variables
- Workload profile
- Dedicated or consumption compute
Scaling and KEDA
- KEDA
- Event-driven autoscaler
- Default rule
- HTTP, 0-10 replicasDefault
- concurrentRequests
- Default 10 per replica
- minReplicas 0
- Scales to zero
- No ingress risk
- Set minReplicas to 1
- Custom scaler
- Service Bus, Kafka, Redis
- Polling interval
- 30 seconds
- Cooldown period
- 300 seconds
- Scale formula
- ceil(current / target)
AKS Essentials
- kubectl apply -f
- Deploys a manifest
- Deployment
- Manages replica pods
- Service
- Stable network endpoint
- Ingress
- HTTP routing layer
- ConfigMap
- Non-secret configuration
- Secret
- Base64 encoded, not encrypted
- kubectl logs
- Container stdout output
- kubectl describe
- Events and failure reasons
- Workload identity
- Pod-level Entra token
- az aks update --attach-acr
- Grants AcrPull to cluster
Domain Weights
Data leads; other three tie
Cosmos Vector vs pgvector
Cosmos NoSQL
- JSON with embeddings
- VectorDistance function
- diskANN at scale
PostgreSQL
- Relational joins and filters
- <-> and <=> operators
- HNSW or IVFFlat
Documents vs relational
Data Store Picker
- Relational plus vectors→PostgreSQL + pgvector(SQL joins)
- Schema-free JSON documents→Cosmos DB NoSQL(Global scale)
- Sub-millisecond lookups→Azure Managed Redis(In-memory)
- Millions of vectors→diskANN index(Cosmos DB)
- Exact recall, small set→flat index(505 dimensions)
- Under 50,000 vectors→quantizedFlat index(Lower RU)
- Best recall in Postgres→HNSW index(Slower build)
- Faster build in Postgres→IVFFlat index(Tune probes)
- React to item changes→Change feed processor(Cosmos DB)
Cosmos DB for NoSQL
- RU/s
- Throughput currency
- Partition key
- Spreads logical partitions
- Autoscale
- Ranges max/10 to max
- Session
- Default consistency levelDefault
- Strong
- Highest RU cost
- Indexing policy
- Include or exclude paths
- TTL
- Automatic item expiry
- Change feed
- Ordered record of changes
- _ts
- Modification timestamp
- _etag
- Optimistic concurrency token
pgvector Operators
<-> L2, <=> cosine, <#> inner
HNSW vs IVFFlat
HNSW
- Graph based
- Best recall
- Slower, larger build
IVFFlat
- Cluster lists
- Faster build
- Needs representative data
Recall vs build cost
Cosmos Vector Search
- Container vector policy
- path, dataType, dimensions, distance
- VectorDistance()
- Similarity system function
- flat
- Exact search, 505 dimensions
- quantizedFlat
- Compressed, up to 4096
- diskANN
- Approximate, above 50,000 vectors
- distanceFunction
- cosine, dotproduct, euclidean
- TOP N
- Always cap vector queries
- 1,000 vector floor
- Needed by quantized indexes
- Default dimensions
- 1536
Vector Index Limits
flat 505, quantizedFlat 4096, diskANN 4096
flat vs diskANN
flat
- Brute force scan
- 100% recall
- Max 505 dimensions
diskANN
- Approximate search
- Max 4096 dimensions
- Needs 1,000 vectors
Exact vs scalable
pgvector on PostgreSQL
- azure.extensions
- Allowlist before creating
- CREATE EXTENSION vector
- Extension name is vector
- vector(n)
- Column type, n dimensions
- <->
- Euclidean L2 distance
- <=>
- Cosine distance
- <#>
- Negative inner product
- HNSW
- Graph index, best recall
- IVFFlat
- List index, faster build
- hnsw.ef_search
- Recall versus latency knob
- ivfflat.probes
- Lists scanned per query
- Metadata filter
- WHERE clause narrows RAG
Consistency Ladder
Strong > Bounded > Session > Prefix > Eventual
Azure Managed Redis
- Cache-aside
- Load on cache miss
- EXPIRE
- Time-based invalidation
- Eviction policy
- What drops when full
- FT.CREATE
- Builds a search index
- Vector index types
- FLAT or HNSW
- Tiers
- Memory, Balanced, Compute, Flash
- Flash Optimized
- No search or vector
- Entra ID auth
- Keyless Redis access
- Redis version
- 7.4.x
- Semantic cache
- Vector-matched response reuse
Event Grid Retry
10s, 30s, 1m, 5m, then hours
Service Bus vs Event Grid
Service Bus
- Carries commands and work
- Ordering, sessions, DLQ
- Consumer pulls
Event Grid
- Announces facts
- Pushes with filters
- At-least-once, unordered
Work queue vs notification
Messaging Picker
- Ordered transactional work→Service Bus queue(Sessions)
- Fan-out with filters→Service Bus topic(Subscriptions)
- Reactive discrete events→Event Grid(CloudEvents)
- Poison message handling→Dead-letter queue(MaxDeliveryCount)
- Serverless HTTP API→Functions HTTP trigger(Binding)
- Multi-step workflow state→Durable Functions(Orchestrator)
- Delay a message→Scheduled enqueue time(Service Bus)
Service Bus
- Queue
- Point-to-point work
- Topic
- Publish to many subscriptions
- Subscription filter
- SQL or correlation rule
- DLQ
- Holds undeliverable messages
- MaxDeliveryCount
- Moves message to DLQ
- Peek-lock
- Receive, process, then complete
- Sessions
- FIFO by session ID
- Duplicate detection
- Ignores repeated MessageId
- Standard size
- 256 KB message
- Premium size
- Up to 100 MB
Function Timeouts
Consumption 5/10; Flex and Premium 30
Event Grid vs Event Hubs
Event Grid
- Discrete events
- Per-event delivery
- Reactive handlers
Event Hubs
- High-volume streams
- Partitions and offsets
- Telemetry ingestion
Discrete vs stream
Event Grid
- CloudEvents 1.0
- Standard event schema
- Subject filter
- Prefix or suffix match
- Advanced filter
- Match on data fields
- At-least-once
- Duplicates possible, order not guaranteed
- Retry policy
- Exponential backoff, best effort
- Event TTL
- Default 1440 minutes
- Max attempts
- Default 30 tries
- Dead-letter
- Storage container required
- Success codes
- 200 through 204 only
- Never retried
- 400, 403, 413
Trigger vs Binding
Trigger
- Starts execution
- Exactly one
- Carries payload
Binding
- Input or output
- Zero or many
- Cannot start function
Starts vs connects
Azure Functions
- Trigger
- Starts the function
- Input binding
- Reads data declaratively
- Output binding
- Writes data declaratively
- host.json
- App-wide runtime settings
- local.settings.json
- Local development only
- Flex Consumption
- Current serverless planDefault
- Consumption timeout
- 5 default, 10 max
- Flex and Premium
- 30 default, unbounded max
- HTTP response cap
- 230 seconds regardless
- Durable Functions
- Stateful orchestration patterns
Keyless Access Recipe
Identity, role, scope, credential
Key Vault vs App Configuration
Key Vault
- Secrets, keys, certificates
- Audited and rotated
- Near-expiry events
App Configuration
- Non-secret settings
- Labels and snapshots
- Feature flags
Secrets vs settings
Troubleshoot Picker
- Slow end-to-end request→Distributed trace(App Insights)
- Which service failed→Application Map(Dependencies)
- Search logs at scale→KQL query(Log Analytics)
- Container keeps restarting→Container console logs(System logs)
- Secret will not resolve→Check identity role(RBAC)
- Traffic right now→Live Metrics(Streaming)
- Traces not correlating→traceparent header(W3C context)
Key Vault + App Config
- Secret
- Password, token, connection string
- Soft delete
- Recoverable, cannot be disabled
- Purge protection
- Blocks early permanent delete
- RBAC data plane
- Preferred over access policies
- Rotation
- Near-expiry event triggers function
- Key Vault reference
- App setting resolves secret
- App Configuration
- Central non-secret settings
- Label
- Per-environment key variant
- Sentinel key
- Signals refresh of all
- Feature flag
- Runtime on/off toggle
System vs User Assigned
System-assigned
- One resource only
- Deleted with resource
- Simplest single app
User-assigned
- Standalone resource
- Shared by many
- Survives redeploys
Lifecycle tied vs independent
Identity and Access
- Managed identity
- Azure-managed, no secrets
- System-assigned
- Tied to one resource
- User-assigned
- Shared across resources
- DefaultAzureCredential
- Chained credential lookup
- Workload identity
- Federated token for pods
- OIDC federation
- GitHub Actions without secrets
- AcrPull
- Pulls container images
- Key Vault Secrets User
- Reads secret values
- Cosmos DB Built-in Data Reader
- Data plane read role
- Private endpoint
- Private IP, no internet
Tracing and App Insights
- OpenTelemetry
- Vendor-neutral telemetry standard
- Azure Monitor Distro
- Microsoft OpenTelemetry package
- Connection string
- Routes telemetry to resource
- traceparent
- W3C trace context header
- Span
- One unit of work
- Cloud role name
- Names service on map
- Application Map
- Service dependency topology
- requests
- Incoming operation telemetry
- dependencies
- Outbound call telemetry
- exceptions
- Captured error telemetry
- Live Metrics
- Real-time streaming view
KQL Query Basics
- where
- Filters rows
- project
- Selects columns
- extend
- Adds computed column
- summarize
- Aggregates by group
- bin()
- Buckets into time intervals
- ago()
- Relative time filter
- top
- Highest N rows
- join
- Combines two tables
- union
- Stacks multiple tables
- render
- Charts the result
- let
- Names a variable
Common Traps
Scaled score
700 of 1000 scaled ≠ Not 70% correct
Identity vs role
Managed identity authenticates ≠ RBAC role authorizes
Work vs notification
Service Bus carries work ≠ Event Grid announces facts
Policy vs index
Vector policy defines shape ≠ Vector index speeds search
Secret vs setting
Key Vault holds secrets ≠ App Config holds settings
Revision vs configuration
Template edits create revisions ≠ Configuration edits do not
Zero replica dead end
No ingress, no rule ≠ App cannot wake up
Distance vs similarity
Lower distance is closer ≠ Cosine distance, not similarity
Flash tier limit
Flash Optimized uses NVMe ≠ No search or vector
Extension name
Docs say pgvector ≠ SQL says CREATE EXTENSION vector
Last Minute
- 1.Pass = 700 scaled, not 70%
- 2.120 minutes, English only
- 3.Data services is biggest domain
- 4.Container Apps default: 0-10 replicas
- 5.No ingress? Set minReplicas 1
- 6.Multiple revision mode splits traffic
- 7.az acr build needs no Docker
- 8.flat 505 dims; diskANN 4096
- 9.VectorDistance queries need TOP N
- 10.pgvector: <-> L2, <=> cosine
- 11.HNSW = recall; IVFFlat = speed
- 12.Service Bus = work; Event Grid = events
- 13.Event Grid TTL 1440 minutes
- 14.DLQ triggered by MaxDeliveryCount
- 15.Consumption timeout 5, max 10
- 16.Key Vault secrets; App Config settings
- 17.Managed identity first, then RBAC
- 18.traceparent carries W3C trace context
- 19.KQL: where, summarize, project, render
- 20.Flash Optimized has no vector
- 21.Renew free every 12 months
Explore More Microsoft Azure Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
