Cheat sheet

Azure AI-200 Cheat Sheet

Quick Facts

Exam
AI-200
Credential
Azure AI Cloud Developer Associate
Time
120 min
Pass
700 of 1000
Score type
Scaled, not 70%
Questions
Not published by Microsoft
Level
Associate
Language
English only
Fee
Varies by country
Renewal
Free yearly assessment
Retake
24 hours, then 14 days
Blueprint
Apr 15 2026

Container Apps Defaults

No rule: HTTP, 0 to 10

10 concurrent requestsPoll every 30 secondsCooldown 300 secondsNo ingress? minReplicas 1

Container Apps vs AKS

Container Apps

  • Serverless, no cluster
  • KEDA built in
  • Scales to zero

AKS

  • Full Kubernetes control
  • Manifests and kubectl
  • You manage nodes

Managed vs full control

Compute Picker

  1. Need full cluster controlAKS(Manifests, kubectl)
  2. Containers without KubernetesContainer Apps(Serverless)
  3. Single web containerApp Service(PaaS)
  4. Event-driven code onlyAzure Functions(Serverless)
  5. Run to completionContainer Apps job(Batch)
  6. Build without local Dockeraz acr build(ACR Tasks)
  7. Blue-green or canaryMultiple revision mode(Traffic split)
  8. Scale on queue depthKEDA custom rule(Service Bus)

Container Registry

ACR
Private image registry
az acr build
Builds image in cloudNo Docker
ACR Tasks
Automated cloud builds
Base image trigger
Rebuilds on patch
AcrPull
Role that pulls images
Admin account
Shared password, keep disabled
Premium tier
Geo-replication, private endpoints
Image digest
Immutable content hash
Image tag
Mutable pointer

Single vs Multiple Revision

Single

  • Default mode
  • New revision takes all
  • No traffic split

Multiple

  • Several revisions active
  • Weighted traffic split
  • Blue-green and canary

Splitting traffic needs multiple

App Service Containers

WEBSITES_PORT
Port the container listens
App settings
Injected as environment variables
Key Vault reference
Secret resolved at startup
Managed identity pull
Keyless registry access
Deployment slot
Stage, then swap
Slot setting
Stays with its slot
Always On
Stops idle unload
Health check
Removes unhealthy instances

Template vs Configuration Scope

Template

  • Image, env, resources
  • Scale rules
  • Creates new revision

Configuration

  • Ingress, secrets, registry
  • Revision mode
  • Applies to all

New revision vs global

Container Apps

Environment
Network and logging boundary
Revision
Immutable app snapshot
Template change
Creates a new revision
Configuration change
Applies to all revisions
Ingress
External or internal
Dapr sidecar
Pub/sub, state, bindings
Jobs
Run to completion
Secrets
Referenced by environment variables
Workload profile
Dedicated or consumption compute

Scaling and KEDA

KEDA
Event-driven autoscaler
Default rule
HTTP, 0-10 replicasDefault
concurrentRequests
Default 10 per replica
minReplicas 0
Scales to zero
No ingress risk
Set minReplicas to 1
Custom scaler
Service Bus, Kafka, Redis
Polling interval
30 seconds
Cooldown period
300 seconds
Scale formula
ceil(current / target)

AKS Essentials

kubectl apply -f
Deploys a manifest
Deployment
Manages replica pods
Service
Stable network endpoint
Ingress
HTTP routing layer
ConfigMap
Non-secret configuration
Secret
Base64 encoded, not encrypted
kubectl logs
Container stdout output
kubectl describe
Events and failure reasons
Workload identity
Pod-level Entra token
az aks update --attach-acr
Grants AcrPull to cluster

Domain Weights

Data leads; other three tie

Containers: 20-25%Data services: 25-30%Connect: 20-25%Secure: 20-25%

Cosmos Vector vs pgvector

Cosmos NoSQL

  • JSON with embeddings
  • VectorDistance function
  • diskANN at scale

PostgreSQL

  • Relational joins and filters
  • <-> and <=> operators
  • HNSW or IVFFlat

Documents vs relational

Data Store Picker

  1. Relational plus vectorsPostgreSQL + pgvector(SQL joins)
  2. Schema-free JSON documentsCosmos DB NoSQL(Global scale)
  3. Sub-millisecond lookupsAzure Managed Redis(In-memory)
  4. Millions of vectorsdiskANN index(Cosmos DB)
  5. Exact recall, small setflat index(505 dimensions)
  6. Under 50,000 vectorsquantizedFlat index(Lower RU)
  7. Best recall in PostgresHNSW index(Slower build)
  8. Faster build in PostgresIVFFlat index(Tune probes)
  9. React to item changesChange feed processor(Cosmos DB)

Cosmos DB for NoSQL

RU/s
Throughput currency
Partition key
Spreads logical partitions
Autoscale
Ranges max/10 to max
Session
Default consistency levelDefault
Strong
Highest RU cost
Indexing policy
Include or exclude paths
TTL
Automatic item expiry
Change feed
Ordered record of changes
_ts
Modification timestamp
_etag
Optimistic concurrency token

pgvector Operators

<-> L2, <=> cosine, <#> inner

<-> Euclidean distance<=> cosine distance<#> negative inner product

HNSW vs IVFFlat

HNSW

  • Graph based
  • Best recall
  • Slower, larger build

IVFFlat

  • Cluster lists
  • Faster build
  • Needs representative data

Recall vs build cost

Cosmos Vector Search

Container vector policy
path, dataType, dimensions, distance
VectorDistance()
Similarity system function
flat
Exact search, 505 dimensions
quantizedFlat
Compressed, up to 4096
diskANN
Approximate, above 50,000 vectors
distanceFunction
cosine, dotproduct, euclidean
TOP N
Always cap vector queries
1,000 vector floor
Needed by quantized indexes
Default dimensions
1536

Vector Index Limits

flat 505, quantizedFlat 4096, diskANN 4096

flat: exact, small setsquantizedFlat: under 50,000diskANN: over 50,000Quantized needs 1,000 vectors

flat vs diskANN

flat

  • Brute force scan
  • 100% recall
  • Max 505 dimensions

diskANN

  • Approximate search
  • Max 4096 dimensions
  • Needs 1,000 vectors

Exact vs scalable

pgvector on PostgreSQL

azure.extensions
Allowlist before creating
CREATE EXTENSION vector
Extension name is vector
vector(n)
Column type, n dimensions
<->
Euclidean L2 distance
<=>
Cosine distance
<#>
Negative inner product
HNSW
Graph index, best recall
IVFFlat
List index, faster build
hnsw.ef_search
Recall versus latency knob
ivfflat.probes
Lists scanned per query
Metadata filter
WHERE clause narrows RAG

Consistency Ladder

Strong > Bounded > Session > Prefix > Eventual

Session is defaultStrong costs most RUsEventual is cheapest

Azure Managed Redis

Cache-aside
Load on cache miss
EXPIRE
Time-based invalidation
Eviction policy
What drops when full
FT.CREATE
Builds a search index
Vector index types
FLAT or HNSW
Tiers
Memory, Balanced, Compute, Flash
Flash Optimized
No search or vector
Entra ID auth
Keyless Redis access
Redis version
7.4.x
Semantic cache
Vector-matched response reuse

Event Grid Retry

10s, 30s, 1m, 5m, then hours

TTL default 1440 minutes30 attempts defaultDead-letter needs storage

Service Bus vs Event Grid

Service Bus

  • Carries commands and work
  • Ordering, sessions, DLQ
  • Consumer pulls

Event Grid

  • Announces facts
  • Pushes with filters
  • At-least-once, unordered

Work queue vs notification

Messaging Picker

  1. Ordered transactional workService Bus queue(Sessions)
  2. Fan-out with filtersService Bus topic(Subscriptions)
  3. Reactive discrete eventsEvent Grid(CloudEvents)
  4. Poison message handlingDead-letter queue(MaxDeliveryCount)
  5. Serverless HTTP APIFunctions HTTP trigger(Binding)
  6. Multi-step workflow stateDurable Functions(Orchestrator)
  7. Delay a messageScheduled enqueue time(Service Bus)

Service Bus

Queue
Point-to-point work
Topic
Publish to many subscriptions
Subscription filter
SQL or correlation rule
DLQ
Holds undeliverable messages
MaxDeliveryCount
Moves message to DLQ
Peek-lock
Receive, process, then complete
Sessions
FIFO by session ID
Duplicate detection
Ignores repeated MessageId
Standard size
256 KB message
Premium size
Up to 100 MB

Function Timeouts

Consumption 5/10; Flex and Premium 30

Consumption: 5 then 10Flex: 30, then unboundedHTTP capped 230 seconds

Event Grid vs Event Hubs

Event Grid

  • Discrete events
  • Per-event delivery
  • Reactive handlers

Event Hubs

  • High-volume streams
  • Partitions and offsets
  • Telemetry ingestion

Discrete vs stream

Event Grid

CloudEvents 1.0
Standard event schema
Subject filter
Prefix or suffix match
Advanced filter
Match on data fields
At-least-once
Duplicates possible, order not guaranteed
Retry policy
Exponential backoff, best effort
Event TTL
Default 1440 minutes
Max attempts
Default 30 tries
Dead-letter
Storage container required
Success codes
200 through 204 only
Never retried
400, 403, 413

Trigger vs Binding

Trigger

  • Starts execution
  • Exactly one
  • Carries payload

Binding

  • Input or output
  • Zero or many
  • Cannot start function

Starts vs connects

Azure Functions

Trigger
Starts the function
Input binding
Reads data declaratively
Output binding
Writes data declaratively
host.json
App-wide runtime settings
local.settings.json
Local development only
Flex Consumption
Current serverless planDefault
Consumption timeout
5 default, 10 max
Flex and Premium
30 default, unbounded max
HTTP response cap
230 seconds regardless
Durable Functions
Stateful orchestration patterns

Keyless Access Recipe

Identity, role, scope, credential

Enable managed identityAssign least-privilege roleScope to the resourceUse DefaultAzureCredential

Key Vault vs App Configuration

Key Vault

  • Secrets, keys, certificates
  • Audited and rotated
  • Near-expiry events

App Configuration

  • Non-secret settings
  • Labels and snapshots
  • Feature flags

Secrets vs settings

Troubleshoot Picker

  1. Slow end-to-end requestDistributed trace(App Insights)
  2. Which service failedApplication Map(Dependencies)
  3. Search logs at scaleKQL query(Log Analytics)
  4. Container keeps restartingContainer console logs(System logs)
  5. Secret will not resolveCheck identity role(RBAC)
  6. Traffic right nowLive Metrics(Streaming)
  7. Traces not correlatingtraceparent header(W3C context)

Key Vault + App Config

Secret
Password, token, connection string
Soft delete
Recoverable, cannot be disabled
Purge protection
Blocks early permanent delete
RBAC data plane
Preferred over access policies
Rotation
Near-expiry event triggers function
Key Vault reference
App setting resolves secret
App Configuration
Central non-secret settings
Label
Per-environment key variant
Sentinel key
Signals refresh of all
Feature flag
Runtime on/off toggle

System vs User Assigned

System-assigned

  • One resource only
  • Deleted with resource
  • Simplest single app

User-assigned

  • Standalone resource
  • Shared by many
  • Survives redeploys

Lifecycle tied vs independent

Identity and Access

Managed identity
Azure-managed, no secrets
System-assigned
Tied to one resource
User-assigned
Shared across resources
DefaultAzureCredential
Chained credential lookup
Workload identity
Federated token for pods
OIDC federation
GitHub Actions without secrets
AcrPull
Pulls container images
Key Vault Secrets User
Reads secret values
Cosmos DB Built-in Data Reader
Data plane read role
Private endpoint
Private IP, no internet

Tracing and App Insights

OpenTelemetry
Vendor-neutral telemetry standard
Azure Monitor Distro
Microsoft OpenTelemetry package
Connection string
Routes telemetry to resource
traceparent
W3C trace context header
Span
One unit of work
Cloud role name
Names service on map
Application Map
Service dependency topology
requests
Incoming operation telemetry
dependencies
Outbound call telemetry
exceptions
Captured error telemetry
Live Metrics
Real-time streaming view

KQL Query Basics

where
Filters rows
project
Selects columns
extend
Adds computed column
summarize
Aggregates by group
bin()
Buckets into time intervals
ago()
Relative time filter
top
Highest N rows
join
Combines two tables
union
Stacks multiple tables
render
Charts the result
let
Names a variable

Common Traps

Scaled score

700 of 1000 scaled Not 70% correct

Identity vs role

Managed identity authenticates RBAC role authorizes

Work vs notification

Service Bus carries work Event Grid announces facts

Policy vs index

Vector policy defines shape Vector index speeds search

Secret vs setting

Key Vault holds secrets App Config holds settings

Revision vs configuration

Template edits create revisions Configuration edits do not

Zero replica dead end

No ingress, no rule App cannot wake up

Distance vs similarity

Lower distance is closer Cosine distance, not similarity

Flash tier limit

Flash Optimized uses NVMe No search or vector

Extension name

Docs say pgvector SQL says CREATE EXTENSION vector

Last Minute

  1. 1.Pass = 700 scaled, not 70%
  2. 2.120 minutes, English only
  3. 3.Data services is biggest domain
  4. 4.Container Apps default: 0-10 replicas
  5. 5.No ingress? Set minReplicas 1
  6. 6.Multiple revision mode splits traffic
  7. 7.az acr build needs no Docker
  8. 8.flat 505 dims; diskANN 4096
  9. 9.VectorDistance queries need TOP N
  10. 10.pgvector: <-> L2, <=> cosine
  11. 11.HNSW = recall; IVFFlat = speed
  12. 12.Service Bus = work; Event Grid = events
  13. 13.Event Grid TTL 1440 minutes
  14. 14.DLQ triggered by MaxDeliveryCount
  15. 15.Consumption timeout 5, max 10
  16. 16.Key Vault secrets; App Config settings
  17. 17.Managed identity first, then RBAC
  18. 18.traceparent carries W3C trace context
  19. 19.KQL: where, summarize, project, render
  20. 20.Flash Optimized has no vector
  21. 21.Renew free every 12 months
Same family resources

Explore More Microsoft Azure Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.