Validated skills
- Identity & governance: Entra ID (Azure AD), RBAC, subscriptions, resource groups, policy.
- Compute management: Deploy/maintain VMs & VMSS, extensions, images, availability sets/Zones.
- Storage: Accounts, Blob/File/Queue, lifecycle management, replication, Azure Files/AD auth.
- Networking: VNets, subnets, NSGs, routing, peering, VPN/ExpressRoute, DNS, load balancers.
- Monitoring & BCDR: Azure Monitor, Log Analytics, alerts, Backup, Site Recovery, updates.
- Security & automation: Key Vault, disk encryption, Defender for Cloud, ARM/Bicep, Automation.
Validated skills
- Fundamentals: IPv4/IPv6, subnetting/VLSM, OSI & TCP/IP models, cabling, wireless standards.
- Implementations: Switching (VLANs, trunks, STP), routing (static/dynamic), NAT, WLAN configuration.
- Operations: Documentation, backups, change control, performance baselining, monitoring.
- Network services & cloud: DHCP, DNS, NTP, proxies, load balancers, virtualization/segmentation.
- Security: Secure topologies, device hardening, ACLs, WPA3/802.1X, AAA concepts.
- Troubleshooting: Methodology & tools (ping/trace/arp, packet capture), L1–L7 fault isolation.
Validated skills
- General concepts: CIA triad, AAA, control types, secure SDLC, change management.
- Threats & vulnerabilities: Malware/social engineering, scanning, assessment, patching, remediation.
- Architecture & design: Network/cloud security, segmentation/zero trust, PKI/crypto basics.
- Implementation: Secure protocols, endpoint/wireless hardening, IAM/MFA, secrets & keys.
- Operations & IR: SIEM logging, playbooks, containment/eradication/recovery, forensics basics.
- GRC: Policies/standards, compliance frameworks, supply-chain & third-party risk, awareness.
Validated skills
- Resilient architectures: Multi-AZ/Region, failover, backup & restore, DR strategies.
- Secure architectures: IAM, KMS, networking controls (SGs/NACLs), encryption in transit/at rest.
- High performance: Right-sizing compute (EC2/Lambda/Fargate), storage patterns (S3/EFS/EBS), caching.
- Cost optimization: Pricing models, lifecycle policies, right-sizing, data transfer & storage tiers.
- Operational excellence: Monitoring/metrics (CloudWatch), automation, CloudFormation/IaC.
- Networking & hybrid: VPC design, subnets/NAT/TGW, PrivateLink, Direct Connect/VPN.