3 - Security, Privacy & Trust Flashcards

1
Q

Azure Firewall​

A

a managed service inside Azure that protects your virtual networks from unauthorized traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Azure DDoS Protection

A

Basic - Free and tuned for Azure region traffic

Standard - Tuned for application traffic. Adds logging, alerting and telemetry for you to see these attacks happening

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Network Security Group (NSG)​

A

Rules that you can apply to both inbound traffic and outbound traffic that lets you specify what sources, destinations and ports are allowed to travel through from outside the virtual network to inside the virtual network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Application Security Group (ASG)

A

A way of grouping related resources together to simplify the way NSG rules are created. All front end VMs can be in one ASG, while the mid-tier is in another. And then you can refer to them in the NSG rule by their ASG name

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

User Defined Routes (UDR)​

A

A way of forcing traffic travelling over a virtual network over a specific path. This is usually used in conjunction with Firewall devices, or ExpressRoute.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security Best Practices

A
  1. All virtual networks should use an NSG
  2. Security through layers is also a good idea because if one layer is breached, there are backups
  3. Application Gateway with WAF is generally a good idea for production systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Azure Security Center​

A

A Unified security management and threat protection; a security dashboard inside Azure Portal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Azure Information Protection (AIP)

A

Classify emails and documents; likea DRM for documents; secret, top secret, public, etc.; enforced by Outlook 365

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Azure Advanced Threat Protection (ATP)​

A

monitor Azure AD and detect when users are behaving differently than they normally do; requires additional login requirements like MFA or even locks them out when they do

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Azure Policy

A
  • Implement standards in Azure for your organization

- Rules can be enforced by blocking the action or just reporting the action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Azure Policy Types

A
● Require SQL Server 12.0 
● Allowed Storage Account SKUs 
● Allowed Regions for resources to be created in 
● Allowed Virtual Machine SKUs 
● Require resources have tag
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Locks Access Control​

A

Limit who has the ability to delete locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Azure Advisor​

A

Recommendations based on your specific account

  • HA
  • Security
  • Performance
  • Cost
  • Op Excellence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

GDPR - General Data Protection Regulation

A

law that covers how you collect, store, protect and report data of EU citizens

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

NIST

A
  • Cyber security framework

- requires an audit to see that you’re following security and privacy best practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Compliance Manager

A
  • Manage your own regulatory compliance

- Track, Assign and verify your companies regulatory compliance

17
Q

Service Trust Portal

A

Service Trust Portal (STP)

-Compliance Manager

18
Q

Azure China cloud services

A
  • Not connected to the rest of Azure

- Separate datacenters, login, standards

19
Q

Trust center

A

A website with details about how Microsoft implements and supports security, privacy, compliance in all Microsoft cloud products and services.

20
Q

Azure Monitor vs. Service Health

A
  • Use Azure monitor to alert on issues in your subscription

- Use Azure Service Health to alert on issues across all of Azure worldwide

21
Q

Azure Blueprints

A

Can consists of a set of resource groups, policies, role assignments, and Resource Manager template deployments.

  • A blueprint is a package to bring each of these artifact types together and allow you to compose and version that package – including through a CI/CD pipeline.
  • Ultimately, each is assigned to a subscription in a single operation that can be audited and tracked.
22
Q

Locks

A

Read Only or Can Not Delete

23
Q

Application Insights

A

Service that monitors the availability, performance, and usage of your web applications

24
Q

Microsoft Privacy Statement

A

Explains what personal data Microsoft processes, how Microsoft processes it, and for what purposes.

25
Q

ISO/IEC 27018

A

Code of practice for protection of personally identifiable information in public clouds

26
Q

Service Trust Portal - Details

A

The Service Trust Portal (STP) hosts the Compliance Manager service, and is the Microsoft public site for publishing audit reports and other compliance-related information relevant to Microsoft’s cloud services.

Compliance Manager
Compliance Manager is a workflow-based risk assessment dashboard within the Trust Portal that enables you to track, assign, and verify your organization’s regulatory compliance activities related to Microsoft professional services and Microsoft cloud services such as Office 365, Dynamics 365, and Azure.