5 - Review Concepts Flashcards

1
Q

NSG vs. Firewall

A
NSG = Allow\Deny Ports
Firewall = Control bandwidth and access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AD Privileged Identity Management

A
  • *Managing Privileged Accounts**
  • just-in-time privileged access to Azure AD
  • Assign time-bound access to resources using start and end dates
  • Require approval to activate privileged roles
  • Enforce multi-factor authentication to activate any role
  • Get notifications when privileged roles are activated
  • Conduct access reviews to ensure users still need roles
  • Download audit history for internal or external audit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Compliance Manager & Service Trust Portal

A

Compliance Manager is a workflow-based risk assessment dashboard
-track, assign, and verify your organization’s regulatory compliance related to Microsoft professional services & Microsoft cloud services such as Office 365, Dynamics 365, and Azure

Service Trust Portal (STP) hosts the Compliance Manager service, and is the Microsoft public site for publishing audit reports and other compliance-related information relevant to Microsoft’s cloud services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Main Factors for Cost

A
  • Resource Type
  • Services - Azure usage rates and billing periods can differ between Enterprise, Web Direct, and Cloud Solution Provider (CSP) customers.
  • Location
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

BluePrints

A

Azure Blueprints is intended to assist with environment setup. Such environments often include Azure resource groups, role assignments, Azure policies and Resource Manager template deployments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

DDOS Protection

A

Basic - Free and across region
Standard - Provides additional mitigation capabilities over the Basic service tier that are tuned specifically to Azure Virtual Network resources. DDoS Protection Standard is simple to enable, and requires no application changes. Protection policies are tuned through dedicated traffic monitoring and machine learning algorithms. Policies are applied to public IP addresses associated to resources deployed in virtual networks, such as Azure Load Balancer, Azure Application Gateway, and Azure Service Fabric instances, but this protection does not apply to App Service Environments. Real-time telemetry is available through Azure Monitor views during an attack, and for history. Rich attack mitigation analytics are available via diagnostic settings. Application layer protection can be added through the Azure Application Gateway Web Application Firewall or by installing a 3rd party firewall from Azure Marketplace. Protection is provided for IPv4 and IPv6 Azure public IP addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Application Insights

A

Application Monitoring - performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CLI, Powershell, CloudShell,

A

CLI - Cross platform used for managing Azure. *Cant run powershell scripts
PowerShell -
Cloudshell - Browser based access to Powershell or BASH. Requires a fileshare. Android
Azure Portal -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AD Identity Protection

A

RISKS

  • Automate the detection and remediation of identity-based risks.
  • Investigate risks using data in the portal.
  • Export risk detection data to third-party utilities for further analysis.
  • offers MFA.
  • prompt to change password from anonymous
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Azure Logic App

A

-implement a workflow that could be run on a serverless infrastructure?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Azure AI Bot Service

A

Provide a digital online assistant that provides speech support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly