Active Directory Flashcards

1
Q

What does Active Directory provide?

A

Single sign-on (SSO) and Multi-factor authentication (MFA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 4 pricing tiers for AD?

A

Free, Office 365 Apps, Premium P1, and Premium P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What pricing tier do you need to provide ‘Identity Protection’ and ‘Identity Governance’?

A

Premium P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the acronym RBAC stand for?

A

Role Based Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What 3 things to you need to specify when creating a role?

A

Security Principal, Role Definition, Scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name the different types of Service Principals

A

User, managed identity, service principal, group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How long are RBAC Activity Logs stored by default?

A

90 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the workaround for the RBAC activity log storage limitation?

A

Use Azure Event Hub

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How many RBAC Activity Log categories are there?

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

List the RBAC Activity Log categories

A

Administrative, Service Health, Resource Health, Alert, Autoscale, Recommendation, Security, Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 3 methods for achieving Hybrid Identity?

A

Password Hash Synchronisation (PHS), Pass-through authentication (PTA), Federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is PHS?

A

Password Hash Synchronisation. Sync the hash of the hashed password to Azure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is PTA?

A

Pass-through authentication. Use the same password as on-premise. Validates directly with On-premise AD. Password never stored on Azure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Federation Hybrid Identity?

A

Collections of domain trust each other for shared access of resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the acronym SAML stand for?

A

Security Assertion Markup Language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does the acronym MFA stand for?

A

Multi-Factor Authentication

17
Q

What types of MFA are there?

A

Password, SMS, Voice Call, Email, App, Security questions, App passwords, OAUTH hardware token

18
Q

What is Azure AD B2B used for?

A

To allow external partners access to Azure. No need for external accounts and passwords or syncing accounts. Invite guest user via email

19
Q

What is Azure AD B2C used for?

A

To control how customers use apps

20
Q

What identity methods are there for Azure B2C?

A

Identity Providers, Users, Other systems, Local Directory

21
Q

What is Self-service Password reset (SSPR)?

A

Allows users to reset their own passwords

22
Q

What SSPR functionality is provided in the BASIC AD license?

A

Only allows CLOUD USERS to reset their passwords

23
Q

What AD licenses provide full SSPR functionality?

A

AD Premium P1 and P2

24
Q

What is SAS used for?

A

Provided delegated access to Azure Resources with granular control

25
Q

What are the 3 types of SAS for storage accounts?

A

User delegation SAS, Service SAS, Account SAS

26
Q

What is User delegation SAS?

A

Use AD to create SAS

27
Q

What resource is User Delegation SAS limited to?

A

Blob Storage

28
Q

What is Service SAS?

A

Use Storage Account key to create SAS

29
Q

What are the limitations of Service SAS?

A

Can only access ONE storage account type

30
Q

What are the limitations of Account SAS?

A

Use the Account Key to create SAS

31
Q

Are there any limitations to using Account SAS?

A

No. You can give access to one or more storage account types

32
Q

What 3 benefits does Azure AD Identity Protection provide?

A

1) Get summary of flagged users and detected risk events. 2) Set risk-based conditional access policies 3) Get suggested vulnerabilities to act on