Azure Governance and Compliance Flashcards

1
Q

What Types of Rules appear in contact with Governance?

A
  • servers must be running software withing Microsoft Extended Support guidelines
  • all servers must be backed up every 24 hours at a minimum
  • Firewalls must block all inbound ports from the Internet except 443
  • Only Operations Support can reboot a production server
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can you enforce governance rules in Azure?

A
  • Azure Blueprint will be retired
  • Template specs replaces it (ARM templates)
  • as well as Deployment Stacks
  • Azure Policy (predefined and own rules)
  • Resource Locks (prevents accidental changes)
  • Microsoft Purview (data governance)
  • RBAC
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

At what level can Azure Policy rules be defined?

A
  • for resources and resource groups
  • all or some
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does Azure Policy allow you to do?

A
  • definition of rules for resources and resource groups
  • evaluation of compliance of those rules
  • enforce rules so that resources cannot violate those rules
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name examples for Azure Policies

A
  • require SQL Server 12.0
  • automatically apply tagging
  • not allowed resource types
  • reject certain storage accounts SKUs
  • limit deployment locations
  • limit vm SKUs (Specs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When talking about scope of Azure Policies what is meant?

A
  • subscriptions / management groups
  • and/or resource groups
  • i.e. where Azure Policies should be enforced
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How can you apply a new Azure Policy to already existing resources?

A
  • via a remediation task after creation of the Azure policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What types of Resource Locks exist?

A
  • Read Only
  • Can Not Delete
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the Read-Only Resource Lock entail?

A
  • only allows to see the resource exists and view its properties
  • does not allow to make any changes to resource or delete it
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the Can Not Delete Resource Lock entail?

A
  • only blocks deletions
  • changes can be applied to the resource
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How can RBAC and Resource locks work together?

A
  • RBAC can be used to restrict who can unlock (update, delete, add) locks
  • access to locks is denied by default
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the Tool Microsoft Perview used for?

A
  • Data Governance Tool
  • one-stop shop, centralised dashboard

lots of features:
- auditing
- communication compliance
- Data Map and Data Catalog
- Information Protection
- Data Loss Prevention
- Data Lifecycle Management
- Insider Risk Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does Communication Compliance of the Microsoft Perview tool entail?

A
  • SEC compliance (tracking of messages between employees)
  • FINRA (financial tracking requirements)
  • sensitive or confidential information
  • harassing or threatening language
  • sharing of adult content

Report that shows what policy issues come up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does Information Protection of the Microsoft Perview tool entail?

A
  • proactively finds sensitive information in your organization
  • Know your data - what sensitive information is stored where
  • protect your data - sensitivity labels, encryption
  • prevent data loss - browser extensions, pop-up tips, block sharing

Based on labels options for dealing with data can be restricted, etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly