deck-1 (m) Flashcards
License and Access Review
P2
ACR accessing from SF office vnet and using MFA. 2 things for access control?
Disable admin and Set Firewall rule
Storage Account V1 supported by AD authentication? need to upgrade to V2?
Yes, No
VM update management and 2 related resources
Log Analytics workspace, Automation Account
Enterprise App running non-interactive mode. What permission? Admin or User consent? Where to review the enterprise app? MDC or AD
App Permission, Admin consent. AD
SQL injection attack. What to implement? ATP?
Advanced Threat Protection
TLS certificate format for Web App to upload and Min Service plan
PFX and Basic. CRT for public key certificate.
3 encryptions in SQL: at rest, column encryption, and in transit
TDE (Transparent Data Encryption), Always Encrypted, TLS/SSL encryption. DDM is not a encryption.
cmd to create a spn (Service principal name) in AKS
az ad sp create-for-rbac
Web app reading a secret from KV on behalf of users. What permission and consent?
Delegated permission + no admin consent (why? no write).
and no user consent either since it is not reading from user’s profile.
Enterprise App reading all user profile within the tenant. Graph API scope, scope type, consent
Directory.Read.All, app-only (not app.only), and admin consent - Yes.
- why? running as a service
Payroll manager reviews group membership. What implementation? Licenses?
Access Review, P2
traffic going thru NVA. what routing solution?
UDR (User Defined Route)
NSG migration to AKS environment. What implementation? NetworkPolicy or NetworkRule? What sub-elements?
NetworkPolicy
with ingress and port
Locate the trusted data? Purview what?
Catalog