Describe Security, Privacy, Compliance, and Trust Flashcards
Describe network security group
Allows filtering of network traffic to and from azure resources.
Filter by Source IP address Destination up address Port Protocol
Describe application security group
Configure network security as a extension of an application’s structure allowing you to group virtual machines and define security policies based on those groups
Describe user defined rules
Check answer
Describe azure firewall
Service that grants access based on originating up address.
Network protocol and port specific
Describe azure did protection
Ddos.
Levels
Basic - automatically enabled. Always on traffic monitoring real time mitigation of common network level attacks
Standard - additional mitigation capabilities tuned to azure virtual network resources
Standard
Volumetric attacks
Protocol attacks
Resource layer Attacks
What is authorisation
Process of establishing what level of access an authenticated person or service has.
It specifies what data they’re allowed to access and what they can do with it.
What is authentication?
Establishing the identity of a person or service looking to access a resource.
Challenging for legitimate credentials
What is azure active directory
Microsoft cloud based identity and access management service.
Helps
Employees sign in and access resources
Authentication Single sign on App Management B2b B2c Device management
Intended for
It admins
App developers
Microsoft 365, office 365, azure or cram online
What is mfa?
Multi factor authentication
Provides additional security by requiring two or
More elements for full authentication
Comes as part of
Ad premium license
Authentication subscription for office 365
Azure AD directory global adminstrators
What is azure security centre
Monitoring service provides threat
Protection to on prem and azure resources
Security recommendations Monitor Assessments Machine learning Analyse and identify inbound attacks Access control for ports
Versions
Free - azure resources only
Standard - full suite
What is azure security centre usage scenarios?
Integrate into workflows
1 use security centre for an incident response
Detect
Assess
Diagnose
2 enhance security
Security policy recommendations
What is azure key vault ?
Centralised cloud service for storing
Application secrets
Secrets management
Key management
Certificate management
Store secrets backed by HSMs
What is azure information protection (AIP)
Helps organisations classify and protect documents and email by applying labels
Manually or automatically
What is azure advanced threat protection (ATP)
Identifies, detects and helps
You investigate advances threats
License
Describe azure policy
Service to create assign and manage policies
Policies enforce different rules and effects on resources so they’d stay compliant with corporate standards and sla’s