General Security and Network Security - 10-15% Flashcards
Objective area 4
Includes the following concepts: ▪ Azure Security features • Security Center and resource hygiene • Key Vault, Sentinel, and Dedicated Hosts ▪ Azure network security • Defense in depth • Network Security Groups and Firewalls • DDoS protection
Security tools and features - Objective Domain
Describe the features and the functionality of:
• Azure Security Center, including policy compliance, security alerts, secure score, and resource hygiene
• Azure Sentinel
• Key Vault
• Azure Dedicated Hosts
What is an Azure Security Center?
Azure Security Center is a monitoring service that provides threat protection across both Azure and on-premises datacenters. • Provides security recommendations • Detect and block malware • Analyze and identify potential attacks • Just-in-time access control for ports
What is the Walkthrough of the Azure Security Center?
Open Azure Security Center and view some of the common features and configuration options.
- Launch Azure Security Center.
- View Policy compliance options.
- Review your Secure Score.
- Set a Security Alert.
- Explore Resource Hygiene.
What are the Azure Security center capabilities?
-Policy compliance
Security Center is built on top of Azure Policy controls so you can set and monitor your policies to run on management groups, across subscriptions, and even for a whole tenant.
-Security alerts
Security Center automatically collects, analyzes, and integrates log data from your Azure resources like firewall and endpoint protection to detect real threats. Then list of prioritized security alerts is shown in Security Center along with the information you need to quickly investigate and remediate an attack.
-Secure score
Security Center continually assesses your resources for security issues; then aggregates all the findings into a single score so that you can tell your current security situation.
-Resource Security Hygiene
Security visibility and recommendations by resource.
-Policy Compliance
Run policies across management groups, subscriptions, or tenants
-Continuous Assessments-
Assess new and deployed resources to ensure that they are configured properly
-Tailored Recommendations
Recommendations based on existing workload with instructions on how to implement them.
-Threat Protection- Analyze attempted threats through alerts and impacted resource reports.
What is Azure Sentinel?
Azure Sentinel is a security information management (SIEM) and security automated response (SOAR) solution that provides security analytics and threat intelligence across an enterprise.
Connector and Integrations: • Office 365 • Azure Active Director • Azure Advanced Threat Protection • Microsoft Cloud App Security
What is Azure Key Vault?
Azure Key Vault stores application secrets in a centralized cloud location in order to securely control access permissions and access logging.
- Secrets management.
- Key management.
- Certificate management.
- Storing secrets backed by hardware security modules (HSMs).
What is the walkthrough to implement Azure Key Vault?
Create an Azure Key vault and then create a password secret within the key vault.
- Create an Azure key vault.
- Add a secret to the Azure key vault.
What is an Azure Dedicated Host?
Azure Dedicated Host provides physical servers that host one or more Azure virtual machines that is dedicated to a single organization’s workload.
Benefits
• Hardware isolation at the server level
• Control over maintenance event timing • Aligned with Azure Hybrid Use Benefits
Secure Network Connectivity - Objective Domain
Describe the concept and functionality of: • Defense in depth • Network Security Groups (NSG) • Azure Firewall • Azure DDoS protection
What is defense in depth?
Defense in depth
• A layered approach to securing computer systems.
• Provides multiple levels of protection.
• Attacks against one layer are isolated from subsequent layers.
What is shared security?
Shared Security
• Migrating from customer- controlled to cloud-based datacenters shifts the responsibility for security.
• Security becomes a shared concern between cloud providers and customers.
What are NSGs?
Network Security Groups (NSGs)
Network Security Groups (NSGs) filter network traffic to and from Azure resources on
Azure Virtual Networks.
• SetinboundandoutboundrulestofilterbysourceanddestinationIPaddress,port, and protocol.
• Addmultiplerules,asneeded,withinsubscriptionlimits.
• Azureappliesdefault,baselinesecurityrulestonewNSGs. • Overridedefaultruleswithnew,higherpriorityrules.
Azure Firewall?
Azure Firewall
A stateful, managed Firewall as a Service (FaaS) that grants/denies server access based on originating IP address, in order to protect network resources.
• Applies inbound and outbound traffic filtering rules
• Built-in high availability
• Unrestricted cloud scalability
• Uses Azure Monitor logging
Azure Distributed Denial of Service (DDoS) protection?
Azure Distributed Denial of Service (DDoS) protection
DDoS attacks overwhelm and exhaust network resources, making apps slow or unresponsive.
• Sanitizes unwanted network traffic before it impacts service availability.
• Basic service tier is automatically enabled in Azure.
• Standard service tier adds mitigation capabilities that are tuned to protect Azure Virtual Network resources.