Identity, Governance, Privacy, and Compliance Flashcards

1
Q

Authentication

A
  • Identifies the person or service seeking access to a resource
  • Requests legitimate access credentials
  • Basis for creating secure identity and access control principles
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Authorization

A
  • Determines and authenticated person’s or service’s level of access
  • Defines which data they can access and what they can do with it
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Azure Multi-Factor Authentication

A

Provides additional security for your identities by requiring two or more elements for full authentication. (something you know, possess, are).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Azure Active Directory (AAD)

A

Microsoft Azure’s cloud-based identity and access management service.
• Authentication (employees sign-in to access resources).
• Single sign-on (SSO).
• Application management.
• Business to Business (B2B).
• Business to Customer (B2C) identity services.
• Device management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Conditional Access

A
Used by Azure Active Directory to bring signals together, to make decisions, and enforce organizational policies.
• User or Group Membership
• IP Location
• Device
• Application
• Risk Detection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Role-Based Access Control (RBAC)

A
  • Fine-grained access management
  • Segregate duties within the team and grant only the amount of access to users that they need to perform their jobs
  • Enables access to the Azure portal and controlling access to resources
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Resource Locks

A

Protect your Azure resources from accidental deletion or modification. Manage locks at subscription, resource group, or individual resource levels within Azure Portal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Tags

A
  • Provides metadata for your Azure resources.
  • Logically organizes resources into a taxonomy.
  • Consists of a name-value pair.
  • Very useful for rolling up billing information.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Azure Policy

A

Helps to enforce organizational standards and to assess compliance at scale. Provides governance and resource consistency with regulatory compliance, security, cost, and management.
• Evaluates and identifies Azure resources that do not comply with your policies.
• Provides built-in policy and initiative definitions, under categories such as Storage, Networking, Compute, Security
Center, and Monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CanNotDelete Lock Type

A

Read - Yes
Update - Yes
Delete - No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

ReadOnly Lock Type

A

Read - Yes
Update - No
Delete - No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Azure Blueprints

A

• Makes it possible for development teams to rapidly build and stand up new environments.
• Development teams can quickly build trust through organizational compliance with a set of built-in components
(such as networking) in order to speed up development and delivery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Azure Blueprints Functionality

A
  • Role Assignments
  • Policy Assignments
  • Azure Resource Manager Templates
  • Resource Groups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Cloud Adoption Framework

A
  • Strategy – define biz justification and expected outcomes
  • Migrate – migrate and modernize existing workloads
  • Manage – operations mgmt. for cloud and hybrid solutions
  • Plan – align actionable adoption plans to biz outcomes
  • Innovate – develop new cloud-native or hybrid solutions
  • Ready – prepare the cloud environ for planned changes
  • Govern – govern environment and workloads
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Security

A

• Secure by design.
• With built in intelligent security, Microsoft helps to protect against known and unknown cyberthreats, using
automation and artificial intelligence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Privacy

A

Ensuring privacy through contractual agreements and by providing user control and transparency.

17
Q

Compliance

A

Respect local laws and regulations and provide comprehensive coverage of compliance offerings.

18
Q

Azure Sovereign Regions

A
  • US Govt - separate instance isolated from non-gov deployments. Only accessible to screened/auth personnel
  • China - all data stays in China to ensure compliance. Operated by 21Vianet.
19
Q

Compliance Offerings

A
  • CJIS
  • CSA STAR
  • EU Model Clauses
  • HIPPA
  • ISO/IEC 27018
  • NIST
20
Q

Microsoft Privacy Statement

A
  • What data is processed
  • How data is processed
  • What data is used for
21
Q

Online Services Terms

A

The licensing terms define the terms and conditions for the products and Online Services you purchase through
Microsoft Volume Licensing programs.

22
Q

Data Protection Addendum

A

The DPA sets forth the obligations, with respect to the processing and security of Customer Data and Personal Data, in
connection with the Online Services.

23
Q

What is on the Trust Center website?

A
  • In-depth, expert info
  • Curated list of recommended resources
  • Role-specific info for biz managers, administrators, engineers, risk assessors, privacy officers, and legal teams