Microsoft security solutions Flashcards

1
Q

Azure Bastion

A

You use TLS protocol to establish a connection to Azure Bastion from the Azure portal. From there, Bastion uses the RDP protocol to provide remote connectivity to the target VM

You do not need to install an agent. Bastion is agentless and does not require any additional software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Do you need to open the RDP port (3389) on the target VM with Azure Bastion?

A

Yes, you still need to open the RDP port on the target VMs.

The value add of Azure Bastion is you do not expose the RDP port of the target VMs outside of the virtual network since it lets you use Private IPs for those VMs.

Bastion will connect to target VMs over the Private IP, not the public IP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Azure DDoS Protection Standard

A

Does NOT protect against man-in-the-middle attacks
Is NOT enabled by default in an Azure subscription
It DOES protect against protocol attacks
The maximum number of resources that Azure DDoS Protection Standard can protect without additional cost is 100!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Microsoft 365 Defender

A

Unified enterprise defense suite that comprises of:
Microsoft Defender for Endpoint
Microsoft Defender for Office 365 (documents and emails)
Microsoft Defender for Identity
Microsoft Cloud App Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Microsoft Defender XDR

A

A unified pre-post brech enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Built-in security initiative in Microsoft Defender for Cloud

A

“Microsoft Cloud Security Benchmark” is a built-in security initiative that is automatically assigned when you enable Microsoft Defender for Cloud on your subscription

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Microsoft Defender for Endpoint

A

A unified endpoint platform for preventative protection, post-breach detection, automated investigation, and response.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Microsoft Intune

A

Intune, which is apart of Microsoft Endpoint Manager, provides the cloud infrastructure, the cloud-based mobile device management (MDM), cloud-based mobile application management, and cloud-based PC management for your organization

You manage Microsoft Intune by using the Microsoft Endpoint Manager admin center!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Microsoft Defender for Office 365

A

safeguards your organization against malicious threats posed by email messages, links (URLs), and collaboration tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Microsoft Defender for Identity

A

Uses Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Microsoft Defender for Cloud Apps

A

A comprehensive cross-SaaS solution that brings deep visibility, strong data controls, and enhanced threat protection to your cloud apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the minimun edition of Microsoft Entra ID needed to use Microsoft Entra Privilege Identity Management (PIM)?

A

Microsoft Entra ID P2. This is the only edition that provides PIM support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are types of distributed denial-of-service (DDoS) attacks?

A

Resource layer attackers, protocol attacks, and volumetric attacks are the most common DDoS attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which Azure featue provides network-level filtering, application-level filtering, and outbound SNAT?

A

Azure firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which Azure feature provides application-level filtering and SSL termination?

A

Azure Web Application Firewall (WAF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which three authentication methods does Hello for Business support?

A

Fringer print
Facial recognition
PIN

17
Q

Your organization has developed a line-of-business app that handles sensitive customer information. Your IT team installs an app on your smartphone (BYOD). Which is true?

A

Your IT team can remotely update thee office apps on your mobile devices
You can use your personal apps along with the business apps
If the device is stolen/lost, the IT team can erase just the business apps

Mobile Application Management enables this BYOD scenario, NOT MDM (Mobile Device Management)

18
Q

Which of the following Azure services can you deploy Azure Web Application Firewall with?

A

Azure Application Gateway
Azure Front Door
Azure Content Delivery Network (CDN) services

19
Q

Which of the following implements Azure Security Benchmark’s security recommendations on an individual Azure service?

A

Security baseline!
Security baseline can only be used on devices running Windows 10 version 1809 or later. No iOS or Android devices
Security benchmark contains security recommendatiosn grouped by the security control. They target specific technology