Microsoft security solutions Flashcards
Azure Bastion
You use TLS protocol to establish a connection to Azure Bastion from the Azure portal. From there, Bastion uses the RDP protocol to provide remote connectivity to the target VM
You do not need to install an agent. Bastion is agentless and does not require any additional software
Do you need to open the RDP port (3389) on the target VM with Azure Bastion?
Yes, you still need to open the RDP port on the target VMs.
The value add of Azure Bastion is you do not expose the RDP port of the target VMs outside of the virtual network since it lets you use Private IPs for those VMs.
Bastion will connect to target VMs over the Private IP, not the public IP
Azure DDoS Protection Standard
Does NOT protect against man-in-the-middle attacks
Is NOT enabled by default in an Azure subscription
It DOES protect against protocol attacks
The maximum number of resources that Azure DDoS Protection Standard can protect without additional cost is 100!
Microsoft 365 Defender
Unified enterprise defense suite that comprises of:
Microsoft Defender for Endpoint
Microsoft Defender for Office 365 (documents and emails)
Microsoft Defender for Identity
Microsoft Cloud App Security
Microsoft Defender XDR
A unified pre-post brech enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks
Built-in security initiative in Microsoft Defender for Cloud
“Microsoft Cloud Security Benchmark” is a built-in security initiative that is automatically assigned when you enable Microsoft Defender for Cloud on your subscription
Microsoft Defender for Endpoint
A unified endpoint platform for preventative protection, post-breach detection, automated investigation, and response.
Microsoft Intune
Intune, which is apart of Microsoft Endpoint Manager, provides the cloud infrastructure, the cloud-based mobile device management (MDM), cloud-based mobile application management, and cloud-based PC management for your organization
You manage Microsoft Intune by using the Microsoft Endpoint Manager admin center!
Microsoft Defender for Office 365
safeguards your organization against malicious threats posed by email messages, links (URLs), and collaboration tools
Microsoft Defender for Identity
Uses Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
Microsoft Defender for Cloud Apps
A comprehensive cross-SaaS solution that brings deep visibility, strong data controls, and enhanced threat protection to your cloud apps
What is the minimun edition of Microsoft Entra ID needed to use Microsoft Entra Privilege Identity Management (PIM)?
Microsoft Entra ID P2. This is the only edition that provides PIM support
What are types of distributed denial-of-service (DDoS) attacks?
Resource layer attackers, protocol attacks, and volumetric attacks are the most common DDoS attacks
Which Azure featue provides network-level filtering, application-level filtering, and outbound SNAT?
Azure firewall
Which Azure feature provides application-level filtering and SSL termination?
Azure Web Application Firewall (WAF)
Which three authentication methods does Hello for Business support?
Fringer print
Facial recognition
PIN
Your organization has developed a line-of-business app that handles sensitive customer information. Your IT team installs an app on your smartphone (BYOD). Which is true?
Your IT team can remotely update thee office apps on your mobile devices
You can use your personal apps along with the business apps
If the device is stolen/lost, the IT team can erase just the business apps
Mobile Application Management enables this BYOD scenario, NOT MDM (Mobile Device Management)
Which of the following Azure services can you deploy Azure Web Application Firewall with?
Azure Application Gateway
Azure Front Door
Azure Content Delivery Network (CDN) services
Which of the following implements Azure Security Benchmark’s security recommendations on an individual Azure service?
Security baseline!
Security baseline can only be used on devices running Windows 10 version 1809 or later. No iOS or Android devices
Security benchmark contains security recommendatiosn grouped by the security control. They target specific technology