Security Flashcards
what is Defense in Depth ?
multiple layers of security
physical, identity and access (AD), perimeter (DDOS), Network (virtual nw, filtering), Compute (VMs, DB), Gateways/Firewalls, Data (encrypted)
How is NW Connectivity secured ?
vNET firewall rules (hardware or software)
DDOS - one of most common attacks
Azure Protection Service - catches and mitigates (deflects from servers)
NSGs - personal firewall - specify set of rules per VM
ASG - focus security on application via logical application groups
What is Azure Security Center ?
threats portal with pre-defined set of rules (can create own) works on hybrid cloud each VM has agent policy compliance/scoring integrates with AWS, GCP raises alerts
What is Key Vault ?
password (Secret) storage
access to KV given to other applications
hosted on secure h/w, application isolation and capable of global scaling
can create has access policies
What is Azure Information Protection ?
secure data outside of company n/w
classify data (policies or manually)
track activities and safely share data
uses labels
What is Advanced Threat Protection ? (ATP)
monitors users and analyses behavioural activity
creates and reports against baseline behaviour
recommends best practice
How does ATP deal with Cyber Attack Kill Chain ?
deals with 3 stages :
- Recon (searching IPs, etc)
- Brute Force (guessing credentials)
- Increasing user privileges
What is Azure Sentinel ?
SIEM tool data collected and aggregated, analysed to take action behavioural analytics Integrates with AWS Cloud scaling
What are Azure Dedicated Hosts ?
own physical server on Azure h/w isolation at physical layer control over maintenance required for Compliance Allows OS of choice including BYOL Global infra. features come included - e.g. scale sets and Avail. zones