Skill 4.2 Flashcards

1
Q

Network Security Groups (NSG)

A

Allows you to control which network flows are permitted into and out of your virtual networks and virtual mahcines. It’s a standalone Azure resource, which acts as a networking filter. Each NSG contains a list of security rules that are used to allow or deny inbound traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are NSGs associated with

A

a subnet or with specific VMs network interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How are NSGs enforced

A

By priority with values ranging from 100 to 4096

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a NSG service tag

A

Platform-defined shortcuts that map to the IP ranges of various Azure Services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are service tags used for in NSG rules

A

As a quick and reliable way of creating rules that control traffic to each service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the default NSG rules

A

Virtual Network – traffic originating and ending in a virtual network is allows both inbound and outbound
Internet – Outbound traffic is allows but inbound traffic is block
Load Balancer – Allows the Azure health balancer to probe the health of you VMs and role instances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are application security groups (ASG)

A

Offer an approach to network segmentation. They allow you to achieve the same goal of segmenting you application into seperate tiers and they strictly control the permitted network flows between tiers. You explicitly define which application tier each VM belongs to rather than implicitly defining which application tier each VM eblongs to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What do NSG rules define

A

the permitted traffic flows between application tiers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the steps to configure an ASG

A

Create an application security group resource for each server. This resource has no properties other than its name resource group and location
Associate the network interface from each BM with the appropriate ASG
Define you network security group rules using ASG names instead of explicit IP ranges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Does NSG define rules for
IAAS
PAAS
SAAS

A

IAAs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How many NSG can each nic or subnet be associated to

A

one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define Effective Security Rules View

A

designed to provide insight to drill into each NSG rule and see the exact list of source adn desitnation IP prefices that have been applied regardless of how the NSG rule was defined

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Azure Firewall

A

A managed service that provides out-of-the-box network security for Azure resources. It is highly available and scalable.
Provides an ability to limit the outbound IP addresses and ports that are allowed to communicate within the Azure Subnet. Provides outbound SNAT support, Inbound DNAT support, and Azure Monitor Logging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the standard deployment model for Azure Firewall

A

Hub and Spoke where the firewall is hosted on its own VNET and other resources are placed in peered VNets in the same region with one or more subnets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Where must Azure Firewall be hosted

A

IN a subnet named AzureFirewallSubnet with a minimum /26 address space for the Azure firewall to provision more VMs for scaling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is alowed by Azure Firewall by default

A

infrastructure FQDNs which can be overridden by creating a deny all applications rule collection

17
Q

What is Azure Bastion

A

provides secure connections to Azure Virtual Machines using SSL channel through a browser directly without any external client using port 443

18
Q
A