Stoage Account Authorization Flashcards

1
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

With Shared Access Key Authorization, how many access keys are created by default?

A

Two Default keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What kind of access does having a Shared Access Key to a Storage Account grant you?

A

Gives access to your entire storage account, basically root/admin access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where does Microsoft recommend for storing your Shared Access Keys?

A

Azure Key Vault

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What types of Shared Access Signatures (SAS) does Azure support?

A
  • User Delegation
  • Service
  • Account
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is User Delegation SAS?

A

A user delegation SAS is secured with Azure Active Directory (Azure AD) credentials and also by the permissions specified for the SAS. A user delegation SAS applies to Blob storage only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Service SAS?

A

A service SAS is secured with the storage account key. A service SAS delegates access to a resource in only one of the Azure Storage services: Blob storage, Queue storage, Table storage, or Azure Files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Account SAS?

A

An account SAS is secured with the storage account key. An account SAS delegates access to resources in one or more of the storage services.

All the operations available via a service or user delegation SAS are also available via an account SAS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Azure AD Storage Authorization

A

Uses Azure AD to authorize requests to blob and queue data.

You can use Azure role-based access control (RBAC) to grant permissions to a security principal, which may be a user, group, or application service principal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In Azure AD Storage Authentication, what two sets of permissions are needed for a Service Principal to access storage resources?

A
  • Data Layer Permissions
  • Management Permissions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

With the Layered Security Model, what rules can you limit access to storage accounts?

(Firewalls and Virtual Networks)

A
  • Limit by Subnets in Azure vNets
  • Limit by IP addressees
  • Limit by IP ranges
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When limiting access to Storage Accounts through with firewalls or virtual networks, is Authorization still required, or can it be optional?

A

Authorization is still required with Azure AD, Account Access Key or SAS token.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly