Storage Accounts Flashcards

1
Q

Storage Account authentication methods

A

-Access Keys
-Shared Access Signatures
-RBAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Storage Account Access Keys

A

-2x 512-bit kets
-access keys allow global access to all resources within the storage account (not good security practice)
-Use access leys sparingly
-The use of access keys violates the principle of least privilege
-access keys need to be diligently protected and rotated regularly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Share Access Signature (SAS)

A

-Authentication token
-Access parameters
-Resource location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Storage Account security

A

-All storage accounts and their containers (BLOB, files, VHDs) are encrypted using Storage System Encryption (SSE).
-Windows OS (that runs on top of a virutal hard disk that is transparently encrypted) can again encrypt the data using Azure Disk Encryption aka Bit Locker with the keys secured in Azure Key Vault.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly