Understand Security, Privacy, Compliance, & Trust Flashcards

1
Q

What is a Network Security Group (NSG)?

A

NSG is a regulatory mechanism that controls the communication amongs the N-tier loosely coupled architecture from low tier to high tier.

The Network Security Group feature is important because it only allows trusted communication between your different data layers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the Application Security Group (ASG)? **

A

Application Security Group provides protection by giving recommendations on a free tier, standard tier, and gives full-on monitoring service.

Detect Phase
Assess Phase
Diagnose Phase- containment strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Azure firewall?

A

Azure firewall protects the perimeter of the virtual network; cloud-based network security that establishes IP address boundaries & protects VN from the perimeter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Azure DDoS Protection?

A

DDoS are full-blown attacks on virtual machines that tries to overload load balancers with requests.

  • Basic DDoS Protection
  • Advanced DDoS protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is authentication?

A

Authentication is the process where the cloud provider gives an employee an identity in the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is authorization?

A

Authorization is when the employer gives the employee authorization or access to a set of resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Azure Active Directory (AD)?

A

AD is an “active directory” of already given prior authentication lists for people and it can sync with your already- made active directory for authentications and authorizations.

  • Azure AD gives:
  • MF Authentication
  • SSO (multiple environments)
  • Application Management
  • B2B Identity services
  • Device Management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is SSO?

A

SSO also called Single-Sign-On is part of the Azure Active Directory.

  • This decreases problems for Help Desk which gives more control to help desk by allowing a single password and username for multiple sign-in for different resources.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Azure Multi-Factor Authentication?

A

MFA is part of the Azure Directory list of resources:
- It gives authentication by the provider- so multi-factor authentication can be created:

3 questions asked here:

  • Something you know?
  • Something you possess?
  • Something you possess?

(pin code, thumbprint, mothers maiden name)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Azure Security Center?

A

Azure security center is similar to the applications security group

  • give DAD assessment
  • give recommendations on security measures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Azure Key Vault?

A

Azure Key Vault is a specialized application to store secrets via centralized cloud services.

Functions of Azure Key Vault:

  • Secrets Management
  • Key Management
  • Certification Management
  • Has hardware security modules
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Azure Information Protection?

A

AIP or Azure Information Protection helps organizations classify & optionally protect documents & emails by applying labels

  • Ex: word documents (you label as: all employees, confidential employees- X,Y,Z)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Azure Advanced Threat Protection?

A

Advanced Threat Protection (ATP) is cloud based security solution that identifies, detects, and helps you investigate ADVANCED THREATS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Azure Policy?

A

Policies created to ensure IT measures are met including:

  • SLA met for customers
  • allows for cost management
  • keeps your corporate standards in place on a smaller level than higher level
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Role-Based-Access- Control (RBAC)?

A

Role Based Access Control (RBAC) is what it sounds like. It gives authorization to a specific authenticated identity to have access to resource groups/ resources.

  • Also allowed through Azure Active Directory (AD)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Azure Resource Locks?

A

Azure Resource Locks are a setting that can be applied to any resource to block modifications or deletions of that resource.
- Delete Feature- delete will allow all operations against the resource but block the ability to delete
*this is good for
modifications

  • Read-Only- read- only feature will only allow you to read and no blocking or modifications
17
Q

What is Azure Advisor security assistance?

A

Azure Advisor provides high availability, security, performance, operational excellence, and cost improvement recommendations.

18
Q

What is Azure Blue Print?

A

Azure Blue Print is a tool that can replicate virtual environments.

-It can replicate: role assignments, policy assignments, resource groups, etc.

19
Q

What is Azure Monitor? **

A

Azure Monitor is an application on the Azure portal.

It collects, analyzes, and acts on telemetry from your cloud & on-premise environment. Monitors activity logs & metrics for your deployed apps with time stamps.

20
Q

What is Azure Service Health? **

A

Azure Service Health is a maintenance application that tracks milestone service objectives for your purchased applications and resources.

21
Q

What is the difference between Azure Monitor vs. Azure Service Health?

A

Azure Monitor= monitors resources for cost and efficiency

Azure Service Health= tracks and logs with reminders for service updates like a car that needs an oil change!

22
Q

What are GDPR, SIO, NIST?

A

These are government regulating organizations for IT to make sure that the terms of the provided conditions for cloud-providers are being met for the clients.

23
Q

What is the Microsoft Privacy Statement?*

A

The microsoft privacy statement states how personal data of clients are processed, what data is processed, and for what reasons.

24
Q

What is Microsoft Trust Center?*

A

The Microsoft Trust Center is a website resource containing information and details about how Microsoft implements and supports security, privacy, compliance, and transparency in all Microsoft cloud products.

25
Q

What is the Service Trust Portal? **

A

The Service Trust Portal is where you can find published external audit reports by 3rd parties to validate the extent of Microsoft’s Privacy Statement.

26
Q

What is compliance manager?

A

Compliance manager is a compliance tool for clients to see how well mircosoft are meeting their own privacy statements via monitors.

27
Q

What is Azure Government Cloud Services?

A

Azure government cloud services allows you to apply policies by root management group which is linked to all different groups.