Module 7 - Configure Storage Security Flashcards

1
Q

Create shared access signatures

A

Never share you key as it will give them access to all the storage

Provides delegated access to resources

Grants access to cleints without sharing your storage keys

The accounts SAS delagtes access to resources in one or more of the storage services

The SAS dlagtes access to a resoyrce in just one storage serviecs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Identify URI and SAS parameters

A

A SAS is a signed URI that points to one or more storage resources

Consists of a storage resource URI and the SAS token

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Determine storage service encryption

A

You can use your own key

Protects your data for securtiy compliance

Auto enryots and decrtypys your data

Encrypted through 256 bit AES encryption

Is enabled for all new and existing storage accounts and connto be disabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Create customer managed keys

A

Use the Azure key vault to manage your encryption keys

Create your own encyption keys and store them in a key fault

Use azure key faults API to geneate encyption keys

Custom keys give you more flexibility and control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Apply Storage Secirty best practices

A

Always use HTTPS to create or distribute a SAS

Refence stored access policies where possible

Use near term expiration times on an ad hoc SAS

use storage analytics to monitor your application

Be careful with SAS start time

be specicfic with resource to be be accessed

Understand that your account will be billed for any usage

Validate data written using SAS

don’t assume SAS is always…

How well did you know this?
1
Not at all
2
3
4
5
Perfectly