Security Flashcards

1
Q

what is Defense in Depth ?

A

multiple layers of security
physical, identity and access (AD), perimeter (DDOS), Network (virtual nw, filtering), Compute (VMs, DB), Gateways/Firewalls, Data (encrypted)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How is NW Connectivity secured ?

A

vNET firewall rules (hardware or software)
DDOS - one of most common attacks
Azure Protection Service - catches and mitigates (deflects from servers)
NSGs - personal firewall - specify set of rules per VM
ASG - focus security on application via logical application groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Azure Security Center ?

A
threats portal with pre-defined set of rules (can create own)
works on hybrid cloud 
each VM has agent
policy compliance/scoring
integrates with AWS, GCP
raises alerts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Key Vault ?

A

password (Secret) storage
access to KV given to other applications
hosted on secure h/w, application isolation and capable of global scaling
can create has access policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Azure Information Protection ?

A

secure data outside of company n/w
classify data (policies or manually)
track activities and safely share data
uses labels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Advanced Threat Protection ? (ATP)

A

monitors users and analyses behavioural activity
creates and reports against baseline behaviour
recommends best practice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does ATP deal with Cyber Attack Kill Chain ?

A

deals with 3 stages :

  1. Recon (searching IPs, etc)
  2. Brute Force (guessing credentials)
  3. Increasing user privileges
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Azure Sentinel ?

A
SIEM tool
data collected and aggregated, analysed to take action
behavioural analytics
Integrates with AWS 
Cloud scaling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are Azure Dedicated Hosts ?

A
own physical server on Azure
h/w isolation at physical layer
control over maintenance
required for Compliance
Allows OS of choice including BYOL
Global infra. features come included - e.g. scale sets and Avail. zones
How well did you know this?
1
Not at all
2
3
4
5
Perfectly