Active Directory Flashcards

1
Q

What does Active Directory provide?

A

Single sign-on (SSO) and Multi-factor authentication (MFA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 4 pricing tiers for AD?

A

Free, Office 365 Apps, Premium P1, and Premium P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What pricing tier do you need to provide ‘Identity Protection’ and ‘Identity Governance’?

A

Premium P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the acronym RBAC stand for?

A

Role Based Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What 3 things to you need to specify when creating a role?

A

Security Principal, Role Definition, Scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name the different types of Service Principals

A

User, managed identity, service principal, group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How long are RBAC Activity Logs stored by default?

A

90 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the workaround for the RBAC activity log storage limitation?

A

Use Azure Event Hub

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How many RBAC Activity Log categories are there?

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

List the RBAC Activity Log categories

A

Administrative, Service Health, Resource Health, Alert, Autoscale, Recommendation, Security, Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 3 methods for achieving Hybrid Identity?

A

Password Hash Synchronisation (PHS), Pass-through authentication (PTA), Federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is PHS?

A

Password Hash Synchronisation. Sync the hash of the hashed password to Azure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is PTA?

A

Pass-through authentication. Use the same password as on-premise. Validates directly with On-premise AD. Password never stored on Azure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Federation Hybrid Identity?

A

Collections of domain trust each other for shared access of resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the acronym SAML stand for?

A

Security Assertion Markup Language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does the acronym MFA stand for?

A

Multi-Factor Authentication

17
Q

What types of MFA are there?

A

Password, SMS, Voice Call, Email, App, Security questions, App passwords, OAUTH hardware token

18
Q

What is Azure AD B2B used for?

A

To allow external partners access to Azure. No need for external accounts and passwords or syncing accounts. Invite guest user via email

19
Q

What is Azure AD B2C used for?

A

To control how customers use apps

20
Q

What identity methods are there for Azure B2C?

A

Identity Providers, Users, Other systems, Local Directory

21
Q

What is Self-service Password reset (SSPR)?

A

Allows users to reset their own passwords

22
Q

What SSPR functionality is provided in the BASIC AD license?

A

Only allows CLOUD USERS to reset their passwords

23
Q

What AD licenses provide full SSPR functionality?

A

AD Premium P1 and P2

24
Q

What is SAS used for?

A

Provided delegated access to Azure Resources with granular control

25
What are the 3 types of SAS for storage accounts?
User delegation SAS, Service SAS, Account SAS
26
What is User delegation SAS?
Use AD to create SAS
27
What resource is User Delegation SAS limited to?
Blob Storage
28
What is Service SAS?
Use Storage Account key to create SAS
29
What are the limitations of Service SAS?
Can only access ONE storage account type
30
What are the limitations of Account SAS?
Use the Account Key to create SAS
31
Are there any limitations to using Account SAS?
No. You can give access to one or more storage account types
32
What 3 benefits does Azure AD Identity Protection provide?
1) Get summary of flagged users and detected risk events. 2) Set risk-based conditional access policies 3) Get suggested vulnerabilities to act on