SC-100: Governance/Compliance Flashcards

(31 cards)

1
Q

Microsoft Defender for Cloud

A

Microsoft Defender for Cloud helps streamline the process for meeting regulatory compliance requirements using the regulatory compliance dashboard. Continuously assess your hybrid cloud environment to analyze the risk factors according to the controls you have applied.

Microsoft Cloud Security Benchmark is automatically assigned when onboarding Microsoft Defender for Cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Microsoft Defender for Cloud Paid Features

A

Attack Path analysis and Permissions Management are two Defender for Cloud capabilities that require a Defender paid plan.

Features included for free are:
Microsoft Secure Score
Multicloud coverage
Cloud Security Posture Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Microsoft Defender for Cloud PII

A

It can help you identify PII data at risk by scanning your Azure resources for misconfigurations and vulnerabilities that could expose PII data.

Provides a holistic view of your security posture, making it easier to identify and mitigate risks to PII data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Microsoft Defender Secure Score

A

Achievable Score: Displays the Secure Score that can be achieved based on Microsoft licenses and current risk acceptance.

Planned Score: shows the projected score when planned actions are selected

Current license score: Displays score that is currently achieved.

History: Shows the history of improvement actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Microsoft Defender for Cloud
Trusted Launch Feature

A

Trusted launch is integrated with Defender for Cloud to ensure that virtual machines are properly configured by remotely attesting that the virtual machine is booted in a healthy way.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Azure Policy (Part 1)

A

A service for defining and enforcing policies for cloud resources. It helps organizations maintain compliance by ensuring that resources in their Azure environment are configured and managed in accordance with company policies, industry standards, and regulatory requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Azure Policy (Part 2)

A

Identifies which resources are applicable, and then evaluates resources that have not been excluded or exempt. Policy assignments which append or deny effects are considered non-compliant for existing resources when the conditions of the policy rule evaluate to True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Azure Policy effects

A

Deny: prevents the deployment or modification of resources that do not comply with the policy

Append: Adds specific properties to a resource during deployment or modification if the resource does not have them.

Audit: creates a warning event in the activity log when a resource is non-compliant, but it does not prevent the deployment or modification

Disabled: this effect turns off the policy so it has no effect on resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Microsoft Priva

A

A suite of privacy management tools within Microsoft 365 designed to help organizations manage personal data, automate risk mitigation and manage subject rights requests, ultimately building trust with customers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Microsoft Priva capabilities

A

Priva capabilities are available through:

Priva Privacy Risk Management: Provides visibility into your organization’s data and policy templates for reducing risks.

Priva Subject Rights Request: Provides automation and workflow tools for fulfilling data requests.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Microsoft Priva
Privacy Risk Management

A

Helps you to set up policies that identify privacy risks in your Microsoft 365 environment and enable easy remediation. Policies are meant to be internal guides and can help you:

Detect overexposed personal data so that users can secure it

Spot and limit transfers of personal data across departments or regional borders.

Help users identify and reduces the amount of unused personal data that you store.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Microsoft Priva
Subject Rights Request

A

A solution designed to help alleviate the complexity and length of time involved in responding to data subject inquiries. Provides automation, insights and workflows to help organizations fulfill requests more confidently and efficiently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Microsoft Purview

A

A unifed suite of Compliance and Governance tools designed to help organizations understand, manage, and secure their data across on-prem, multi-cloud and SaaS environments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Microsoft Purview Compliance Manager

A

A tool for analyzing and managing compliance with regulatory standards. It provides a unified view of an organization’s compliance posture and helps prioritize actions to meet compliance requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Microsoft Purview Data Map

A

A cloud native platform as a service that captures metadata about enterprise data present in on-prem and cloud-based systems. Data Map is automatically kept up to date by using a built-in automated scanning and classification system.

17
Q

Microsoft Purview Data Catalog

A

Finds trusted data sources by browsing and searching your data assets. The Data Catalog aligns your assets with friendly business terms and data classification to identify data sources.

18
Q

Microsoft Purview
Data Estate Insight

A

Access Data Estate health

Gives you an overview of your data estate to help you discover what kinds of data you have and where it is.

19
Q

Microsoft Purview
Data Sharing

A

Allows you to securely share data internally or cross organizations with business partners and customers.

20
Q

Microsoft Purview
PII feature

A

Microsoft Purview can help you identify PII data across your Azure resources by scanning data sources like Azure Storage, Azure SQL Database, and Azure Data Lake Storage.

Purview provides a comprehensive view of your data estate, maing it easier to identify and protect PII data.

21
Q

Azure compliance tools

A

Microsoft Purview and its Compliance Manager
Microsoft Priva
Azure Policy
Microsoft Defender for Cloud

22
Q

5 disciplines of cloud governance

A

Cost management
Security baseline
Resource consistency
Identity baseline
Deployment acceleration

23
Q

Compliant Foundation in Azure

A

Azure compliance offerings are grouped into four segments:

Global
US Government
Industry
Region

24
Q

Microsoft Security Compliance Toolkit

A

A set of tools that allows enterprise security admins to download, analyze, test, edit and store Microsoft recommended security configuration baselines for Windows and other Microsoft products

Tools include:
Policy Analyzer
Local Group Policy Object
Set Object Security
GPO to policy rules

25
Data Loss Prevention (DLP)
It allows organizations to create policies that automatically detect sensitive data tyoes and take actions such as blocking access or notifying users.
26
Data Classification Content Explorer
Primarily a reporting tool rather than a proactive solution. It helps you review what has already been classified, but does not actively scan or classify data itself.
27
eDiscovery
Legal compliance tool used to search for and retrieve data relevant to legal cases or investigations.
28
Information Governance
Focuses on managing data lifecycle policies, retention and compliance but does not specifically target the identificaition of sensitive information
29
30
Azure Policy definition
Policy definitions define what compliance rules are
31
Azure Policy assignment
Azure Policy assignments are how policies are applied to specific scopes (subscriptions, resource groups, etc.). Updating the assignment allows you to exclude specific resource groups from the policy’s scope.