Skill 2.1 Secure Storage Flashcards

1
Q

How are storage accounts managed

A

through Azure resource manager, Mangement operations are authenticated and authroized using Azure Active directory and RBAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How are storage account services exposed

A

as a interent facing endpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does a storage firewall do

A

allows you to limit access to specific IP addresses or a range

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What route do service endpoints create

A

a direct network route from the virtual network to the endpoitn

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the two steps to configure service endpoints

A
  1. From the virtual network subnet create the route from the subnet to the storage service but does not restrict which storage account the virtual network can use
  2. Configuring which virtual networks can access a particular storage account.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe blob storage access levels

A

by default no public read access is enabled for anonymous users, and only users with rights granted through RBAC or with the storage account name and key will have access to the stored blobs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are blob storage access levels,

A

Private – With this option only the stroage account owber can access the container and its blobs
Blob – with this optio nonly blobs within the container can be accessed anonymously
Container – blobs and there containers can be access anonymously

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Shared Access Signature Token (SAS Token)

A

URI query string parameter that grans access to specific containers, blobs, queues, and tables. Used to grant access to a client that should not have access to the entire storage account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How do SAS tokens grant access to resources

A

for a specific period of time with a specified set of instruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are SAS tokens widely used for

A

to copy blobs or files to another storage account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What protocol do SAS tokens use

A

HTTPS protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are blob

A

Provides a highly scalable service for storing abitrary data such as text or binary data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the three types of blobs

A

Append Blobs
Block Blobs
Page Blobs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are storage account service tables

A

Provides a NoSQL-style store for storing structured data. Unlike a relational database, tables in Azure storage do not require a fixed schema, so different entries in the same table can have different fields

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are storage account Queues

A

Provide a reliable message queueing between applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are storage account files

A

Managed files shares that can be used by either Azure VM or on-prem servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What Storage Account Service Disks do

A

Provides a persistent volume for Azure VM which can be attached as a virtual hard disk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the rules for naming storage accounts

A

Storage account name must be unique across all existing storage account names in Azure
Must be between 3 and 24 characters adn can contain only lowercase letters and numbers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is a standard performance tier

A

Supports all storage services. Blobs, tables files, queues, and unmanged Azure virtual machine disks. Uses magnetic disks to provide cost-efficient and reliable storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the premium performance tier

A

Designed to support workloads with gratr demand on I/O and is backed by high performance SSDS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What kind of storage is supported by the standard account tier

A

General purpose v1 and V2 and blob

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What kind of storage is supported by Premium tier

A

General-Purpose V1 and V2, BlockBlobStorage and FileStorage

23
Q

What is a Blob storage account

A

specialized storage account used to store block blobs and append blobs. Page blobs cannot be stored in this account

24
Q

What account types can be upgraded to General-Purpose V2

A

General-Purpose V2 and Blob storage though the process can’t be reversed.

25
Q

What feature does a General-Purpose V2 Account support

A

Supports blob, File, table, and queue, suppors unmanged disk, standard and performance tiers.
Supports Hot, Cool, and ARchive Access

26
Q

What features does General Purpose V1 Support have

A

Supports Blob, File, Table, and Queue, and unmanaged disk access
Standard and Performance Tiers, N/A for supported access tiers.

27
Q

What features does blob storage support have

A

Supports blob, block and append blobs only. No unmanaged disk support.
Standard performance tierW

28
Q

What features does blob block storage have

A

Supports blob, block adn append blobs only. No unmanaged disk support. Premium performance tier. N/A for access tiers

29
Q

What features does the file storage tier have

A

Supports only file service. No unmanaged disk support. Supports the premium performance tier

30
Q

What is locally redundant storage (LRS)

A

Three synchronous copies of data within a single datacenter. Available for general-purpose or blob storage accounts at both the standard and performance tier

31
Q

What is Zone Redundant Storage (ZRS)

A

Make three synchronous copies to three seperate availability zones within a region. Available for General Purpose V2 storage accounts only.

32
Q

What is geographically redundant storage (GRS)

A

Same as LRS (three local copies), plus three additional asynchronous copies to a second data center hundreds of miles away from the primary region. Data replication typically occurs within 15 minutes although no SLA is provided

33
Q

Read Access GRS

A

Same capabilities as GRS, plus you have read-only access to teh data in teh secondary data center.

34
Q

What are the Azure blob storage tiers

A

Hot
Cool
Archive

35
Q

Describe the blob Cool Storage Tier

A

Data is stored for at least 30 days

36
Q

Describe the Archive blob storage tier

A

Long-term storage, Will remain for 180 days.

37
Q

What storage type is User delegation through Azure AD available with

A

Blob storage

38
Q

What allows you to change the access parameters (start and end time, permissions) as part of the token.

A

Stored access policies, Allows for modifying of access of existing tokens without having to reissue them

39
Q

How many stored access policies can you have on a container, table, queue, or file share

A

five

40
Q

What are access keys used for

A

Allow full access to all data in all service within the storage account. You can create, read, update, and delete container, blobs, tables, queues, and file shares. You will have full administrative access to everything other then the storage account itself

41
Q

What are access keys used with

A

the storage account name and an access key

42
Q

What does rolling a storage account access key do

A

invalidate any SAS tokens that were generated using that key

43
Q

What does Azure key vault do

A

helps safeguard storage account access keys as well as cryptographic keys and secrets used by cloud applications and services such as authentication keys

44
Q

What is AAD authentication

A

recently addes authorization mechanism for Azure Storage.

45
Q

What authentication do accounts created with Azure Resource Manager use

A

authentication Azure AD authorization

46
Q

what can SAS signatures be signed by

A

Azure AD credentials to provide access to storage accounts

47
Q

What is a managed service identity (MSI)

A

Can be used for access blobs or queues from an Azure entity like Azure VM, virtual machine scale set, or an Azure functions app

48
Q

What is a container RBAC resource role scope

A

All blobs inside the container, the container properties, and the metadata will inherit the role assignment when this scope is selected

49
Q

What is a Queue RBAC resource role

A

All the messages inside the queue, as well as queue properties and metadata will inherit the role assignment when this scope is selected

50
Q

What is a Storage account RBAC resource scope

A

Under this scope, the role assignment will be applicable at the storage account level. All the containers, blobs, queues, and messages within the storage account will inherit the role assignment when this scope is selected

51
Q

What are the two types of Azure identity authentication

A

On premesis Active Directory Domain Services (AD DS)
Azure Active directory Domain services (Azure AD DS)

52
Q

What must be used to access Azure files by using SAS

A

You must use the REST method

53
Q
A