Microsoft Certified: Azure Security Engineer Associate flashcards
142 free flashcards. Tap a card to flip it.
KQL 'project' Operator
Flip cardA Kusto Query Language (KQL) operator used to select a subset of columns, rename columns, or reorder columns in the query result.
- Essential for shaping query output to only relevant fields.
- Can be used with `project-away` to remove columns, or `project-rename` to rename.
- Improves readability and reduces data transfer size.
Memory trick: Project your desired Columns.
Microsoft Sentinel Automation Rules
Flip cardRules in Microsoft Sentinel that automatically execute actions on incidents or alerts based on predefined conditions.
- Automate incident triage, assignment, and closure.
- Can trigger playbooks for more complex automation.
- Help reduce alert fatigue and improve SOC efficiency.
Memory trick: Automation rules 'rule' over how incidents 'flow'.
Sentinel AKS Data Connector
Flip cardA dedicated data connector in Azure Sentinel designed to ingest a wide range of security events, logs, and metrics from Azure Kubernetes Service (AKS) clusters.
- Simplifies comprehensive data collection from AKS.
- Includes control plane, audit, node, and container logs.
- Integrates seamlessly with Log Analytics and Sentinel analytics.
Memory trick: AKS Connector is the Sentinel's Best Friend.
Azure Log Analytics Workspace
Flip cardAn Azure Log Analytics workspace is a unique environment in Azure Monitor used to collect, aggregate, and analyze log data from various sources using Kusto Query Language (KQL).
- Centralized log collection.
- Powerful KQL querying capabilities.
- Integrated with Azure Monitor and Microsoft Sentinel.
Memory trick: Log Analytics is the 'brain' for all your logs.
Azure Monitor Agent (AMA)
Flip cardA unified agent for Azure Monitor that collects a wide range of monitoring data from virtual machines and servers, offering enhanced capabilities and granular control.
- Replaces Log Analytics agent (MMA) and Azure Diagnostic Extension (ADE).
- Supports data collection from Azure VMs, Azure Arc-enabled servers, and on-premises servers.
- Uses Data Collection Rules (DCRs) for granular control over collected data.
Memory trick: Agents are like 'collectors' for your VM's 'story'.
Azure Policy DeployIfNotExists
Flip cardThe 'DeployIfNotExists' effect in Azure Policy automatically deploys a specified resource or template when a non-compliant resource is identified, ensuring compliance by adding missing configurations.
- Used for automated remediation.
- Deploys resources or configurations if they are missing.
- Requires a managed identity for deployment actions.
Memory trick: Audit reports, Deny stops, DeployIfNotExists adds, Modify changes.
Azure Policy
Flip cardA service in Azure that helps enforce organizational standards and assess compliance at scale.
- Defines rules for resource properties and configurations.
- Can audit, deny, or modify resources.
- Integrates with other Azure services like Defender for Cloud.
Memory trick: Azure Policy 'sets the rules' for your 'cloud kingdom'.
Defender for Cloud Regulatory Compliance
Flip cardThe Regulatory Compliance dashboard in Microsoft Defender for Cloud provides a centralized view of an organization's compliance posture against various industry standards and regulatory benchmarks. It assesses resource configurations and provides actionable recommendations to improve compliance.
- Monitors compliance against standards (e.g., PCI DSS, ISO 27001).
- Provides a compliance score.
- Offers detailed reports and recommendations.
- Integrates with Azure Policy for enforcement.
Memory trick: Regulate your cloud with a dashboard for compliance checks.
Sentinel Playbook
Flip cardAn automated, predefined response procedure in Microsoft Sentinel, powered by Azure Logic Apps, that can be triggered by alerts or incidents to perform remediation actions.
- Built using Azure Logic Apps.
- Executes automated actions like blocking users, isolating hosts, sending emails.
- Can be attached to analytics rules or run manually from incidents.
Memory trick: Playbooks Orchestrate the Security Dance.
Log Analytics for Security
Flip cardAzure Monitor Log Analytics workspaces serve as a central hub for collecting and analyzing operational and security logs from a wide array of Azure resources, hybrid environments, and other cloud providers. Its Kusto Query Language (KQL) enables powerful correlation and analysis for security investigations.
- Centralized log collection from diverse sources.
- Uses Kusto Query Language (KQL) for advanced querying.
- Essential for security investigations and threat hunting.
- Underpins services like Microsoft Sentinel and Defender for Cloud.
Memory trick: Log Analytics collects all logs for deep insight.
Microsoft Sentinel Playbooks
Flip cardAutomated procedures in Microsoft Sentinel that can be triggered by incidents or alerts to perform predefined actions.
- Enable Security Orchestration, Automation, and Response (SOAR) capabilities.
- Built on Azure Logic Apps.
- Can integrate with various services for actions like notifications, blocking IPs, or creating tickets.
Memory trick: Playbooks 'play' out your response automatically.
Azure Policy 'DeployIfNotExists' Effect
Flip cardAn Azure Policy effect that deploys a template when a condition is met (e.g., a resource is missing a required configuration) and the resource does not exist or is not compliant.
- Used for automatic remediation and configuration enforcement.
- Requires a deployment template (ARM template) within the policy definition.
- Ideal for ensuring baseline configurations like diagnostic settings or security features.
Memory trick: Policy's 'DeployIfNotExists' keeps configurations in line.
Log Alerts in Azure Monitor
Flip cardAzure Monitor log alerts use Kusto Query Language (KQL) to evaluate resources logs at a specified frequency. If the query results indicate a specific condition, an alert is triggered, notifying users or initiating automated actions.
- Uses KQL for flexible log pattern matching.
- Evaluates logs from Log Analytics workspaces.
- Can trigger alerts based on count, average, minimum, maximum, total, or unique count.
- Supports various action groups for notifications and automation.
Memory trick: Monitor your logs with KQL and alert rules to catch anomalies.
Azure Monitor Activity Log Alerts
Flip cardAlert rules in Azure Monitor that trigger based on events recorded in the Azure Activity Log, which tracks control plane operations.
- Monitors administrative operations (e.g., resource creation, deletion, updates).
- Can filter by resource, resource group, subscription, event level, caller, etc.
- Ideal for detecting unauthorized changes or critical administrative actions.
Memory trick: Alerts are like different 'sensors' for different 'events' in Azure.
Sentinel Playbooks for SOAR
Flip cardMicrosoft Sentinel Playbooks, powered by Azure Logic Apps, enable Security Orchestration, Automation, and Response (SOAR) by automating complex workflows, integrating with external systems, and performing actions based on incidents.
- Built on Azure Logic Apps.
- Automate incident response and enrichment.
- Connect to external services via connectors.
- Can be triggered by incidents or alerts.
Memory trick: Playbooks orchestrate complex 'plays' for SOAR.
Defender for Cloud Security Incidents
Flip cardA feature in Microsoft Defender for Cloud (and Sentinel) that groups related security alerts into a single, comprehensive view to facilitate investigation and response.
- Correlates alerts across different resources and services.
- Provides a timeline of events and affected entities.
- Often includes MITRE ATT&CK TTPs for context.
Memory trick: Incidents Provide the Full Attack Story.
Sentinel KQL Query Optimization
Flip cardThe process of improving Kusto Query Language (KQL) queries in Azure Sentinel analytics rules to enhance detection accuracy, reduce false positives, and improve performance.
- Involves adding specific filters, exclusions, or behavioral baselines.
- Aims to distinguish between legitimate activity and malicious behavior.
- Crucial for maintaining an effective and actionable SIEM.
Memory trick: Refine the KQL to Filter the Noise.
Log Search Alert Rule
Flip cardAn Azure Monitor alert rule that triggers based on the results of a Kusto Query Language (KQL) query run against log data in a Log Analytics workspace.
- Used for detecting patterns, specific events, or thresholds in log data.
- Requires a KQL query to define the alert condition.
- Can be configured with various aggregations and time windows.
Memory trick: MALAS: Metrics, Activity, Logs, Application, Security
Azure Policy for Security
Flip cardAzure Policy helps enforce organizational standards and assess compliance at scale. Through its compliance dashboard, it provides an aggregated view to evaluate the overall state of the environment, with the ability to drill down to the per-resource, per-policy, and per-assignment detail.
- Enforces organizational standards.
- Assesses compliance at scale.
- Integrates with Azure Security Center (Microsoft Defender for Cloud).
- Can prevent resource creation that violates policies.
Memory trick: Govern your cloud with a strict Azure Policy.
Defender for Cloud Tenant Onboarding
Flip cardOnboarding the Azure AD tenant root management group to Microsoft Defender for Cloud automatically enables monitoring and protection for all current and future subscriptions within that tenant.
- Provides tenant-wide visibility and control.
- Simplifies onboarding for large organizations.
- Ensures consistent security posture across all subscriptions.
Memory trick: The 'root' of your tenant secures the whole 'tree'.
Microsoft Defender for Cloud Security Posture Management
Flip cardA unified security management system that strengthens the security posture of cloud resources and provides advanced threat protection.
- Continuously assesses security configurations.
- Provides security recommendations based on benchmarks and standards.
- Offers a secure score to quantify security posture.
Memory trick: Defender for Cloud 'defends' your 'posture' by 'checking' everything.
Log Analytics Data Retention
Flip cardThe ability to configure how long different types of data are stored within an Azure Log Analytics workspace.
- Retention can be configured at the workspace level, applying to all data.
- Retention can also be configured per data type (table) for more granular control.
- Granular retention helps manage costs and meet compliance requirements.
Memory trick: Log Analytics lets you 'sort' your logs by how long they 'stay' in the 'pile'.
Azure AD PIM Just-in-Time Access
Flip cardAzure AD Privileged Identity Management (PIM) provides Just-in-Time (JIT) access to minimize the window of exposure for privileged roles. Users activate their roles on demand, for a specific duration, and their permissions are automatically revoked when the time expires.
- Grants temporary, time-bound access to privileged roles.
- Access is activated on demand by the user.
- Automatically revokes access after the specified duration.
- Supports multi-factor authentication (MFA) for activation and approval workflows.
Memory trick: PIM gives privileged roles just enough time.
Microsoft Sentinel AKS Connector
Flip cardThe Microsoft Sentinel Azure Kubernetes Service (AKS) data connector enables the ingestion of detailed AKS audit logs, control plane logs, and other security data into Sentinel for comprehensive threat detection and analysis.
- Collects audit logs from AKS control plane.
- Gathers security events from worker nodes.
- Provides deep visibility into containerized environments.
Memory trick: Each service has its own 'plug' for Sentinel.
Microsoft Defender for Cloud Alert Details
Flip cardThe alert details page within Microsoft Defender for Cloud provides a comprehensive breakdown of a specific security alert, offering context, affected resources, attack timeline, and recommended actions to facilitate investigation and response.
- Consolidates all relevant information for a single alert.
- Includes affected resources and related entities.
- Shows attack kill chain details.
- Provides recommended actions for remediation.
Memory trick: When an alert fires, dive into its details for the full story.
Azure Activity Log
Flip cardThe Azure Activity Log provides a record of control-plane events (operations on resources) that occur in Azure, including who, what, when, and where for any write or delete operation.
- Records all control-plane operations.
- Useful for auditing and troubleshooting resource changes.
- Can be queried, exported, and used to create alerts.
Memory trick: Activity Log shows 'who did what'.
Azure Monitor Metric Alerts
Flip cardAlert rules in Azure Monitor that trigger when a numerical metric (e.g., CPU, memory, network I/O) crosses a predefined threshold.
- Monitors resource performance and usage.
- Can use static thresholds or dynamic thresholds (machine learning).
- Supports various action groups for notifications and automation.
Memory trick: Alerts are like 'tripwires' for different 'events' or 'numbers'.
Azure AD Privileged Identity Management (PIM)
Flip cardAn Azure AD feature that allows for managing, controlling, and monitoring access to important resources in Azure AD, Azure, and other Microsoft Online Services.
- Enables just-in-time (JIT) privileged access.
- Provides time-bound access to roles, with automatic revocation.
- Supports approval workflows and audit trails for privileged operations.
Memory trick: PIM 'P'rotects 'I'dentity 'M'anagement with temporary keys.
Defender for Cloud Custom Compliance
Flip cardMicrosoft Defender for Cloud enables organizations to define and assess custom regulatory compliance standards by integrating custom Azure Policy initiatives directly into its compliance dashboard.
- Extends Defender for Cloud's compliance capabilities.
- Integrates custom Azure Policy initiatives.
- Provides unified reporting with built-in standards.
Memory trick: Custom standards let you 'write' your own rules.
Microsoft Defender for SQL
Flip cardMicrosoft Defender for SQL is a security offering within Microsoft Defender for Cloud that protects Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure Virtual Machines. It includes vulnerability assessment and advanced threat protection capabilities.
- Protects Azure SQL Database, Managed Instance, and SQL on VMs.
- Includes vulnerability assessment.
- Detects SQL injection, unusual access, and other threats.
- Provides actionable security alerts.
Memory trick: Each Defender plan protects a specific cloud treasure.
Sentinel Scheduled Query Rules
Flip cardScheduled query rules in Microsoft Sentinel enable security analysts to define custom detection logic using Kusto Query Language (KQL). These rules run periodically against ingested log data to identify specific patterns, anomalies, or correlated events across multiple data sources, generating security incidents when triggered.
- Uses KQL for custom detection logic.
- Runs on a defined schedule (e.g., every 5 minutes).
- Correlates events from various integrated data sources.
- Generates incidents for investigation.
Memory trick: Schedule your queries to find the hidden threats.
KQL project operator
Flip cardA Kusto Query Language operator used to select, rename, and reorder columns in the output of a query.
- Filters down to only the specified columns.
- Improves readability and performance by reducing result set size.
- Can be used to create new columns with simple expressions.
Memory trick: To 'project' a clear view, you 'cut' out the noise.
Log Analytics Centralization Challenges
Flip cardPotential difficulties encountered when consolidating log data from diverse, geographically dispersed Azure resources into a single Log Analytics workspace.
- Primary concern is data ingestion latency from distant regions.
- Can impact real-time monitoring and incident response.
- Cost considerations also exist but latency is often more critical for security.
Memory trick: Distance Delays Data Delivery.
Sentinel Multi-Workspace Architecture
Flip cardA multi-workspace architecture in Microsoft Sentinel involves deploying separate Log Analytics workspaces and Sentinel instances in different regions to satisfy data residency requirements. Azure Lighthouse can then be used to delegate management of these regional workspaces to a central Security Operations Center (SOC) for a consolidated incident view and centralized threat hunting without moving raw data.
- Ensures data residency per region.
- Uses separate Log Analytics workspaces and Sentinel instances.
- Azure Lighthouse enables delegated management across workspaces.
- Allows for centralized incident management and threat hunting.
Memory trick: Regional workspaces keep data local, Lighthouse gives a global view.
Defender for Cloud Exclusions
Flip cardMicrosoft Defender for Cloud allows users to exclude specific resources or security recommendations from their security policies. This feature is crucial for maintaining an accurate secure score when recommendations are addressed by external means, are not applicable, or have compensating controls in place.
- Prevents specific recommendations from impacting secure score.
- Can exclude resources, recommendations, or both.
- Useful for compensating controls or third-party solutions.
- Helps focus on actionable and relevant recommendations.
Memory trick: Exclude the noise to focus on the score.
Azure Monitor Log Search Alerts
Flip cardAzure Monitor Log Search Alerts trigger when the results of a scheduled Kusto Query Language (KQL) query against Log Analytics data meet a specified condition, such as a count exceeding a threshold.
- Queries log data in Log Analytics workspaces.
- Uses KQL for flexible and powerful query conditions.
- Ideal for detecting specific events, patterns, or trends in logs.
Memory trick: Logs are for searching, metrics are for measuring, activity is for actions, health is for service.
Defender for Cloud Compliance Details
Flip cardA feature within Microsoft Defender for Cloud that provides granular information on why a resource is non-compliant with a specific security policy or initiative.
- Shows specific assessment results against policy definitions.
- Helps in diagnosing the root cause of non-compliance.
- Often includes recommended remediation steps.
Memory trick: Compliance Details Reveal the Policy's Secrets.
Azure Policy Definition
Flip cardAn Azure Policy definition is a JSON-based rule that specifies the conditions under which a policy is enforced and the effect that takes place if those conditions are met.
- Defines the 'what' of the policy.
- Contains the policy rules, parameters, and effect.
- Can be custom-created or used from built-in definitions.
Memory trick: Definition is the 'rule', initiative is the 'book of rules', assignment is 'where' to apply the book.
Microsoft Sentinel (Azure Sentinel)
Flip cardA cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.
- Collects security data from diverse sources
- Uses AI and machine learning for threat detection
- Offers incident management and automated response capabilities
Memory trick: SOC's eyes on all Azure threats, Sentinel guides their insights.
Azure Disk Encryption (ADE)
Flip cardA capability that helps encrypt the OS and data disks used by Azure Virtual Machines. It uses industry-standard encryption technology and integrates with Azure Key Vault to manage encryption keys.
- Encrypts both OS and data disks.
- Uses BitLocker (Windows) and DM-Crypt (Linux).
- Key management is handled by Azure Key Vault.
Memory trick: ADE makes sure your disks are locked, and Key Vault holds the key.
Azure Front Door WAF Geo-filtering
Flip cardAzure Front Door's WAF geo-filtering capability allows you to control access to your web applications based on the client's geographical location or country of origin.
- Part of Azure Front Door's Web Application Firewall (WAF).
- Allows defining allow or block rules based on country/region codes.
- Crucial for compliance with data residency and access restrictions.
- Can be configured as a custom WAF rule condition.
Memory trick: To filter by land, use 'Geo-filtering' to understand the client's stand.
Azure Key Vault for Application Secrets
Flip cardAzure Key Vault provides a secure, centralized store for application secrets like connection strings, API keys, and passwords, protecting them from unauthorized access.
- Eliminates the need to hardcode secrets in application code.
- Integrates with Azure AD for identity-based access control.
- Supports secret versioning and soft-delete.
- Used by Azure App Service, Azure Functions, VMs, and other services.
Memory trick: Keep your app's secrets in the 'Key Vault' to keep them safe and sound.
Key Vault Certificate Management
Flip cardAzure Key Vault provides a secure way to store and manage X.509 certificates, including those issued by custom Certificate Authorities, enabling their use by Azure applications.
- Supports importing certificates with private keys.
- Integrates with Azure services for certificate consumption.
- Manages certificate lifecycle (renewal, expiration alerts).
- Provides secure, centralized storage for certificates.
Memory trick: Key Vault: Your custom certs' secure home in the cloud.
Defender for Cloud for ACR
Flip cardMicrosoft Defender for Cloud, with its Defender for Containers plan, provides vulnerability assessment and threat protection for container images stored in Azure Container Registry.
- Scans images for vulnerabilities upon push to ACR.
- Provides continuous assessment of images.
- Integrates with Azure Container Registry.
- Offers security recommendations and alerts.
Memory trick: Defender for Cloud: Your image's security scanner in the registry.
Azure Application Gateway WAF
Flip cardA web application firewall (WAF) that protects web applications from common web-based attacks. It's integrated with Azure Application Gateway, providing Layer 7 load balancing and security.
- Protects against OWASP Top 10 vulnerabilities.
- Operates at Layer 7 (HTTP/HTTPS).
- Can be deployed with custom WAF rules and managed rule sets.
Memory trick: WAF is the bouncer for your web app, keeping bad requests out.
Azure Policy 'Deny' Effect
Flip cardThe 'Deny' effect in Azure Policy prevents a resource request from succeeding if it doesn't meet the policy definition, ensuring strict compliance at creation or update.
- Prevents non-compliant resource deployments or updates.
- Returns a 403 Forbidden error.
- Used for strict governance where non-compliance is unacceptable.
- One of several effects that can be assigned to a policy definition.
Memory trick: Policies can Audit, Deny, Deploy, or Modify, but 'Deny' means 'NO'.
Hyper-V Isolation for Containers
Flip cardA container isolation mode where containers run inside highly optimized virtual machines, providing strong hardware-based isolation from the host and other containers.
- Offers strongest isolation for containers.
- Each container gets its own lightweight VM.
- Protects against host kernel exploits and side-channel attacks.
Memory trick: Hyper-V isolation puts each container in its own secure bubble.
Azure Firewall
Flip cardAzure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources with stateful inspection, built-in threat intelligence, and centralized policy management.
- Stateful firewall as a service.
- Built-in high availability and scalability.
- Supports Application, Network, and FQDN Tag rules.
- Includes SNAT and DNAT capabilities.
Memory trick: Azure Firewall: The VNet's smart gatekeeper, knowing who's who.
Microsoft Defender for Containers (ACR)
Flip cardMicrosoft Defender for Containers (part of Defender for Cloud) provides vulnerability scanning for images stored in Azure Container Registry, offering continuous assessment and threat protection.
- Scans images for vulnerabilities upon push and continuously.
- Integrates with Qualys for vulnerability assessment.
- Generates security recommendations and alerts.
- Protects images in ACR, running AKS clusters, and Azure Container Instances.
Memory trick: To defend my containers, I need a 'Defender' to scan their images.
Kubernetes Network Policies
Flip cardA specification of how groups of pods are allowed to communicate with each other and with other network endpoints. Network Policies are implemented by a network plugin.
- Control ingress and egress traffic for pods.
- Based on labels and namespaces.
- Allows micro-segmentation within a Kubernetes cluster.
Memory trick: Network Policies are the traffic cops for your pods.
Azure Private Link
Flip cardA service that enables you to access Azure PaaS services (for example, Azure Storage and Azure SQL Database) and Azure-hosted customer/partner services over a private endpoint in your virtual network.
- Traffic remains on the Microsoft Azure backbone network.
- Eliminates data exposure to the public internet.
- Simplifies network architecture by keeping traffic within your VNet.
Memory trick: Private Link is your secret tunnel to Azure services.
Azure Firewall for VNet Segmentation
Flip cardAzure Firewall is a managed, cloud-based network security service that provides centralized, stateful firewall capabilities to protect Azure Virtual Network resources, offering granular control over inbound and outbound network traffic.
- Stateful firewall as a service.
- Supports VNet-to-VNet and VNet-to-Internet filtering.
- Provides FQDN filtering for outbound traffic.
- Offers centralized management and logging.
Memory trick: Firewall Filters All VNet Traffic Deeply.
Microsoft Defender for Cloud (Server Protection)
Flip cardA comprehensive cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that helps secure Azure, on-premises, and multi-cloud resources.
- Provides threat protection and vulnerability management.
- Includes antimalware, file integrity monitoring, and adaptive application controls.
- Offers recommendations to improve security posture across hybrid environments.
Memory trick: Defender for Cloud guards your VMs like a loyal knight.
Network Security Groups (NSGs)
Flip cardNetwork Security Groups (NSGs) are an Azure networking feature that allows you to filter network traffic to and from Azure resources in an Azure Virtual Network, using security rules.
- Filter traffic at Layer 4 (TCP/UDP ports).
- Can be associated with subnets or individual network interfaces.
- Rules are evaluated by priority, with lower numbers having higher priority.
- Default rules exist to allow/deny certain traffic.
Memory trick: NSG: The security guard for your subnet's doorstep.
Azure Firewall Premium
Flip cardAzure Firewall Premium is a cloud-native, intelligent network firewall security service that provides advanced threat protection for your cloud workloads.
- Includes IDPS (Intrusion Detection and Prevention System) for deep packet inspection.
- Supports TLS inspection for encrypted traffic.
- Offers FQDN (Fully Qualified Domain Name) filtering for outbound traffic.
- Integrates with Microsoft Threat Intelligence for enhanced protection.
Memory trick: For the toughest network security, 'Firewall Premium' inspects and defends with precision.
Azure Key Vault for Secrets
Flip cardAzure Key Vault provides a secure and centralized service for storing and managing access to secrets, keys, and certificates used by cloud applications and services.
- Protects cryptographic keys and secrets used by cloud applications and services.
- Supports hardware security modules (HSMs) for enhanced protection.
- Enables automatic rotation of secrets and certificates.
- Integrates with Azure AD for access control.
Memory trick: Keep your keys in the vault, safe and rotating.
Defender for Containers (AKS)
Flip cardMicrosoft Defender for Containers provides cloud-native security for containerized workloads, including vulnerability scanning of images in registries and runtime protection for Azure Kubernetes Service (AKS) clusters, with capabilities like admission control.
- Scans container images for vulnerabilities.
- Provides runtime protection for AKS clusters.
- Can block deployments with admission control.
- Integrates with Azure Container Registry and AKS.
Memory trick: Containers Need Vigilant Defense.
Azure Key Vault
Flip cardA cloud service for securely storing and accessing secrets, keys, and certificates. It helps protect cryptographic keys and other secrets used by cloud applications and services.
- Centralized secret management.
- Hardware Security Module (HSM) protected keys.
- Integration with other Azure services for secure access.
Memory trick: Keys in the Vault keep secrets safe and sound.
Azure Policy for Compliance
Flip cardAzure Policy is a service in Azure that you use to create, assign, and manage policies that enforce rules and effects over your resources to stay compliant with organizational standards.
- Enforces organizational standards and assesses compliance.
- Can audit, deny, or modify resource deployments.
- Used for governance, security, and cost management.
- Policies can be applied at subscription or resource group scope.
Memory trick: For rules and compliance, Azure Policy is the governing hand.
App Service VNet Integration (Gateway required)
Flip cardA feature that allows an Azure App Service app to access resources in an Azure Virtual Network, routing all outbound traffic through the VNet's gateway for static egress IP addresses.
- Enables App Service to access resources in a VNet.
- Gateway required routing forces all outbound traffic through the VNet gateway.
- Provides a static, known outbound IP address for App Service.
Memory trick: App Service wants to go home, but needs a fixed address to get through the gate.