Microsoft Certified: Azure Security Engineer Associate flashcards
142 free flashcards. Tap a card to flip it.
Azure Container Instances Hyper-V Isolation
Flip cardHyper-V isolation for Azure Container Instances runs each container within its own dedicated, lightweight Hyper-V virtual machine, providing strong kernel-level isolation from other containers and the host.
- Offers the strongest isolation for Windows containers (and some Linux).
- Each container group runs in its own dedicated Hyper-V VM.
- Prevents kernel-level exploits from affecting other containers or the host.
- Important for multi-tenant environments with sensitive workloads.
Memory trick: For ultimate container security, 'Hyper-V' creates a private VM fortress.
Microsoft Defender for Servers
Flip cardMicrosoft Defender for Servers is a cloud-native solution providing comprehensive protection for your Windows and Linux machines across Azure, hybrid, and multi-cloud environments.
- Part of Microsoft Defender for Cloud.
- Includes endpoint detection and response (EDR) capabilities.
- Provides vulnerability assessment and recommendations.
- Enables Just-in-Time (JIT) VM access to reduce attack surface.
Memory trick: To defend my server, I need a 'Defender' to protect, scan, and guard access.
Microsoft Defender for Cloud
Flip cardMicrosoft Defender for Cloud is a unified infrastructure security management system that strengthens the security posture of your cloud workloads and provides advanced threat protection.
- Continuously assesses security posture.
- Provides security recommendations.
- Detects threats and generates security alerts.
- Supports hybrid cloud environments.
Memory trick: Defender for Cloud: Your VM's security guard, always watching.
Key Vault Certificate Management with Custom CA
Flip cardAzure Key Vault can integrate with an organization's existing Certificate Authority (CA) to automate the enrollment, renewal, and deployment of certificates for Azure services and applications.
- Supports integration with various CAs (e.g., DigiCert, GlobalSign, or custom CAs).
- Automates certificate lifecycle from issuance to renewal.
- Securely stores certificate private keys within Key Vault.
Memory trick: Key Vault is your certificate's personal assistant, even with custom CAs.
Hyper-V Isolation for ACI
Flip cardHyper-V isolation for Azure Container Instances (ACI) provides the strongest level of isolation for Windows containers by running each container in a dedicated, lightweight Hyper-V virtual machine.
- Offers full kernel isolation from the host and other containers.
- Suitable for multi-tenant environments and sensitive workloads.
- Ensures no shared kernel vulnerabilities with other containers.
- Primarily used for Windows containers on ACI.
Memory trick: Hyper-V: Each container gets its own fortified mini-VM.
Azure Managed Identities
Flip cardAutomatically managed identities in Azure Active Directory that Azure services can use to authenticate to cloud services without managing credentials.
- Eliminates hardcoding credentials.
- Two types: system-assigned and user-assigned.
- Azure manages the identity lifecycle and secret rotation.
Memory trick: Managed Identity is like having a trusted valet for your Azure resources' credentials.
Azure AD Managed Identities
Flip cardAutomatically managed identities in Azure AD for Azure services, eliminating the need for developers to manage credentials.
- No credentials in code.
- Two types: System-assigned and User-assigned.
- Integrates with Azure AD authentication for services.
Memory trick: Managed Identity: Machines Manage Identity.
SAML Claims Mapping
Flip cardThe process of configuring which attributes from Azure AD user profiles are included as claims in the SAML token sent to a service provider (SaaS application) during single sign-on.
- Crucial for passing user data to applications.
- Configured within the enterprise application's SSO settings.
- Allows mapping Azure AD attributes to custom SAML claim names.
Memory trick: SAML claims mapping is like packing a custom lunchbox of user info for the app.
SCIM (System for Cross-domain Identity Management)
Flip cardAn open standard protocol for automating the exchange of user and group identity information between identity domains or cloud applications.
- Used for automated provisioning and deprovisioning.
- Simplifies identity lifecycle management.
- Reduces manual administration and human error.
Memory trick: SCIM is for 'Synchronizing' 'Cloud' 'Identities' 'Magically'.
Workload Identity Federation
Flip cardWorkload Identity Federation allows workloads (like Azure DevOps pipelines, Kubernetes pods) to authenticate with Azure AD and access Azure resources without needing to manage secrets or certificates. It uses an OpenID Connect (OIDC) federation between the workload and Azure AD.
- Eliminates the need for client secrets.
- Enhances security by removing long-lived credentials.
- Leverages OpenID Connect (OIDC) for trust establishment.
- Suitable for CI/CD pipelines and external platforms.
Memory trick: Federated Workloads: No Secrets, Just Trust.
Azure Management Groups
Flip cardContainers that help you manage access, policy, and compliance across multiple Azure subscriptions, providing a level of organization above subscriptions.
- Form a hierarchy to organize subscriptions.
- Allow application of policies and RBAC roles that inherit down.
- Enable centralized governance for large-scale Azure deployments.
Memory trick: Management Groups are the organizational trees for your Azure subscriptions.
Azure AD Application Proxy
Flip cardA service that provides secure remote access to on-premises web applications, allowing users to access them from outside the corporate network using their Azure AD credentials.
- Acts as a reverse proxy.
- Supports IWA, header-based, and form-based authentication.
- No VPN required for external users.
Memory trick: Application Proxy is your secure bridge to on-prem apps from the outside world.
Azure RBAC Least Privilege
Flip cardAssigning only the necessary permissions (role) at the narrowest possible scope to perform a task.
- Roles define what actions can be performed (e.g., Reader, Contributor, Owner).
- Scopes define where the permissions apply (e.g., management group, subscription, resource group, resource).
- Combining the right role with the right scope is crucial for security.
Memory trick: Give the right key to the right map, no more.
Azure AD Administrative Units (AUs)
Flip cardContainers for users and groups that allow for more granular delegation of administrative roles in Azure AD.
- Scopes administrative roles to a subset of users/groups.
- Prevents broad administrative access.
- Supports roles like User Admin, Password Admin, Group Admin.
Memory trick: Admin Units: Administer Unique Sections.
Conditional Access Authentication Strength
Flip cardA feature within Azure AD Conditional Access that allows administrators to specify the strength of authentication required for specific resources or scenarios.
- Enforces specific MFA methods (e.g., FIDO2, Windows Hello for Business).
- Provides granular control over authentication requirements.
- Integrates with Conditional Access policies to secure access.
Memory trick: Conditions dictate the keys to every app's door.
Conditional Access: Location & Sign-in Frequency
Flip cardAzure AD Conditional Access policies allow granular control over resource access. The location condition restricts access based on IP ranges, while the sign-in frequency session control mandates re-authentication (including MFA) after a defined period, even if other sessions are active.
- Location condition: Defines trusted IP ranges for access.
- Sign-in frequency: Controls how often users must re-authenticate.
- Crucial for high-security applications requiring continuous validation.
- Overrides default session behavior like persistent browser sessions.
Memory trick: Location Lock, Frequent Login for Sensitive Secrets.
Managed Identities for Azure Resources
Flip cardManaged Identities provide an identity for Azure services to use when connecting to resources that support Azure AD authentication. This eliminates the need for developers to manage credentials by allowing Azure to manage the lifecycle of the identity.
- Automatically managed by Azure.
- Removes the need for developers to manage credentials.
- Can be assigned to Azure resources like VMs, App Services, Functions.
- Supports system-assigned and user-assigned types.
Memory trick: Managed Identities: No Keys to Lose, No Credentials to Abuse.
Continuous Access Evaluation (CAE)
Flip cardA security standard that enables applications to evaluate policy changes and revoke access tokens in near real-time based on critical security events.
- Immediate token revocation for critical events.
- Reduces the window of opportunity for attackers.
- Requires client applications to support CAE.
Memory trick: CAE is like an instant security camera that can snatch your keys if you're compromised.
Azure AD Admin Consent Workflow
Flip cardThe Azure AD admin consent workflow enables users to request administrator approval for an application that requires permissions an ordinary user cannot grant. It streamlines the process by allowing non-admin users to initiate a request for an admin to review and approve the application's access to tenant resources.
- Users can request admin approval for applications.
- Admins can review requests in the Azure portal.
- Allows delegation of consent approval to roles like Application Administrator.
- Crucial for multi-tenant applications requiring elevated permissions.
Memory trick: Consent Workflow: Ask, Delegate, Approve.
OAuth 2.0 Authorization Code Flow with PKCE
Flip cardA secure OAuth 2.0 grant flow for applications to obtain delegated access to APIs on behalf of a user, preventing code interception attacks.
- Recommended for web, mobile, desktop apps.
- Exchanges an authorization code for tokens.
- PKCE protects against authorization code interception.
Memory trick: Auth Code PKCE: Always Code, Protect Keys, Control Everything.
Azure Role-Based Access Control (RBAC)
Flip cardAn authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources.
- Allows assignment of roles to users, groups, service principals, or managed identities.
- Permissions can be granted at management group, subscription, resource group, or resource scope.
- Enforces the principle of least privilege by defining specific actions allowed.
Memory trick: RBAC and Least Privilege: Only the right keys for the right locks.
OAuth 2.0 / OpenID Connect (OIDC)
Flip cardOAuth 2.0 is an authorization framework, and OpenID Connect is an identity layer built on OAuth 2.0, enabling clients to verify end-user identity and obtain basic profile information.
- OAuth 2.0 focuses on authorization (delegated access to resources).
- OpenID Connect focuses on authentication (identity verification).
- Widely adopted for modern web, mobile, and API security with Azure AD.
Memory trick: OAuth and OIDC are the modern keys for web apps and APIs.
Azure AD B2B Collaboration
Flip cardEnables organizations to securely collaborate with external users by inviting them to use their own identities to access resources.
- External users are guest accounts.
- Supports various identity providers.
- Integrates with Entitlement Management for lifecycle.
Memory trick: B2B: Bring External, Bound by Time.
Azure AD SAML Claims Mapping
Flip cardConfiguring custom user attributes (claims) to be included in the SAML token issued by Azure AD for an enterprise application.
- Configured in Enterprise Applications > Single sign-on.
- Maps Azure AD user properties to SAML claims.
- Essential for LOB applications requiring specific attributes.
Memory trick: SAML Claims: Send Attributes, Make it Known.
Azure AD B2B Collaboration with Social IdPs
Flip cardAzure AD B2B Collaboration allows you to invite external users to your Azure AD tenant. When configured with social identity providers like Google, these external users can sign in using their existing social accounts.
- Enables collaboration with users outside your organization.
- Supports various identity providers, including Google and Microsoft accounts.
- Guest users are represented in your directory and can be assigned access to applications and resources.
Memory trick: B2B for Business Partners, B2C for Customers.
Azure AD PIM for Azure Resources
Flip cardA feature of Azure AD PIM that extends just-in-time, time-limited, and approval-based access to Azure RBAC roles for subscriptions, resource groups, and resources.
- Elevates access to Azure RBAC roles.
- Enforces time limits and approval workflows.
- Integrates with Azure AD Audit logs for logging.
Memory trick: PIM for Azure resources is like a secure vault for your admin powers, with an audit trail.
Azure AD Connect: Prevent Accidental Deletions
Flip cardThis feature in Azure AD Connect is a safeguard that prevents the synchronization of an excessive number of deletions from the on-premises directory to Azure AD. It halts the sync process if the number of detected deletions exceeds a configurable threshold, requiring administrator approval to proceed.
- Protects against unintended bulk user/object deletions.
- Configurable threshold for the number of deletions.
- Requires manual approval if the threshold is exceeded.
- Essential for maintaining data integrity in hybrid environments.
Memory trick: Don't Delete, Delay and Decide.
Password Hash Synchronization (PHS)
Flip cardA method of identity synchronization where a hash of the user's password from on-premises Active Directory is synchronized to Azure AD.
- Provides a simple way to enable cloud authentication for hybrid identities.
- Offers high availability and disaster recovery for authentication.
- Requires Azure AD Connect to be installed and configured.
Memory trick: Syncing hashes securely ensures cloud access.
Azure AD Identity Protection
Flip cardA feature that enables organizations to detect, investigate, and remediate identity-based risks.
- Detects various types of risks: impossible travel, unfamiliar locations, leaked credentials, infected devices.
- Calculates a risk score for both users and sign-ins.
- Can be integrated with Conditional Access to enforce automated remediation (e.g., block, MFA).
Memory trick: Protect identities by spotting and stopping danger.
OAuth 2.0 & OpenID Connect (OIDC)
Flip cardOAuth 2.0 is an authorization framework, and OpenID Connect is an identity layer built on OAuth 2.0 for authentication.
- OIDC for authentication (who is the user).
- OAuth 2.0 for authorization (what can the app do).
- Widely adopted for modern web and mobile apps.
Memory trick: OIDC/OAuth: Open Doors for Identity and Access.
Azure AD Service Principal
Flip cardA security identity that represents an application, service, or automation tool that needs to access specific Azure resources.
- Acts as the instance of an application object in a specific tenant.
- Used to assign permissions to applications, following least privilege.
- Can be client secret or certificate-based for authentication.
Memory trick: Service Principal: The app's ID card for accessing resources.
Conditional Access + Identity Protection
Flip cardA powerful combination in Azure AD where Conditional Access policies are enhanced by real-time risk detections from Identity Protection to enforce adaptive access controls.
- Conditional Access defines 'if-then' access rules.
- Identity Protection feeds sign-in and user risk levels into Conditional Access.
- Allows for highly adaptive and dynamic access policies based on risk and context.
Memory trick: Smart access: know who, from where, and how risky.
Conditional Access with Identity Protection
Flip cardCombining Conditional Access policies with Identity Protection risk detections to enforce adaptive access controls based on user, sign-in, or user risk levels.
- Conditional Access defines 'what to do' (e.g., block, require MFA).
- Identity Protection defines 'when to do it' by providing risk signals.
- Enables adaptive security, responding to real-time threats.
Memory trick: Conditional Access and Identity Protection: the traffic cop and the risk detector.
Azure AD B2C
Flip cardA cloud-based identity and access management service that enables customer-facing applications to authenticate users using social accounts, enterprise accounts, or local credentials.
- Designed for consumer applications.
- Supports social identity providers (Google, Facebook, etc.).
- Highly customizable user journeys for sign-up/sign-in.
Memory trick: B2C is for your 'Customers' (Consumers) and their 'Casual' logins.
Azure AD Conditional Access
Flip cardA feature of Azure Active Directory that enables organizations to enforce policies for accessing resources based on specific conditions.
- Enforces 'if-then' statements for access.
- Commonly used for MFA, device compliance, location-based access.
- Requires Azure AD Premium P1 or P2 license.
Memory trick: Conditional Access is the bouncer checking your credentials at the club door.
Azure AD Pass-through Authentication (PTA)
Flip cardAn Azure AD Connect authentication method that validates user passwords directly against an on-premises Active Directory.
- Uses lightweight agents on-premises.
- Provides immediate password validation.
- Does not store passwords in Azure AD.
Memory trick: PTA: Pass Through Always to On-Prem.
OAuth 2.0 / OpenID Connect
Flip cardOAuth 2.0 is an authorization framework, and OpenID Connect (OIDC) is an identity layer built on OAuth 2.0, providing authentication.
- OIDC provides identity (who the user is), OAuth 2.0 provides authorization (what the user can do).
- Widely adopted for modern web and mobile applications.
- Enables Single Sign-On (SSO) and secure API access using access tokens.
Memory trick: For web apps, choose the modern key for identity and permissions.
Azure AD Connect
Flip cardA Microsoft tool designed to synchronize on-premises Active Directory identities with Azure Active Directory.
- Enables hybrid identity scenarios.
- Supports password hash synchronization (PHS), pass-through authentication (PTA), and federation integration.
- Synchronizes users, groups, and contacts.
Memory trick: Connect on-premises to the cloud with the right tool.
Azure AD PIM
Flip cardA service in Azure Active Directory that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft Online Services.
- Provides just-in-time (JIT) access to roles.
- Requires activation for privileged roles, often with approval workflows.
- Includes auditing, access reviews, and alerts for privileged activities.
Memory trick: Give kings temporary crowns, not permanent ones.
Conditional Access Session Controls (Sign-in Frequency)
Flip cardA Conditional Access control that dictates how often users are required to re-authenticate, even within an active session.
- Configurable in hours or days.
- Applies to specific applications or users.
- Enhances security for sensitive resources.
Memory trick: Conditional Session: Control Re-Auth Time.
Azure AD Conditional Access (Location-based)
Flip cardEnforces access policies based on the user's network location, allowing for granular control like MFA exemptions.
- Uses 'Named locations' to define trusted IPs.
- Allows 'Exclude' trusted locations from policies.
- Requires Azure AD Premium P1.
Memory trick: Conditional Location: Control MFA by Where You Are.
Service Principal Least Privilege
Flip cardConfiguring an application's service principal with only the permissions absolutely necessary to perform its functions at the smallest possible scope.
- Use built-in roles if they fit, otherwise create custom roles.
- Assign roles at the lowest possible scope (resource, resource group, subscription, management group).
- Regularly review assigned permissions for continued necessity.
Memory trick: Give machines only the exact tools they need, in their own workspace.
Conditional Access: User Actions Condition
Flip cardA condition type in Azure AD Conditional Access that allows policies to be applied specifically when users perform certain sensitive actions within Azure AD.
- Targets specific sensitive actions (e.g., registering security info).
- Can enforce MFA or other controls for these actions.
- Provides granular control over sensitive operations.
Memory trick: User Actions is like a mini-MFA checkpoint for just the 'extra sensitive' buttons.
Pass-through Authentication (PTA)
Flip cardAn Azure AD Connect authentication method that signs users in by validating their passwords directly against on-premises Active Directory.
- Uses lightweight agents on-premises to validate passwords.
- Does not store password hashes in Azure AD.
- Provides a simple way to achieve single sign-on without ADFS.
Memory trick: Choose how your on-prem password travels to the cloud.
Conditional Access Device State
Flip cardA condition in Azure AD Conditional Access policies that allows evaluating the compliance or join state of a device to control access to resources.
- Integrates with Microsoft Intune for device compliance.
- Can block access from non-compliant devices.
- Supports 'Hybrid Azure AD joined' and 'Azure AD joined' devices.
Memory trick: Device state is like a bouncer checking your ID and vaccination card.
Nonce (Number Used Once)
Flip cardA nonce is a random, single-use value included in cryptographic communication to prevent replay attacks. It ensures that each message or request is unique and cannot be retransmitted by an attacker.
- Used in authentication protocols like OAuth 2.0 and OpenID Connect.
- Ensures token freshness and prevents re-use.
- Typically generated by the client and validated by the server.
Memory trick: No Old Nonce, New Request, No Replay!
Azure App Service Authentication (Easy Auth)
Flip cardAzure App Service Authentication/Authorization (often called 'Easy Auth') provides a way to integrate various identity providers directly into your web app or API without writing authentication code. For internal users in your Azure AD, the 'Microsoft' provider is selected.
- Simplifies authentication integration for App Services.
- Supports Azure AD, Microsoft Accounts, social providers (Google, Facebook, Twitter).
- No code changes required in the application for basic scenarios.
- Handles token validation and session management.
Memory trick: Easy Auth: For Microsoft Users, Pick Microsoft.
Azure AD Audit Logs
Flip cardLogs that capture all changes made within an Azure Active Directory tenant, including administrative actions, application management, and directory updates.
- Records who, what, when, and where for administrative actions.
- Essential for security auditing and compliance.
- Can be integrated with Azure Monitor for advanced analysis.
Memory trick: Audit logs are like the 'change history' of your directory.
Microsoft Defender for Cloud (Containers plan)
Flip cardA security solution that provides cloud-native protection for containers, including vulnerability assessment for images in Azure Container Registry (ACR) and runtime threat protection for Azure Kubernetes Service (AKS) clusters.
- Scans container images for vulnerabilities.
- Provides admission control for AKS to block vulnerable deployments.
- Offers runtime protection for AKS nodes and clusters.
Memory trick: Defender guards the containers from registry to runtime.
Force TLS for Azure Synapse Analytics
Flip cardA setting within Azure Synapse Analytics workspaces that enforces a minimum Transport Layer Security (TLS) version for all client connections to dedicated SQL pools, ensuring secure communication.
- Configured at the Synapse Workspace level.
- Enforces TLS 1.2 (or higher) for all inbound client connections.
- Enhances data in transit security for dedicated SQL pools.
- Helps meet compliance requirements for secure communication protocols.
Memory trick: Ensure your Synapse connections are always securely encrypted with the right lock.
Azure Storage Security for Compliance
Flip cardA combination of Azure features including Azure AD/RBAC for access, Immutable Storage for WORM compliance, Azure Monitor for logging, and Microsoft Defender for Storage for threat detection.
- Azure AD/RBAC: Granular access control.
- Immutable Storage: WORM for audit trails.
- Azure Monitor: Comprehensive logging.
- Defender for Storage: Advanced threat detection for unusual activity.
Memory trick: AD, Immutable, Monitor, Defender: The four pillars of secure, auditable storage.
Customer-Managed Keys (CMK) in Azure Synapse Analytics
Flip cardAllows customers to use their own encryption keys, stored in Azure Key Vault (often with HSMs), to encrypt data at rest within Azure Synapse Analytics.
- Provides full control over encryption keys.
- Keys can be stored in Azure Key Vault with HSMs for FIPS 140-2 Level 2 compliance.
- Enhances regulatory compliance and data governance.
Memory trick: CMK in Key Vault with HSM is the golden key for ultimate data control.
Version-level Immutability Support
Flip cardAn Azure Blob Storage feature that allows setting time-based retention policies on blobs, making them immutable (Write Once, Read Many) for compliance.
- Ensures data cannot be deleted or modified for a specified period.
- Supports both time-based retention and legal holds.
- Critical for regulatory compliance (e.g., HIPAA, FINRA).
Memory trick: Immutability: Your data's time capsule, sealed for compliance.
Microsoft Defender for Cloud (SQL plan)
Flip cardA capability within Microsoft Defender for Cloud that provides advanced security for Azure SQL Databases, including vulnerability assessment, threat detection, and security recommendations.
- Automatically identifies database vulnerabilities and misconfigurations.
- Provides actionable recommendations to improve security posture.
- Detects anomalous activities indicating potential threats.
- Integrates with the broader Defender for Cloud platform.
Memory trick: Defender for SQL: Your database's personal security analyst.
Transparent Data Encryption (TDE)
Flip cardA feature in Azure SQL Database that encrypts the entire database, including data files and transaction log files, at rest and in backups.
- Encrypts data at rest and backups.
- Transparent to applications; no code changes required.
- Uses a database encryption key (DEK) protected by a master key.
Memory trick: TDE protects the whole database like a transparent shield.
Time-based retention policy (WORM)
Flip cardA feature in Azure Blob Storage that applies an immutable, Write Once, Read Many (WORM) state to a container or blob, preventing modification or deletion for a specified duration, even by users with administrative privileges.
- Enforces immutability for compliance (e.g., HIPAA, FINRA).
- Can be configured at the container level.
- Supports 'AllowProtectedAppendWrites' for specific use cases.
- Retention period can be configured for a fixed time or indefinitely (legal hold).
Memory trick: Lock your storage data in time, so no one can change its history.
System-assigned Managed Identity
Flip cardAn identity created and managed by Azure, tied directly to the lifecycle of a single Azure resource (e.g., App Service, VM). It allows the resource to authenticate to other Azure services without storing credentials in code.
- Automatically created and deleted with the Azure resource.
- Cannot be shared with other resources.
- Credentials are automatically managed and rotated by Azure.
- Simplifies secure access to Azure AD-protected services.
Memory trick: Give your Azure resource its own ID card for secure cloud access.
Synapse Managed VNet & Private Endpoints
Flip cardAzure Synapse Analytics feature that provisions a dedicated, Azure-managed virtual network for the workspace's compute resources and enables Managed Private Endpoints for secure, private outbound connectivity to other Azure services.
- Provides network isolation for Synapse Spark and SQL pools.
- All compute traffic stays within the Azure network.
- Managed Private Endpoints ensure private outbound access to data sources/sinks.
- Simplifies network configuration compared to customer-managed VNets for Synapse.
Memory trick: Keep your Synapse data flowing privately, both in and out, within its own secure network.
Azure Private Endpoint for Storage
Flip cardA network interface that connects an Azure Storage account privately and securely to a virtual network, making the storage account accessible only via private IP addresses within that network.
- Removes storage account from public internet.
- Provides private IP address within a VNet.
- Enhances security by eliminating data exfiltration risks.
Memory trick: Private Endpoint is like a secret tunnel for your storage, invisible from the outside.
SQL Vulnerability Assessment
Flip cardA service that provides an easy-to-configure solution that can discover, track, and remediate potential database vulnerabilities. It runs scans, identifies security misconfigurations, and makes recommendations for improving the security posture of Azure SQL Databases.
- Continuously scans for security misconfigurations and vulnerabilities.
- Identifies excessive permissions and sensitive data exposure.
- Provides actionable remediation steps and compliance tracking.
Memory trick: SQL VA: the database's security check-up with a to-do list.