Microsoft Certified: Azure Security Engineer Associate flashcards
142 free flashcards. Tap a card to flip it.
App Service VNet Integration (Regional) with NSGs for Outbound Control
Flip cardA networking feature that routes outbound traffic from an Azure App Service through a subnet in a virtual network, enabling granular control over destination endpoints using Network Security Groups (NSGs).
- Enables outbound traffic filtering for App Service.
- Uses a delegated subnet within a VNet.
- NSGs on the subnet define allowed outbound destinations (IPs, FQDNs, Service Tags).
Memory trick: VNet Integration + NSG = Your App Service's outbound traffic police.
Azure Firewall for AKS Outbound Traffic
Flip cardAzure Firewall is a cloud-native, intelligent network firewall security service that provides highly available and scalable network security for all your Azure Virtual Network resources, including outbound filtering for Azure Kubernetes Service (AKS) clusters.
- Provides FQDN-based filtering for outbound traffic.
- Offers network and application rule collections.
- Integrates with Azure Monitor for auditing and logging.
Memory trick: Azure Firewall: AKS's strict internet bouncer.
Storage Account CMK with Auto-rotation
Flip cardAzure Storage account encryption using customer-managed keys (CMK) stored in Azure Key Vault, configured for automatic key rotation.
- Encrypts all data at rest in the storage account (blobs, files, queues, tables).
- Keys are managed by the customer in Azure Key Vault.
- Azure Key Vault supports automatic key rotation for CMKs.
Memory trick: CMK Auto-rotate: Your storage's personal key, always fresh from the vault.
Always Encrypted with Secure Enclaves
Flip cardAn Azure SQL Database/Synapse feature that allows client applications to encrypt sensitive data, ensuring data is never revealed in plaintext to the database engine or administrators, even during computations, by using secure enclaves.
- Client-side encryption, data remains encrypted at rest, in transit, and in use.
- Secure enclaves enable in-place computations on encrypted data.
- Keys are managed by application owners, not DBAs.
Memory trick: Always Encrypted with enclaves keeps secrets safe, even from the database itself.
App Service Access Restrictions
Flip cardA feature in Azure App Service that allows you to control inbound network access to your web app based on IP addresses, IP ranges, or virtual network subnets using VNet Service Endpoints.
- Configured directly on the App Service.
- Supports Allow/Deny rules based on IP addresses/ranges.
- Can integrate with VNet Service Endpoints for subnet-level access.
- Rules are evaluated in priority order.
Memory trick: Control who enters your App Service with a clear access list.
TDE with CMK and Auto-rotation
Flip cardTransparent Data Encryption (TDE) with Customer-Managed Keys (CMK) stored in Azure Key Vault, configured for automatic key rotation, provides comprehensive encryption for data at rest with enhanced security and compliance.
- Encrypts entire database at rest and backups.
- Customer retains full control over encryption keys via Azure Key Vault.
- Automated key rotation minimizes operational overhead and enhances security posture.
- Supports various Azure SQL offerings.
Memory trick: Secure your SQL data with customer control and seamless key updates.
Microsoft Defender for Cloud (Containers)
Flip cardA cloud-native security solution that provides comprehensive threat protection and security posture management for containerized workloads, including vulnerability assessment, runtime threat detection, and security recommendations for Azure Kubernetes Service (AKS).
- Scans container images for vulnerabilities in Azure Container Registry and during runtime.
- Detects runtime threats to pods, nodes, and clusters.
- Provides security recommendations based on best practices.
- Integrates with Azure Policy for compliance enforcement.
Memory trick: Defend your containers from build to runtime with a centralized cloud guardian.
HTTP Strict Transport Security (HSTS)
Flip cardA web security policy mechanism that helps to protect websites against protocol downgrade attacks and cookie hijacking by forcing web browsers to interact with it only using secure HTTPS connections.
- Browser remembers to only use HTTPS for a specified duration.
- Prevents HTTP-to-HTTPS downgrade attacks.
- Set via a 'Strict-Transport-Security' HTTP response header.
Memory trick: App Service offers built-in security for simple enforcement.
App Service Client Certificates with Key Vault
Flip cardA secure method for Azure App Service to use client certificates for mutual TLS authentication to backend systems, leveraging Azure Key Vault for certificate storage, management, and automated loading.
- Key Vault securely stores and manages certificates.
- App Service can load certificates directly from Key Vault.
- Supports automated certificate renewal and rotation.
Memory trick: Key Vault: The secure 'pocket' for App Service's outbound certificates.
Azure Synapse Workspace Managed VNet & Private Endpoints
Flip cardA combination of features in Azure Synapse Analytics where the workspace is configured with a managed Virtual Network (VNet) for its compute resources (like Spark pools) and uses Private Endpoints to securely connect to other Azure services, ensuring all data processing and connectivity remain within a private, isolated network.
- Ensures data residency by keeping all Spark pool traffic within the VNet.
- Private Endpoints eliminate public internet exposure for data movement.
- The managed VNet is created and managed by Synapse for its compute needs.
Memory trick: Managed VNet + Private Endpoint = Synapse's private island.
Azure App Service Environment (ASEv3)
Flip cardA single-tenant deployment of Azure App Service that runs entirely within a customer's Azure Virtual Network, providing complete network isolation and scalability.
- Full network isolation for inbound and outbound traffic.
- Deployed directly into a customer's VNet.
- Ideal for high-security, high-scale, and regulatory compliance scenarios.
Memory trick: ASEv3 is like putting your App Service in its own private, secure VNet bubble.
App Service Private Endpoint
Flip cardA networking feature that allows Azure App Service to be accessed privately from a virtual network, eliminating public internet exposure.
- Provides a private IP address for the App Service within a VNet.
- Ensures all traffic (inbound and outbound) flows through the VNet.
- Enhances security by removing public internet access.
Memory trick: Private Endpoint: Your App Service's VIP private party.
Azure App Service Access Restrictions
Flip cardA security feature in Azure App Service that allows you to define a prioritized list of allow/deny rules based on IP addresses, IP ranges, or virtual network subnets for inbound access to your web application.
- Controls inbound network traffic to the App Service.
- Supports IP addresses, CIDR blocks, and Service Tags (e.g., AzureFrontDoor.Backend).
- Rules are processed in priority order (lowest number first).
Memory trick: Access Restrictions are the bouncer at the App Service door.
Kubernetes Network Policy
Flip cardA Kubernetes resource that specifies how groups of pods are allowed to communicate with each other and with external network endpoints.
- Enforces both inbound (ingress) and outbound (egress) rules.
- Applied using label selectors to target specific pods.
- Provides granular network segmentation within a cluster.
Memory trick: Network Policy: Your cluster's traffic cop for pod conversations.
Azure Firewall for AKS Outbound
Flip cardIntegrating Azure Firewall with an Azure Kubernetes Service (AKS) cluster to centrally inspect and filter all outbound network traffic from the cluster, ensuring compliance and enhanced security.
- Provides centralized egress traffic filtering for AKS.
- Supports FQDN-based filtering, network rules, and application rules.
- Offers advanced threat protection features.
- Helps meet regulatory compliance for traffic inspection.
Memory trick: Make sure all traffic leaving your AKS cluster passes through a strict security checkpoint.
Azure AD-only Authentication for Azure SQL
Flip cardA configuration option for Azure SQL Database that enforces all connections to use Azure Active Directory identities for authentication, enabling MFA and centralized identity management.
- Mandates Azure AD identities for all users and administrators.
- Enables MFA enforcement via Azure AD Conditional Access.
- Centralizes identity management with Azure AD.
Memory trick: Azure AD-only: Your SQL database's bouncer, only letting AD identities with MFA in.
Microsoft Defender for Containers
Flip cardA cloud-native security solution within Microsoft Defender for Cloud that provides comprehensive threat protection for containerized environments, including vulnerability management, runtime protection, and policy enforcement.
- Scans container images for vulnerabilities.
- Provides runtime threat detection for AKS clusters and nodes.
- Integrates with Kubernetes admission control for policy enforcement.
Memory trick: Defender for Containers defends your entire container lifecycle, from image to runtime.
Immutability policy (time-based retention)
Flip cardA feature of Azure Blob Storage that allows users to store business-critical data in a WORM (Write Once, Read Many) state for a user-specified interval, ensuring data cannot be modified or deleted for the retention period.
- Enforces WORM state for regulatory compliance.
- Supports time-based retention and legal holds.
- Once set, cannot be shortened or removed in a locked state.
Memory trick: Immutability: a digital concrete block for your data.
Azure Storage Encryption Scope with CMK and auto-rotation
Flip cardAn Azure Storage feature that allows defining encryption settings (including using Customer-Managed Keys from Azure Key Vault) at a container or blob level, with the ability to automatically rotate the CMK.
- Provides granular encryption control within a storage account.
- Supports Customer-Managed Keys (CMK) from Azure Key Vault.
- Can be configured for automatic key rotation to enhance security posture.
Memory trick: Encryption Scope: your key, your rules, auto-rotated.
Version-level immutability support (WORM)
Flip cardA feature for Azure Blob Storage that enables Write Once, Read Many (WORM) compliance by allowing you to set a time-based retention policy on individual blob versions, making them immutable for the specified duration.
- Achieves WORM compliance.
- Prevents modification or deletion for a set period.
- Applies at the blob version level.
Memory trick: Version immutability 'freezes' your data like a timestamped, unchangeable record.
App Service VNet Integration (Regional)
Flip cardAllows your App Service app to access resources in or through an Azure Virtual Network (VNet) in the same region. All outbound traffic from the app is then directed through the integrated VNet, enabling network security controls.
- Connects App Service to a VNet in the same region.
- Enables outbound traffic control via NSGs.
- App becomes part of the VNet for outbound connectivity.
Memory trick: VNet Integration is the 'gateway' for App Service to get its outbound traffic secured.
Azure Private Endpoint
Flip cardA network interface that connects you privately and securely to a service powered by Azure Private Link. Private Endpoint uses a private IP address from your VNet, effectively bringing the service into your VNet.
- Connects Azure services privately to your VNet.
- Traffic stays on the Azure backbone network.
- Eliminates public internet exposure for the service.
Memory trick: Private Endpoints keep services 'behind closed doors' in your VNet.