Microsoft Cybersecurity Architect (SC-100) flashcards
131 free flashcards. Tap a card to flip it.
OT PAM (Privileged Access Management)
Flip cardOT PAM extends traditional PAM principles to operational technology environments, providing secure, controlled, and auditable access to critical industrial control systems, often via specialized gateways.
- Secures privileged access to industrial systems.
- Provides granular control and session monitoring.
- Helps maintain network segmentation and isolation.
Memory trick: OT's air gap needs a PAM bridge, not an open door.
Cloud-Native XDR
Flip cardCloud-native XDR (Extended Detection and Response) unifies security data from multiple domains (endpoint, cloud, identity, network) into a single platform for improved threat detection, investigation, and automated response across hybrid and multi-cloud environments.
- Unifies telemetry across multiple security layers.
- Provides enhanced threat detection and context.
- Automates response actions across the attack chain.
Memory trick: Multi-cloud needs a unified eye, XDR sees all, acts fast.
Zero Trust Architecture (ZTA)
Flip cardA security model where no user, device, or application is implicitly trusted, regardless of their location. All access requests are authenticated, authorized, and continuously verified.
- Based on the principle 'never trust, always verify'.
- Enforces least privilege access.
- Requires continuous monitoring and validation of trust.
Memory trick: Zero Trust: Verify Everything, Grant Least Privilege
Cloud Security Posture Management (CSPM)
Flip cardCSPM tools continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation capabilities.
- Identifies cloud misconfigurations.
- Ensures compliance with regulatory standards.
- Provides continuous security assessment.
Memory trick: Cloud posture needs a constant watch, CSPM is the watchful eye.
Data Classification and Protection (DCP)
Flip cardDCP is a framework that categorizes data based on its sensitivity and regulatory requirements, then applies appropriate security controls (encryption, access controls, integrity checks) throughout its lifecycle.
- Identifies and tags sensitive data.
- Enforces granular access policies.
- Applies encryption at rest and in transit.
- Maintains data integrity and audit trails.
Memory trick: DCP is the 'Lab Guardian' for 'Sensitive Research Data'.
Data Security Posture Management (DSPM)
Flip cardDSPM is a security solution that provides continuous, real-time visibility into sensitive data across hybrid and multi-cloud environments. It automates data discovery, classification, and risk assessment, identifying misconfigurations, access risks, and compliance gaps related to data.
- Automates data discovery and classification.
- Identifies data risks and compliance gaps.
- Provides continuous monitoring of data posture.
- Covers hybrid and multi-cloud environments.
Memory trick: Discover, classify, protect your data everywhere.
DLP + IRM Integration
Flip cardIntegrating Data Loss Prevention (DLP) with Information Rights Management (IRM) creates a powerful defense that prevents unauthorized data outflow and maintains control over data usage even when it's shared.
- DLP prevents data exfiltration.
- IRM controls data access and usage post-distribution.
- Encrypts and enforces policies on sensitive files.
Memory trick: To protect IP everywhere, DLP guards the gate, IRM locks the content.
Policy-as-Code & Cloud-Native Secrets Management
Flip cardPolicy-as-Code defines security and compliance policies in machine-readable code, while cloud-native secrets management secures and distributes sensitive credentials in dynamic cloud environments.
- Automates policy enforcement in CI/CD.
- Ensures consistent security across environments.
- Secures API keys, database credentials, etc., for microservices.
Memory trick: Policy-as-Code and Secrets Management are the 'Guardians' of 'Cloud-Native Deployments'.
Threat Intelligence Platform (TIP)
Flip cardA software solution that aggregates, processes, and disseminates threat intelligence from various sources, making it actionable for security operations.
- Normalizes and enriches threat data from multiple feeds.
- Integrates with SIEM, SOAR, firewalls, and other security controls.
- Enables proactive defense and automated incident response.
Memory trick: TIP Feeds Proactive Security Operations
Secure Collaboration Platforms
Flip cardThese platforms enable secure communication and data sharing among users, often incorporating encryption, access controls, and audit trails to meet compliance requirements.
- Ensures confidentiality and integrity of shared data.
- Provides granular access controls.
- Often includes audit and logging features for compliance.
Memory trick: HIPAA needs secure chats, not just good defense.
Container Security Platforms
Flip cardThese platforms provide comprehensive security for containerized applications throughout their lifecycle, including vulnerability management, runtime protection, and compliance.
- Scans container images for vulnerabilities.
- Monitors container runtime behavior for anomalies.
- Enforces security policies within container environments.
Memory trick: PCI containers need a specialized guard, not just the building's watchman.
Data Loss Prevention (DLP)
Flip cardDLP is a set of tools and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.
- Prevents unauthorized data exfiltration.
- Enforces data handling policies.
- Monitors data in use, in motion, and at rest.
Memory trick: Residency rules keep data home, DLP's the guard at the door.
Integrated Risk Management (IRM)
Flip cardIRM is a set of practices and processes supported by technology that enables an organization to understand and manage the full scope of its risks. It integrates governance, risk, and compliance (GRC) activities into a unified framework.
- Centralizes risk data and management.
- Automates compliance and audit processes.
- Provides a holistic view of an organization's risk posture.
- Supports decision-making across diverse business units and environments.
Memory trick: Integrate risks, unify compliance, see the whole picture.
Privileged Access Management (PAM)
Flip cardPAM solutions manage and secure privileged accounts, credentials, and sessions, enforcing least privilege and providing comprehensive auditing capabilities.
- Controls access to sensitive systems and data.
- Reduces the attack surface by limiting privileged credential exposure.
- Enables session recording and auditing for compliance and forensics.
Memory trick: PAM Protects Critical Remote Access
Privileged Access Management (PAM) for OT
Flip cardPAM for OT is a specialized solution that secures, manages, and monitors privileged accounts and access to operational technology systems, ensuring strict control, auditability, and compliance.
- Manages shared and administrative credentials.
- Enforces least privilege for critical OT systems.
- Records and audits privileged sessions.
- Supports specialized OT protocols and devices.
Memory trick: PAM is the 'Royal Guard' for 'OT's Crown Jewels'.
Hybrid/Multi-Cloud SIEM/SOAR
Flip cardThis refers to the integration of Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) capabilities to provide unified security visibility, alert management, and automated incident response across complex hybrid and multi-cloud environments.
- Centralizes security event data from diverse sources.
- Automates incident detection and response workflows.
- Provides a holistic view of security posture across hybrid/multi-cloud.
- Reduces manual effort and improves response times.
Memory trick: See all, automate all, respond fast, hybrid or not.
Cryptographic Integrity for Data Migration
Flip cardUsing cryptographic hashing and digital signatures, combined with a verifiable chain of custody, to ensure the integrity, authenticity, and auditable transfer of sensitive and regulated data during migrations.
- Hashing verifies data hasn't changed.
- Digital signatures prove sender identity and message integrity.
- Chain of custody documents every data handling step.
Memory trick: Divested data needs crypto proofs and a custody chain, no trust without it.
Policy-as-Code (PaC)
Flip cardPolicy-as-Code defines security and compliance policies in machine-readable code, enabling automated enforcement throughout the software development lifecycle and across infrastructure. It allows policies to be version-controlled, tested, and deployed like any other code.
- Automates policy enforcement.
- Integrates with CI/CD pipelines.
- Ensures consistency across environments.
- Enables 'shift-left' security.
Memory trick: Code your rules, deploy your security, keep it clean.
Software Composition Analysis (SCA)
Flip cardSCA tools analyze software applications to identify and inventory open-source and third-party components, scanning them for known security vulnerabilities and license compliance issues.
- Essential for managing software supply chain risks.
- Integrates into CI/CD pipelines for continuous monitoring.
- Helps ensure compliance with licensing and security policies.
Memory trick: SCA Scans the Supply Chain Continuously
GRC Platform
Flip cardA software solution that integrates and manages an organization's governance, risk management, and compliance activities, providing a unified view of risk and control status.
- Automates compliance monitoring and evidence collection.
- Streamlines audit processes and reporting.
- Provides visibility into risk posture and control effectiveness.
Memory trick: GRC Platform Automates SOC 2 Proof
Enterprise GRC Platform
Flip cardAn Enterprise GRC Platform is a centralized system that helps organizations manage governance, risk, and compliance activities, automate control validation, and provide real-time compliance posture.
- Maps controls to multiple regulations.
- Automates evidence collection for audits.
- Provides real-time visibility into compliance posture.
- Manages risks and policies centrally.
Memory trick: The 'GRC Platform' is the 'Financial Auditor's Best Friend'.
SOAR (Security Orchestration, Automation, and Response)
Flip cardSOAR platforms automate and orchestrate security operations tasks, incident response workflows, and threat intelligence management.
- Reduces manual effort and response times for security incidents.
- Integrates with various security tools (e.g., SIEM, firewalls).
- Enables consistent and repeatable incident response processes.
Memory trick: Automated Response Needs Human Oversight
Security Orchestration, Automation, and Response (SOAR)
Flip cardSOAR platforms integrate security tools, automate incident response workflows, and orchestrate threat hunting and management tasks.
- Automates repetitive security tasks.
- Orchestrates complex incident response processes.
- Enhances threat intelligence utilization.
Memory trick: SOAR is the 'Orchestra Conductor' of 'Security Automation' and 'Response'.
Edge Anonymization for IoT/Vehicles
Flip cardProcessing and anonymizing sensitive data directly at the data source (e.g., within a vehicle or IoT device) using edge computing, ensuring privacy-by-design before data leaves the local environment.
- Implements privacy-by-design at the source.
- Reduces sensitive data exposure during transmission and storage.
- Enables compliance with privacy regulations for real-time data.
Memory trick: Vehicle data privacy starts at the edge, anonymize before it speeds away.
Unified Cloud-Native XDR
Flip cardUnified Cloud-Native Extended Detection and Response (XDR) provides a consolidated, cloud-based platform for detecting and responding to threats across hybrid and multi-cloud environments, integrating data from various security layers.
- Correlates data across endpoints, cloud, network, identity.
- Leverages AI/ML for advanced threat detection.
- Automates and orchestrates response actions.
Memory trick: XDR is the 'Hybrid Cloud Detective' connecting all 'Security Clues'.
Identity Governance and Administration (IGA)
Flip cardIGA is a framework that manages digital identities and access rights across an organization, ensuring that access aligns with policy and regulations.
- Automates user provisioning and deprovisioning.
- Enforces least privilege and segregation of duties.
- Facilitates access reviews and certifications.
Memory trick: IGA is the 'Guard' who gives 'Access' to the 'Enterprise'.
Shift Left Security
Flip cardThe practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC) to find and fix vulnerabilities when they are less costly.
- Reduces the cost and effort of fixing security defects.
- Promotes a culture of security awareness among developers.
- Often involves automated security testing tools in CI/CD pipelines.
Memory trick: Move Security Left, Catch Bugs Early
Data Classification
Flip cardThe process of categorizing data based on its sensitivity, value, and regulatory requirements to apply appropriate security controls.
- Enables targeted application of security policies (e.g., encryption, access controls).
- Crucial for compliance with data privacy regulations.
- Often implemented with automated tools and user input.
Memory trick: Classify Data, Control Access, Prevent Loss for Global Rules
AI/ML in Fraud Detection
Flip cardUtilizing Artificial Intelligence and Machine Learning models to analyze vast datasets and identify anomalous patterns indicative of fraudulent activities in real-time.
- Enhances detection accuracy and speed compared to rule-based systems.
- Adapts to new fraud techniques by learning from data.
- Requires significant data for training and continuous model refinement.
Memory trick: AI Catches Fraud, SIEM Logs Compliance
Automated Data Classification
Flip cardThe use of software tools to automatically identify, categorize, and tag data based on its content, context, and sensitivity, often integrating with existing data protection systems.
- Ensures consistent application of classification policies across large datasets.
- Reduces manual effort and human error.
- Enables dynamic enforcement of security controls based on data sensitivity.
Memory trick: Automated Classification + IGA for Government Data
Serverless CWPP + Cloud-Native Security
Flip cardThis strategy combines cloud provider's built-in security services with a specialized Cloud Workload Protection Platform (CWPP) tailored for serverless, providing comprehensive, agentless runtime protection and threat detection.
- Leverages cloud provider's inherent security capabilities.
- CWPP provides runtime protection for ephemeral serverless functions.
- Offers agentless security for highly dynamic environments.
Memory trick: Serverless needs native eyes and a function shield, no agents allowed.
OT Security Operations Center (OT SOC)
Flip cardAn OT SOC is a specialized security operations center focused on monitoring, detecting, and responding to threats within industrial control systems and operational technology environments.
- Understands unique OT protocols and vulnerabilities.
- Prioritizes system uptime and safety.
- Integrates with OT-specific security tools (e.g., OT IDS/IPS).
Memory trick: An OT SOC is the 'Industrial Watchdog' for 'Critical Operations'.
IoT Device Management
Flip cardThe process of provisioning, authenticating, monitoring, updating, and decommissioning IoT devices throughout their operational lifecycle.
- Crucial for maintaining security and compliance in large IoT deployments.
- Often involves features like secure boot, firmware updates, and certificate management.
- Enables remote management and automation of device operations.
Memory trick: Manage IoT Devices Centrally and Securely
Azure Front Door WAF
Flip cardA Web Application Firewall (WAF) integrated with Azure Front Door that protects web applications from common web vulnerabilities and exploits at the network edge.
- Operates at Layer 7 (application layer)
- Protects against OWASP Top 10 vulnerabilities
- Centralized management and logging
- Global threat intelligence
Memory trick: Front Door WAF guards the web's entrance.
Azure SQL Always Encrypted
Flip cardA feature in Azure SQL Database that protects sensitive data, enabling clients to encrypt data inside client applications before storing it in the database, with encryption keys managed by the client.
- Column-level encryption.
- Client-side encryption, keys managed externally.
- Data remains encrypted in the database, even to DBAs.
- Secure enclaves allow computations on encrypted data.
Memory trick: Always Encrypted means the data stays a secret, even from the database itself.
Microsoft Information Protection (MIP) Sensitivity Labels
Flip cardMicrosoft Information Protection (MIP) sensitivity labels enable organizations to classify and protect their sensitive data across various Microsoft services and applications, and even third-party apps. These labels apply encryption, visual markings, and access restrictions that persist with the content.
- Persistent protection that travels with the data.
- Automated or manual classification and labeling.
- Supports encryption and access restrictions based on label.
- Integrates across Microsoft 365, Azure, and other platforms.
Memory trick: MIP labels are like smart tags that protect your data wherever it goes.
Azure Blob Storage Immutability Policies
Flip cardAllow users to store business-critical data in a WORM (Write Once, Read Many) state, meaning it cannot be modified or deleted for a specified retention interval or until a legal hold is removed.
- Supports time-based retention (fixed period) and legal hold (indefinite until removed).
- Essential for regulatory compliance (e.g., GDPR, HIPAA, SEC 17a-4).
- Protects against accidental and malicious data modification/deletion.
Memory trick: Immutable Versions with CMEK for GDPR Compliance.
Azure Firewall Premium
Flip cardA cloud-native, highly scalable network security service that provides advanced threat protection capabilities, including TLS/SSL inspection, URL filtering, and IDPS, for all traffic flows across Azure Virtual Networks.
- Cloud-native, highly scalable firewall
- Provides advanced threat protection (IDPS, TLS/SSL inspection, URL filtering)
- Centralized management and logging
- Supports both inbound and outbound traffic filtering
Memory trick: Premium Firewall: Inspect, Filter, Detect, Block.
Defender for Cloud - DevOps Security
Flip cardA capability within Microsoft Defender for Cloud that integrates security into the DevOps workflow, providing visibility and protection across multi-pipeline environments by scanning for vulnerabilities and misconfigurations in code, images, and IaC templates.
- Integrates with Azure DevOps, GitHub, and GitLab.
- Scans container images for vulnerabilities.
- Identifies misconfigurations in Infrastructure-as-Code (IaC) templates.
- Shifts security left into the development lifecycle.
Memory trick: DevOps Security: Scan code early, fix issues quickly.
Microsoft Defender for Cloud - DevOps Security
Flip cardMicrosoft Defender for Cloud's DevOps Security capabilities provide comprehensive security management across multi-pipeline environments, integrating security into the development lifecycle from code to cloud.
- Unified visibility and posture management for DevOps.
- Scans code, open-source components, and infrastructure-as-code.
- Helps 'shift-left' security to identify vulnerabilities early.
Memory trick: Defender protects your code from the start of the DevOps journey.
Azure Data Lake Storage Gen2 ACLs
Flip cardAccess Control Lists (ACLs) for Azure Data Lake Storage Gen2 provide granular, POSIX-like permissions at the file and directory level, integrated with Azure Active Directory for identity management.
- Granular permissions for files and directories.
- Integrated with Azure Active Directory identities.
- Supports both owner and named user/group permissions.
Memory trick: ACLs are like bouncers for each file, checking your Azure AD ID.
Azure Data Lake Storage Gen2 ACLs and RBAC
Flip cardAzure Data Lake Storage Gen2 combines Azure Role-Based Access Control (RBAC) for broad permissions at the container or storage account level with POSIX-like Access Control Lists (ACLs) for fine-grained, identity-based access control over individual files and directories.
- Hierarchical namespace support
- RBAC for coarse-grained permissions
- POSIX-like ACLs for fine-grained permissions
- Identity-based access control
Memory trick: RBAC for the forest, ACLs for the trees.
Application-Level Encryption (Client-Side Encryption)
Flip cardApplication-level encryption, or client-side encryption, involves encrypting sensitive data fields within an application before the data is sent to the database. The database then stores only the encrypted ciphertext, and decryption occurs only within the client application.
- Ensures data is encrypted before it reaches the database.
- Database never sees plaintext data or encryption keys.
- Provides granular control over which fields are encrypted.
- Requires application code changes to handle encryption/decryption.
Memory trick: Client-side encryption means the 'secret' stays secret from the start.
Client-side Encryption
Flip cardAn encryption approach where data is encrypted by the application or client device before it is transmitted to and stored in a database or cloud service, ensuring the data never exists in plaintext on the server.
- Encryption occurs at the application/client layer.
- Database/server only receives and stores ciphertext.
- Client (application) manages encryption keys.
- Provides end-to-end encryption for sensitive fields.
Memory trick: Client-side encryption means the secret is locked before it even leaves your hands.
Azure Blob Storage Immutable Storage
Flip cardA feature of Azure Blob Storage that allows users to store business-critical data in a WORM (Write Once, Read Many) state, meaning it cannot be modified or deleted for a specified retention period or indefinitely.
- WORM (Write Once, Read Many) capability
- Supports time-based retention and legal hold
- Protects against accidental or malicious deletion/modification
- Meets regulatory compliance for data retention
Memory trick: Immutable storage makes data 'rock solid' for compliance.
Azure Application Gateway WAF
Flip cardA web traffic load balancer that enables you to manage traffic to your web applications. It includes a Web Application Firewall (WAF) that protects web applications from common web vulnerabilities and exploits.
- Layer 7 (application layer) load balancing.
- Web Application Firewall (WAF) for common web attacks.
- SSL/TLS termination (offloading).
- Ideal for securing web applications like those on Azure App Service.
Memory trick: Application Gateway WAF is the bouncer for your web app, checking for bad guests.
Azure Key Vault Premium Tier
Flip cardThe Azure Key Vault Premium tier provides hardware security module (HSM) backed keys (FIPS 140-2 Level 2 validated) and supports importing or generating keys within FIPS 140-2 Level 3 validated HSMs.
- Offers FIPS 140-2 Level 3 validated HSMs for key protection.
- Suitable for highly regulated industries requiring strict key management.
- Higher cost due to dedicated HSM resources.
Memory trick: Premium is for top-tier, hardware-backed keys and compliance.
Azure Information Protection (AIP) Sensitivity Labels
Flip cardLabels that can be applied to documents and emails to classify them according to their sensitivity, and then apply protection policies such as encryption, access restrictions, and visual markings.
- Supports manual, recommended, or automatic labeling.
- Integrates with Microsoft 365 services and other Azure services.
- Helps enforce data governance and regulatory compliance.
Memory trick: AIP Labels and Policies for Sensitive Data.
Managed Identities for Azure Resources
Flip cardAn Azure Active Directory feature that provides Azure services with an automatically managed identity in Azure AD, allowing them to authenticate to other Azure services without requiring developers to manage credentials.
- Eliminates the need for credential management in code.
- Identities are automatically managed by Azure.
- Supports both system-assigned and user-assigned identities.
- Uses OAuth 2.0 and Azure AD for authentication.
Memory trick: Managed Identity: Azure handles the key, not your code.
Microsoft Purview
Flip cardMicrosoft Purview is a unified data governance service that helps organizations manage and govern their on-premises, multi-cloud, and SaaS data. It offers data discovery, sensitive data classification, end-to-end data lineage, and a comprehensive data catalog.
- Unified data governance for hybrid and multi-cloud environments.
- Automated data discovery and classification.
- Provides data lineage for understanding data origins and transformations.
Memory trick: Purview gives you a clear view of all your data for governance.
Azure Private Link
Flip cardA service that provides private connectivity from an Azure virtual network to Azure PaaS services, customer-owned services, or Azure-hosted partner services. It uses private endpoints to bring services into your VNet, ensuring traffic stays on the Azure backbone.
- Private connectivity to Azure PaaS services (e.g., SQL DB, Storage, Cosmos DB)
- Traffic remains on the Azure backbone network
- Bypasses the public internet
- Uses private IP addresses within your VNet
Memory trick: Private Link is your personal Azure highway.
Azure Key Vault Managed HSM
Flip cardA fully managed, highly available, single-tenant, FIPS 140-2 Level 3 validated hardware security module (HSM) service for storing and managing cryptographic keys.
- Dedicated, single-tenant HSMs
- FIPS 140-2 Level 3 validated
- Full control over HSMs
- Ideal for high-value keys and regulatory compliance
Memory trick: Managed HSM is your own 'private vault' of keys.
Azure Managed Identities
Flip cardAzure Managed Identities provide an identity for Azure services in Azure Active Directory (Azure AD). This allows Azure services to authenticate to other services that support Azure AD authentication without developers having to manage credentials.
- Eliminates the need for hardcoded credentials.
- Automatically managed by Azure AD.
- Supports system-assigned and user-assigned identities.
- Enhances security posture by reducing credential exposure.
Memory trick: Managed Identities give your services their own 'ID badge' for Azure AD.
Azure Key Vault Certificates
Flip cardAzure Key Vault can securely store and manage X.509 certificates, allowing for automated renewal and deployment, crucial for TLS/SSL.
- Centralized certificate management.
- Automated certificate renewal.
- Integration with Azure services like App Service.
Memory trick: Keys and secrets for secure communication live in the Vault.
Azure Confidential Computing
Flip cardA technology that protects data in use by performing computations within a hardware-based Trusted Execution Environment (TEE), ensuring data remains encrypted even during processing.
- Protects data in use (during computation).
- Utilizes hardware-based Trusted Execution Environments (TEEs).
- Minimizes exposure risk during sensitive data processing.
Memory trick: Confidential Computing keeps secrets safe even while thinking.
Azure SQL Always Encrypted with Secure Enclaves
Flip cardAn Azure SQL Database feature that allows sensitive data to remain encrypted throughout its lifecycle (at rest, in transit, and in use) by performing computations on encrypted data inside a secure enclave, ensuring cryptographic separation from database administrators and other privileged users.
- Protects data in use within a secure enclave.
- Cryptographic separation between application and DBA.
- Supports rich computations on encrypted data.
- Enhances confidentiality for highly sensitive data.
Memory trick: Always Encrypted + Enclaves: Even DBAs can't peek.
AKS with Kata Containers
Flip cardAzure Kubernetes Service (AKS) integration with Kata Containers, providing enhanced security isolation for individual containers by running them within lightweight virtual machines (VMs), leveraging hardware virtualization.
- Container-in-VM isolation
- Leverages hardware virtualization (Intel VT-x, AMD-V)
- Mitigates container escape vulnerabilities
- Suitable for multi-tenant and highly sensitive workloads
Memory trick: Kata cuts containers into isolated VMs.
Client-Side Encryption for NoSQL (Cosmos DB)
Flip cardAn encryption method for NoSQL databases like Azure Cosmos DB where the client application encrypts specific data fields before sending them to the database. This ensures that sensitive data is encrypted before it leaves the client and that the encryption keys are managed by the client, not the database service.
- Encryption performed by the client application.
- Keys are managed by the client, often in a secure key store.
- Data is encrypted in transit and at rest from the database's perspective.
- Provides strong data confidentiality and control for sensitive data.
Memory trick: Client-side keys: My app holds the key, not the cloud.
Microsoft Purview Information Protection (Sensitivity Labels)
Flip cardA unified data governance and protection solution that allows organizations to classify, label, and protect sensitive data across clouds, on-premises, and endpoints using sensitivity labels, providing encryption, visual marking, and access controls.
- Classifies and labels data based on sensitivity
- Applies automated encryption and access restrictions
- Includes visual markings (headers, footers, watermarks)
- Works across Microsoft 365, Azure, on-premises, and third-party apps
Memory trick: Purview's labels protect data everywhere.
Azure Data Lake Storage Gen2 Security
Flip cardSecuring Azure Data Lake Storage Gen2 involves a combination of encryption (PMEK/CMEK), access control (RBAC, ACLs), and network security (Private Endpoints, firewalls) to protect sensitive data at scale.
- Supports both RBAC and POSIX-like ACLs for granular access control.
- Integrates with Azure Active Directory for identity management.
- Offers both platform-managed and customer-managed encryption keys for data at rest.
Memory trick: CMEK & RBAC for Data Lake Protection.