Microsoft Cybersecurity Architect (SC-100) flashcards
131 free flashcards. Tap a card to flip it.
Dynamic Access Policies (Continuous Access Evaluation)
Flip cardA Zero Trust mechanism that enables the continuous re-evaluation of access during an active session based on real-time signals, such as changes in user location, device posture, or detected risk events. It ensures that trust is never implicit and access can be revoked immediately if risk conditions change.
- Continuous re-evaluation during active session
- Based on real-time signals
- Revokes access immediately if risk changes
- Never implicit trust
Memory trick: Access is a constantly moving target, always re-checked.
Azure Active Directory (Azure AD)
Flip cardMicrosoft's cloud-based identity and access management service, providing identity for users, groups, and applications.
- Central component for Zero Trust implementation in Azure.
- Supports single sign-on (SSO), multi-factor authentication (MFA), and conditional access.
- Integrates with on-premises Active Directory.
Memory trick: Zero Trust: Never Trust, Always Verify, Constantly Monitor.
Customer-Managed Keys (CMK) in Azure
Flip cardA feature that allows customers to manage their own encryption keys for data at rest in Azure services, often using Azure Key Vault. This provides greater control over key lifecycle, including rotation and revocation, for compliance and security.
- Customer controls encryption keys.
- Keys stored securely in Azure Key Vault.
- Enables key rotation and revocation.
- Meets stringent regulatory and compliance requirements.
Memory trick: Customer-Managed Keys in Key Vault give you full control.
Microsoft Purview Information Protection (MPIP)
Flip cardMPIP is a solution that helps organizations discover, classify, label, and protect sensitive information across documents and emails, providing persistent protection wherever the data travels.
- Enables automatic and manual data classification.
- Applies encryption and access restrictions to sensitive content.
- Provides persistent protection even when data is shared outside the organization.
Memory trick: Purview 'protects your view' of sensitive data, everywhere.
Use Least Privilege (Zero Trust)
Flip cardThe Zero Trust principle of 'Use Least Privilege' mandates that every user, device, and application should be granted only the minimum necessary permissions to perform its required task, for the shortest possible duration.
- Minimizes the attack surface and potential damage from a breach.
- Limits lateral movement for attackers.
- Requires just-in-time and just-enough access.
Memory trick: The Zero Trust Trio: 'Verify, Least, Assume'.
Microsoft Defender for Cloud (Multi-Cloud CSPM & CWP)
Flip cardMicrosoft Defender for Cloud is a unified security management solution that provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across hybrid and multi-cloud environments.
- Offers security posture management across Azure, AWS, and GCP.
- Provides threat protection for various workload types.
- Helps identify misconfigurations and enforce compliance standards.
Memory trick: Defender for Cloud 'defends your diverse digital domain'.
Azure Confidential Computing (ACC)
Flip cardA set of technologies that protects data while it's being processed in memory, using hardware-based Trusted Execution Environments (TEEs) to isolate and encrypt data from the operating system, hypervisor, and cloud administrators.
- Protects data 'in use' (during computation).
- Uses hardware-based Trusted Execution Environments (TEEs).
- Ensures data remains encrypted and isolated from cloud operators and privileged software.
Memory trick: Confidential Computing keeps your secrets safe from everyone, even while the computer is thinking about them.
Azure Blob Immutability Policies
Flip cardA feature of Azure Blob Storage that enables Write Once, Read Many (WORM) support, allowing data to be stored in a non-erasable, non-rewritable format for a specified duration.
- Prevents modification and deletion of data.
- Supports both time-based retention and legal holds.
- Ensures compliance with regulatory requirements like SEC 17a-4(f).
Memory trick: Immutability policies make Blob data 'set in stone' for compliance, no matter who tries to change it.
Microsoft Purview (formerly Azure Purview)
Flip cardA unified data governance solution that helps organizations manage and govern their on-premises, multi-cloud, and SaaS data, providing data discovery, classification, lineage, and a data catalog.
- Automated data discovery and classification.
- Applies sensitivity labels for data protection.
- Provides a data catalog for business users and data lineage for compliance.
Memory trick: Purview is your data's librarian and detective, finding, classifying, and tracking every book in your digital library.
Azure Files with Azure AD DS authentication
Flip cardA managed file share service in Azure that provides cloud file shares accessible via industry-standard SMB or NFS protocols, with support for identity-based authentication using Azure Active Directory Domain Services.
- Provides SMB/NFS file shares for lift-and-shift of legacy applications.
- Enables granular, identity-based access control using Azure AD DS.
- Offers high availability and disaster recovery for file data.
Memory trick: Azure Files with AD DS makes old file shares feel right at home in the cloud, using familiar IDs.
Client-side encryption for Azure Cosmos DB
Flip cardA feature that enables applications to encrypt sensitive data before sending it to Azure Cosmos DB, ensuring that the data is never exposed in plaintext to the database service.
- Encryption occurs at the application layer.
- Encryption keys are managed by the client application owners.
- Data remains encrypted throughout its lifecycle in Cosmos DB.
Memory trick: Client-side encryption keeps Cosmos DB data a secret, even from the cloud, by encrypting before it leaves your app.