Microsoft Security Operations Analyst flashcards
150 free flashcards. Tap a card to flip it.
Defender for Cloud Continuous Export
Flip cardContinuous export in Microsoft Defender for Cloud enables the automatic streaming of security alerts and recommendations to Azure Monitor Log Analytics workspaces, Azure Event Hubs, or Azure Storage for further analysis, reporting, or integration with SIEM/SOAR solutions.
- Streams data in near real-time.
- Supports alerts and recommendations.
- Essential for SIEM/SOAR integration (e.g., Microsoft Sentinel).
- Configurable at the subscription or management group level.
Memory trick: Export's ease: Alerts flow freely, into the SIEM's sea.
Azure Arc and Azure Monitor Agent (AMA)
Flip cardAzure Arc extends Azure management and services to on-premises and multi-cloud environments, while the Azure Monitor Agent (AMA) is the primary agent used to collect monitoring and security data from these connected resources for services like Microsoft Defender for Cloud.
- Azure Arc enables hybrid cloud management.
- AMA collects security events, performance data, and logs.
- Required for onboarding non-Azure servers to Defender for Cloud.
- Replaces the legacy Log Analytics agent for new deployments.
Memory trick: To bring on-prem to the cloud's secure arc, AMA is the mark.
Custom Azure Policy for Endpoint Exemption
Flip cardCustom Azure Policies can be used in Microsoft Defender for Cloud to create exemptions for built-in security recommendations, allowing organizations to maintain compliance while using alternative security controls, such as a specific third-party EDR solution.
- Provides granular control over recommendation evaluation.
- Allows for 'DeployIfNotExists' or 'AuditIfNotExists' effects.
- Can be based on resource tags, installed software, or other properties.
- Helps achieve accurate secure score and compliance reporting.
Memory trick: Policy's precision: Exempt specific, enforce general, ensure compliance.
Microsoft Defender for Key Vault
Flip cardMicrosoft Defender for Key Vault provides an additional layer of intelligence that detects unusual and potentially harmful attempts to access or exploit Key Vault accounts. It monitors for suspicious activities like unusual access patterns, excessive secret retrieval, or potential brute-force attacks.
- Protects Azure Key Vaults.
- Detects suspicious access patterns and key vault operations.
- Generates security alerts for immediate investigation.
Memory trick: For the secrets in the vault, Defender for Key Vault calls a halt.
Adaptive Network Hardening
Flip cardAdaptive Network Hardening in Microsoft Defender for Cloud uses machine learning to analyze network traffic patterns and existing NSG rules to provide recommendations for more restrictive NSG rules, reducing the network attack surface by ensuring only necessary ports and protocols are open.
- Uses machine learning to analyze actual traffic.
- Recommends granular NSG rules (inbound/outbound).
- Reduces network attack surface and helps identify suspicious open ports.
Memory trick: Adaptive hardening, smart rules it weaves, based on the traffic, what it perceives.
Defender for Servers Plan 2
Flip cardThe advanced tier of Microsoft Defender for Servers that provides comprehensive threat protection, endpoint detection and response (EDR), and integrated vulnerability assessment solutions for virtual machines and physical servers.
- Includes Microsoft Defender for Endpoint integration.
- Offers integrated vulnerability assessment (Qualys/Defender Vulnerability Management).
- Provides JIT VM access and adaptive application controls.
- Delivers advanced threat detection for server workloads.
Memory trick: For VMs, if you need full VA, Plan 2 is the way.
Integrated Vulnerability Assessment (Defender for Cloud)
Flip cardMicrosoft Defender for Cloud offers integrated vulnerability assessment solutions to scan virtual machines and containers for software vulnerabilities, providing actionable recommendations for remediation.
- Scans VMs and containers for known vulnerabilities.
- Provides detailed reports and remediation steps.
- Integrated with Defender for Servers Plan 2 and Defender for Containers.
Memory trick: Scan the VM, then patch the flaw, to keep the bad guys out of the law.
Azure Arc and Azure Monitor Agent (Hybrid Security)
Flip cardAzure Arc extends Azure management to on-premises and multi-cloud environments, treating non-Azure machines as Azure resources. The Azure Monitor Agent (AMA) is then installed on these Arc-enabled servers to collect security logs and data for Microsoft Defender for Cloud and other Azure monitoring services.
- Azure Arc enables management of non-Azure machines as Azure resources.
- Azure Monitor Agent collects data for Defender for Cloud.
- Essential for extending Defender for Cloud to hybrid environments.
Memory trick: Arc bridges the gap, AMA gathers the data, for Defender's security, it's the right strata.
Defender for Cloud Recommendation Exclusions
Flip cardA feature in Microsoft Defender for Cloud that allows specific resources or entire subscriptions to be exempted from certain security recommendations, typically for valid business reasons, without negatively impacting the secure score for non-exempted resources.
- Helps manage secure score accurately.
- Can be applied to subscriptions, resource groups, or individual resources.
- Requires justification and can be time-limited.
Memory trick: Recommendations guide, but exclusions handle unique needs.
Defender for Cloud Alert Suppression
Flip cardA feature in Microsoft Defender for Cloud that allows organizations to automatically dismiss or hide specific alerts based on defined criteria, reducing alert noise and improving analyst efficiency.
- Configurable by alert type, entity, IP address, etc.
- Can be set for a specific duration or indefinitely.
- Helps analysts focus on genuine threats.
Memory trick: Too many alerts? Suppress the noise, focus on the signal.
Defender for App Service & DNS
Flip cardMicrosoft Defender for App Service protects web applications from attacks targeting the web layer, while Microsoft Defender for DNS detects suspicious DNS queries and communications, together providing comprehensive network-level threat protection for web applications.
- App Service protects against web-specific attacks (e.g., SQL injection, XSS).
- DNS protects against domain-related threats (e.g., C2 callbacks, phishing).
- Both contribute to network-level security visibility.
Memory trick: Web apps need App Service shield, and DNS needs its own guard.
Azure Arc & Azure Monitor Agent for Hybrid Security
Flip cardFor on-premises servers to be fully integrated with Microsoft Defender for Cloud for security posture, vulnerability management, and threat protection, they require both the Azure Connected Machine agent (for Azure Arc onboarding) and the Azure Monitor Agent (AMA) for data collection.
- Azure Arc agent connects non-Azure machines to Azure.
- AMA collects logs and metrics, including security events.
- Defender for Cloud uses AMA data for security insights and alerts.
- MMA is being replaced by AMA.
Memory trick: Arc connects the house, AMA collects the security clues.
Azure Policy 'Modify' Effect for Enforcement
Flip cardThe 'Modify' effect in Azure Policy is used to add, update, or delete properties or tags on a subscription or resource. It can be used to automatically enforce security settings by modifying resource properties to meet compliance standards, such as enabling MFA-related settings or parameters within a policy definition.
- Automatically updates properties of existing resources/subscriptions.
- Requires a managed identity for remediation.
- Can enforce configurations like MFA settings or tagging standards.
Memory trick: To change a setting, make it true, the Modify effect will see it through.
Just-in-Time (JIT) VM Access
Flip cardA feature in Microsoft Defender for Cloud that hardens network access to virtual machines by locking down inbound traffic to management ports, only opening them on demand for a limited time and from approved source IPs.
- Reduces attack surface by restricting port exposure.
- Allows legitimate access only when needed.
- Integrates with Azure Active Directory for authorization.
- Automatically closes ports after a defined time.
Memory trick: To close the RDP door, but still allow a knock, JIT access is your clock.
Auto-provisioning (Defender for Cloud)
Flip cardAuto-provisioning in Microsoft Defender for Cloud enables the automatic deployment of relevant agents and extensions (e.g., Log Analytics agent, Azure Monitor Agent, Defender for Endpoint extension) to supported Azure resources, ensuring they are protected by Defender for Cloud plans.
- Automates agent deployment for Defender for Cloud plans.
- Ensures consistent security coverage for new and existing resources.
- Reduces manual effort for onboarding resources.
Memory trick: Auto-provisioning means 'set it and forget it' for Defender's agents.
Azure Policy 'Modify' Effect
Flip cardThe 'Modify' effect in Azure Policy is used to add, update, or remove properties or tags on existing Azure resources or resource groups, enabling automatic remediation of non-compliant configurations.
- Requires a managed identity to perform changes.
- Can be used to enforce specific configurations (e.g., encryption settings, tags).
- Applies to existing resources and can be used on new creations.
Memory trick: Policy effects: Audit, Deny, Deploy, Modify – each has a job.
Defender for Cloud Workflow Automation
Flip cardA feature in Microsoft Defender for Cloud that enables automated responses to security alerts and recommendations by triggering Azure Logic Apps or Azure Functions, streamlining incident response.
- Automates repetitive security tasks.
- Integrates with Azure Logic Apps and Azure Functions.
- Can perform actions like quarantining, sending notifications, or opening tickets.
- Reduces manual effort and response time to security events.
Memory trick: For alerts to auto-act, workflow automation is the pact.
Defender for Cloud Enhanced Security Features
Flip cardA comprehensive set of security capabilities within Microsoft Defender for Cloud that provides advanced threat protection and security posture management for various Azure, hybrid, and multi-cloud resources.
- Includes automatic onboarding and agent deployment.
- Offers advanced threat detection and vulnerability assessments.
- Provides security recommendations and regulatory compliance.
- Consolidates security management across different resource types.
Memory trick: To secure all in the cloud, enhance it loud!
Azure Arc for Multi-Cloud Security
Flip cardAzure Arc extends Azure management and security services, including Microsoft Defender for Cloud, to resources running across multi-cloud (AWS, GCP) and on-premises environments, providing a unified control plane.
- Connects servers, Kubernetes clusters, and data services to Azure.
- Enables Defender for Cloud features like vulnerability assessment and threat detection for non-Azure resources.
- Provides a single pane of glass for hybrid and multi-cloud security.
- Requires installing the Azure Connected Machine agent on the non-Azure VMs.
Memory trick: Arc's embrace: Unites all clouds under Azure's grace.
Unsupported Operating Systems
Flip cardOperating system versions that have reached their end-of-life (EOL) and no longer receive security updates, bug fixes, or technical support from the vendor, posing significant security risks.
- Vulnerable to unpatched exploits.
- No new security patches are released.
- May not be compliant with regulatory standards.
- Requires migration or decommissioning for effective risk management.
Memory trick: An old OS, no longer supported, must be upgraded or discarded, for new security to be afforded.
Azure Policy 'DeployIf NotExists'
Flip cardThe 'DeployIf NotExists' effect in Azure Policy is used to automatically deploy a resource (e.g., enable a security setting, deploy an extension) or modify an existing resource if a specified condition is not met on the target resource.
- Used for automatic remediation of non-compliant resources.
- Requires a managed identity for deployment/modification actions.
- Commonly used to enforce security baselines or enable Defender features.
Memory trick: If it's not there, deploy it there, to keep compliance in the air.
Azure Policy 'DeployIfNotExists' Effect
Flip cardAn Azure Policy effect that ensures a specific resource or configuration is deployed if it's not detected on a target resource, commonly used for automated remediation and baseline enforcement.
- Used to automatically deploy missing resources or configurations.
- Evaluated after resource creation or update.
- Ideal for deploying agents, extensions, or enabling settings.
- Supports compliance by ensuring required components are present.
Memory trick: If the agent is not there, 'DeployIfNotExists' will show care.
Defender for Cloud Regulatory Compliance Dashboard
Flip cardThe regulatory compliance dashboard in Microsoft Defender for Cloud provides a centralized view of compliance status against various regulatory standards and custom policies, enabling continuous assessment and reporting.
- Maps security recommendations to compliance controls.
- Supports built-in and custom compliance standards (Azure Policy initiatives).
- Provides a compliance score for each standard.
- Helps identify and remediate non-compliant resources.
Memory trick: Compliance's core: Custom rules, constant checks, clear reports.
Alert Suppression Rules (Defender for Cloud)
Flip cardAlert suppression rules in Microsoft Defender for Cloud allow security teams to reduce alert fatigue by automatically dismissing or hiding specific alerts that are known to be benign, expected, or false positives, based on defined criteria.
- Reduces alert noise and false positives.
- Configurable based on alert name, entities, resource groups, etc.
- Helps SOC teams focus on critical threats.
Memory trick: Too much alert sound? Suppress the noise that's not profound.
Azure Policy for MFA Enforcement
Flip cardAzure Policy can be used to enforce security requirements, such as requiring Multi-Factor Authentication (MFA) for specific administrative roles, ensuring compliance and enhancing security posture across Azure resources.
- Automates compliance checks and enforcement.
- Can target subscriptions, management groups, or resource groups.
- Ensures consistent security configurations.
- Helps improve secure score by addressing recommendations.
Memory trick: Policy's plan: Protect owners, Prevent breaches, Perfect posture.
Custom Security Policies (Azure Policy)
Flip cardMechanisms within Microsoft Defender for Cloud, powered by Azure Policy, allowing organizations to define and enforce custom security configurations and compliance requirements across their Azure resources.
- Extends Defender for Cloud's capabilities beyond built-in recommendations.
- Enables enforcement of specific organizational security baselines.
- Allows for auditing compliance and auto-remediation.
- Uses Azure Policy definitions, assignments, and initiatives.
Memory trick: Custom rules need a policy tool, not just an alert or a dashboard cool.
Defender for Cloud Auto-provisioning
Flip cardMicrosoft Defender for Cloud's auto-provisioning capability automatically deploys security-related agents and extensions to Azure, hybrid, and multi-cloud machines, ensuring consistent security monitoring and posture management.
- Leverages Azure Policy's 'DeployIfNotExists' effect.
- Ensures agents like Log Analytics agent are installed.
- Can deploy Azure Disk Encryption and Endpoint Protection.
- Simplifies initial setup and ongoing compliance for VMs.
Memory trick: Auto-deploy's aim: Agents always on, always active.
Quick Fix (Azure Policy)
Flip cardAutomated remediation actions in Microsoft Defender for Cloud, often leveraging Azure Policy's 'deployIfNotExists' effect, to bring non-compliant resources into compliance with security recommendations.
- Streamlines remediation of common security findings.
- Relies on Azure Policy definitions and assignments.
- Applies configurations or deploys resources automatically.
- Reduces manual effort for security posture management.
Memory trick: A quick fix for a setting, Policy's deployIfNotExists is the betting.
Defender for Storage
Flip cardA Microsoft Defender for Cloud plan that provides advanced threat protection for Azure Storage accounts, detecting suspicious activities like unauthorized access, unusual data exfiltration, and malware uploads.
- Monitors for suspicious activities in Azure Storage.
- Detects malware uploads and sensitive data access anomalies.
- Provides recommendations for storage account security posture.
- Supports Blob, File, Azure Data Lake Store Gen2, and Queue storage.
Memory trick: For storage security, Defender for Storage is the key.
Adaptive Application Controls
Flip cardA feature in Microsoft Defender for Cloud that helps to harden virtual machines by intelligently recommending, and optionally enforcing, an allowlist of applications that are permitted to run on the servers.
- Reduces the risk of malware and unauthorized software execution.
- Learns legitimate application behavior over time.
- Generates rules to allow only known-good applications.
- Requires the Defender for Servers Plan 2.
Memory trick: To control what apps can run free, Adaptive Controls are the key.