Microsoft Security, Compliance, and Identity Fundamentals (SC-900) flashcards
111 free flashcards. Tap a card to flip it.
Auditing (Accountability)
Flip cardThe process of systematically examining and recording system activities, data access, and user actions to ensure compliance, detect anomalies, and establish accountability.
- Creates an immutable record of 'who, what, when, where'.
- Crucial for forensic investigations and compliance.
- Helps enforce non-repudiation.
Memory trick: Auditing: The security camera and logbook of data.
Microsoft Entra Domain Services
Flip cardProvides managed domain services such as domain join, group policy, lightweight directory access protocol (LDAP), and Kerberos/NTLM authentication that are fully compatible with Windows Server Active Directory.
- Enables lift-and-shift of legacy applications to Azure
- No need to deploy, manage, or patch domain controllers
- Integrates with existing Microsoft Entra ID tenant
Memory trick: Old apps in cloud need a familiar AD hug.
User and Entity Behavior Analytics (UEBA)
Flip cardUEBA is a cybersecurity process that leverages machine learning and deep learning algorithms to analyze user and entity behavior patterns, identify deviations from normal baselines, and detect potential threats or attacks.
- Establishes baselines of normal behavior.
- Detects anomalies indicative of threats.
- Identifies insider threats and compromised accounts.
Memory trick: UEBA watches for the odd ones out in behavior patterns.
Microsoft Entra Conditional Access
Flip cardA feature that allows administrators to enforce policies for accessing resources based on various conditions like user, location, device, and application.
- Enables granular access control
- Integrates with other Microsoft services like Intune
- Supports Zero Trust principles
Memory trick: Conditions dictate who gets through the access gate.
Microsoft Entra PIM
Flip cardA service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in Microsoft Entra ID, Azure, and other Microsoft Online Services.
- Provides just-in-time (JIT) privileged access.
- Enforces approval workflows for role activation.
- Offers role activation notifications and audit history.
Memory trick: PIM protects the crown, ensuring only the right people wear it, and only when needed.
Zero Trust
Flip cardA security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter.
- Operates on the principle 'never trust, always verify'.
- Assumes breach is inevitable and continuously verifies.
- Applies to all users, devices, applications, and data.
Memory trick: Zero Trust: No one gets a free pass.
Microsoft Entra MFA
Flip cardA security measure requiring users to provide two or more verification factors to prove their identity during sign-in.
- Adds an extra layer of security beyond just a password
- Supports various methods: app notifications, codes, biometrics, hardware tokens
- Can be enforced conditionally based on risk factors
Memory trick: More factors mean more security for your login.
FIDO2 Security Key
Flip cardA hardware-based authentication method that provides passwordless sign-in to Microsoft Entra ID and other services, adhering to FIDO2 standards.
- Enables passwordless authentication.
- Uses dedicated hardware devices.
- Offers enhanced security against phishing.
Memory trick: FIDO's Key unlocks without a password.
Microsoft Entra Connect
Flip cardA tool that synchronizes on-premises directories with Microsoft Entra ID, enabling hybrid identity scenarios.
- Connects on-premises AD DS with Microsoft Entra ID
- Enables password hash synchronization, pass-through authentication, and federation integration
- Supports device writeback and attribute writeback
Memory trick: Connect the cloud to your local directory.
Microsoft Entra B2B Collaboration
Flip cardA feature of Microsoft Entra ID that enables organizations to securely share their applications and resources with guest users from any organization or social identity, allowing them to sign in with their own credentials.
- Invites external users (guests) to access resources
- Guests use their own identities (Microsoft Entra ID, social)
- Streamlines onboarding/offboarding for partners/contractors
Memory trick: B2B: 'Bring Your Own ID' for seamless collaboration.
Encryption
Flip cardThe process of converting information or data into a code to prevent unauthorized access, making it unreadable without the correct key.
- Protects data at rest and in transit.
- Uses algorithms and cryptographic keys.
- Essential for confidentiality and data privacy.
Memory trick: Encryption is like putting your secret message in a locked box that only those with the right key can open.
Microsoft Entra Application Proxy
Flip cardA Microsoft Entra feature that provides secure remote access to on-premises web applications and other internal resources, without requiring a VPN or exposing the internal network directly.
- Publishes internal web applications for external access.
- Integrates with Microsoft Entra ID for authentication and authorization (SSO, Conditional Access).
- Eliminates the need for VPNs for specific applications.
- Uses a connector to establish an outbound-only connection to Azure.
Memory trick: App Proxy: Your on-prem apps, now global and secure.
Microsoft Entra Connect Sync
Flip cardThe core synchronization service within Microsoft Entra Connect that manages the flow of identity data between on-premises Active Directory and Microsoft Entra ID.
- Handles complex multi-forest Active Directory topologies
- Supports advanced attribute filtering, transformations, and custom rules
- Manages identity object lifecycle including users, groups, and contacts
Memory trick: Connect Sync unifies your tangled forests into one cloud identity.
Identity Governance
Flip cardA framework that ensures the right people have the right access to the right resources at the right time, managing the full lifecycle of identities and their access rights.
- Includes access reviews, entitlement management, and lifecycle management.
- Crucial for compliance and security.
- Often implemented with tools like Azure AD Identity Governance.
Memory trick: Identity Governance: 'The conductor of the identity orchestra, ensuring everyone plays their part correctly.'
Microsoft Entra Access Reviews
Flip cardAn identity governance feature that enables organizations to efficiently manage group memberships, access to enterprise applications, and privileged role assignments.
- Automates periodic review and certification of access.
- Reviewers can be group owners or business users.
- Can automatically remove access for unapproved users.
Memory trick: Access Reviews are like a regular audit to make sure everyone still needs their keys.
Microsoft Entra Privileged Identity Management (PIM)
Flip cardA Microsoft Entra feature that helps manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services, by providing just-in-time and time-bound access.
- Enables 'just-in-time' (JIT) access for privileged roles.
- Provides time-bound access assignments.
- Incorporates approval workflows for role activation.
- Offers auditing and reporting on privileged access.
Memory trick: PIM: Princes only get the crown when needed, for a short reign.
Microsoft Entra Entitlement Management
Flip cardA Microsoft Entra ID governance capability that enables organizations to manage identity and access lifecycle at scale by automating access requests, approvals, provisioning, and deprovisioning.
- Allows delegation of access management to business owners.
- Uses 'access packages' to bundle resources (groups, apps, SharePoint).
- Automates access lifecycle for internal and external users.
Memory trick: Entitlement Management is like a self-service kiosk for access, with managers approving the orders.
Microsoft Entra multifactor authentication (MFA)
Flip cardA security system that requires users to provide two or more verification methods to gain access to a resource, significantly enhancing security.
- Adds an extra layer of security beyond just a password.
- Common verification methods include phone calls, text messages, or authenticator apps.
- Helps protect against credential theft and unauthorized access.
Memory trick: MFA: More Factors for Access.
FIDO2 (Fast Identity Online 2) security keys
Flip cardA passwordless authentication standard that uses public-key cryptography and physical security keys to provide strong, phishing-resistant authentication for web services.
- Uses asymmetric cryptography (public/private key pairs)
- Offers phishing resistance
- Compatible with various devices and platforms
Memory trick: Physical key unlocks access, no password needed.
Data Integrity
Flip cardThe principle of ensuring that data is accurate, complete, and trustworthy, and has not been altered or destroyed in an unauthorized or accidental manner.
- Protects against unauthorized modification or deletion.
- Ensures data accuracy and consistency.
- Crucial for reliable decision-making and compliance.
Memory trick: CIA: Confidentiality, Integrity, Availability – keeping data safe, sound, and ready.
Multi-Factor Authentication (MFA)
Flip cardA security system that requires users to provide two or more verification factors to gain access to a resource.
- Enhances security by requiring multiple proofs of identity.
- Combines different types of authentication factors (e.g., something you know, something you have, something you are).
- Significantly reduces the risk of unauthorized access.
Memory trick: Many Factors Secure Access
Identity and Access Management (IAM)
Flip cardA framework of policies and technologies for ensuring that the right individuals and things have the right access to the right resources at the right time and for the right reasons.
- Manages user identities and their access privileges.
- Includes authentication, authorization, and user lifecycle management.
- Central to modern security strategies.
Memory trick: IAM is the bouncer and guest list for all digital parties.
Supply Chain Security
Flip cardSupply Chain Security in software refers to the measures taken to protect the integrity, confidentiality, and availability of all components, processes, and relationships involved in producing and delivering software, from development to deployment.
- Secures third-party libraries and open-source components.
- Prevents injection of malicious code or vulnerabilities.
- Ensures the integrity of the software artifact from source to production.
Memory trick: Secure the entire software journey, piece by piece.
Directory Services
Flip cardA centralized, hierarchical database that stores information about network resources and users, enabling efficient management and access control.
- Examples include Active Directory and Azure Active Directory.
- Provides a single source of truth for user identities.
- Facilitates authentication and authorization across an organization's resources.
Memory trick: Directory is the phone book of users
Federated Identity
Flip cardA system that allows a user to access resources across different security domains using a single identity, typically managed by their home organization.
- Enables Single Sign-On (SSO) across organizations.
- Eliminates the need for external users to have multiple credentials.
- Often implemented using standards like SAML, OAuth, or OpenID Connect.
Memory trick: Federated: Friends Exchange IDs.
Microsoft Entra Verified ID
Flip cardA decentralized identity solution that enables organizations to issue, hold, and verify digital credentials based on open standards, giving individuals control over their identity information.
- Decentralized identity (DID) solution
- Users control their digital credentials
- Secure, privacy-preserving identity verification
Memory trick: Verified ID: 'You own your digital passport, not the government'.
Auditing (Accounting)
Flip cardThe process of recording and reviewing events and actions within a security system to maintain a log of activity, crucial for accountability and forensic analysis.
- Tracks user actions and system events.
- Provides a trail for accountability and non-repudiation.
- Essential for compliance and security investigations.
Memory trick: Auditing Always Accounts for Actions.
Conditional Access
Flip cardA security feature that evaluates specific conditions (e.g., user, location, device, risk) to determine if and how a user can access a resource.
- Enforces policies based on real-time conditions.
- Can block access, require MFA, or limit capabilities.
- Integrates with identity providers and device management.
Memory trick: Conditional Access Adjusts to Context
General Data Protection Regulation (GDPR)
Flip cardA regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area.
- Mandates strict rules for processing personal data.
- Grants individuals rights over their data (e.g., right to access, erasure).
- Applies to any organization processing EU citizens' data, regardless of location.
Memory trick: EU citizens' data needs GDPR protection.
Microsoft Entra Authentication
Flip cardThe process by which Microsoft Entra ID verifies a user's identity to grant access to resources.
- Enables single sign-on (SSO) for cloud applications.
- Supports various methods like password, MFA, passwordless.
- Centralizes identity verification for Microsoft cloud services.
Memory trick: Think of authentication as the bouncer checking your ID at the cloud club.
Information Protection
Flip cardA comprehensive strategy and set of technologies for identifying, classifying, labeling, and protecting sensitive data throughout its lifecycle.
- Discovers sensitive data across disparate sources.
- Applies labels and encryption based on sensitivity.
- Helps comply with data privacy regulations.
Memory trick: Information Protection finds, labels, and locks your data.
Microsoft Entra Application Management
Flip cardThe capability within Microsoft Entra ID that allows organizations to manage access to all applications (cloud-based and on-premises) by integrating them with Entra ID for authentication, authorization, and centralized user experience.
- Centralizes application access control
- Supports various authentication protocols (SAML, OIDC, password SSO)
- Enables Single Sign-On (SSO) for integrated apps
Memory trick: One control panel for all your digital doors.
Least Privilege
Flip cardA security principle where a user or process is granted only the minimum access rights needed to perform its function.
- Reduces the attack surface.
- Limits potential damage from breaches.
- Fundamental to secure system design.
Memory trick: Least Privilege: 'Just enough keys, not the whole keyring.'
Network Security
Flip cardMeasures taken to protect the underlying networking infrastructure and network traffic from unauthorized access, misuse, malfunction, modification, destruction, or improper disclosure.
- Includes firewalls, intrusion detection/prevention systems, VPNs.
- Focuses on controlling traffic flow and securing network devices.
- Aims to prevent network-based attacks.
Memory trick: Network Security is like a border patrol for your data, checking every package.
Single Sign-On (SSO)
Flip cardAn authentication scheme that allows a user to log in with a single ID and password to gain access to multiple connected systems.
- Improves user experience and productivity.
- Reduces password fatigue.
- Centralizes identity management.
Memory trick: SSO: one key opens all doors.
Microsoft Entra Domain Services (Managed Domain)
Flip cardA fully managed service in Azure that provides Active Directory domain services like domain join, Group Policy, LDAP, and Kerberos/NTLM authentication, enabling legacy applications and VMs to run in Azure without deploying and managing domain controllers.
- Managed domain for Azure VMs and applications.
- Supports domain join and Group Policy Objects (GPOs).
- Compatible with traditional AD authentication protocols (LDAP, Kerberos, NTLM).
Memory trick: Domain Services is your AD in the cloud, no hard hats required.
Confidentiality
Flip cardThe security principle that ensures sensitive information is protected from unauthorized access, disclosure, or theft.
- Often achieved through encryption, access controls, and data masking.
- A cornerstone of the CIA triad.
- Crucial for protecting privacy and proprietary information.
Memory trick: Confidential means Covered and Coded
Non-repudiation
Flip cardThe assurance that someone cannot deny the validity of something. In security, it means a sender cannot deny sending a message, nor can a recipient deny receiving a message.
- Provides undeniable proof of action or origin.
- Often achieved using digital signatures and secure logging.
- Crucial for legal and compliance requirements.
Memory trick: No Denying with Non-repudiation
Accountability (Security)
Flip cardThe security principle that ensures that all actions performed on a system or with data can be uniquely traced back to the individual or entity responsible for those actions, often through logging and auditing mechanisms.
- Answers 'who did what, when, and where'.
- Crucial for compliance, forensics, and incident response.
- Relies on strong authentication and audit trails.
Memory trick: Accountability: Think of it like a security camera always recording 'who did what'.
FIDO2 Security Keys
Flip cardA passwordless authentication method that uses hardware security keys and public-key cryptography for strong, phishing-resistant authentication.
- Phishing resistant, as authentication is tied to a specific origin
- Offers a true passwordless experience
- Supported by major web browsers and operating systems
Memory trick: Keys are better than remembering words.
Managed Identities
Flip cardAn Azure Active Directory feature that provides an automatically managed identity for Azure resources to authenticate to cloud services that support Azure AD authentication, without storing credentials in application code.
- Eliminates credential management for applications.
- Automatically managed by Azure.
- Enhances security by removing secrets from code.
Memory trick: Managed Identities: The application manages its OWN ID with Azure, no code secrets needed.
Microsoft Entra Password Protection
Flip cardA Microsoft Entra ID capability that helps protect your organization by detecting and blocking known weak passwords and custom banned passwords.
- Prevents users from creating commonly used or easily guessed passwords.
- Allows creation of custom banned password lists.
- Supports both cloud-only and hybrid environments.
Memory trick: Password Protection is the stern librarian, making sure no 'password123' books are on the shelf.
Microsoft Entra Identity Protection
Flip cardA feature of Microsoft Entra ID that detects potential identity-based risks, such as compromised credentials or suspicious sign-ins, and can automatically respond to these risks.
- Detects risk events like anomalous sign-ins, leaked credentials, and malware.
- Enforces policies like multi-factor authentication or password resets based on risk level.
- Provides reports on risky users and sign-ins.
Memory trick: Entra's got your back, protecting identities from every crack.
Confidentiality and RBAC
Flip cardConfidentiality ensures data privacy by restricting access to authorized individuals, often implemented using mechanisms like Role-Based Access Control (RBAC) to define what specific roles can access.
- Confidentiality prevents unauthorized data disclosure.
- RBAC assigns permissions based on user roles, enforcing 'need-to-know'.
- Crucial for sensitive data environments like healthcare.
Memory trick: Confidentiality keeps patient data private, RBAC ensures only the right roles see it.
Microsoft Entra Application Provisioning
Flip cardA Microsoft Entra ID capability that automates the creation, maintenance, and removal of user identities in target applications based on changes in Microsoft Entra ID.
- Automates 'create, read, update, delete' (CRUD) operations for user accounts
- Reduces manual administrative overhead and errors
- Improves security by ensuring timely deprovisioning
Memory trick: Provisioning is the automatic employee handler for apps.
Auditability (Compliance)
Flip cardThe capability to record, store, and retrieve records of events and actions to verify compliance with policies, regulations, and security controls.
- Essential for demonstrating compliance to regulators.
- Requires robust logging and monitoring systems.
- Supports forensic analysis in case of a security incident.
Memory trick: Audits verify the A-ctions
Zero Trust Principle: Verify Explicitly
Flip cardThe Zero Trust principle that requires all access requests to be explicitly authenticated and authorized based on all available data points.
- No implicit trust is granted to any user, device, or service.
- Access decisions are made in real-time based on context.
- Verifies identity, device health, location, data classification, and more.
Memory trick: Zero Trust means 'Never Trust, Always Verify' – it's like a strict bouncer at every door.
Microsoft Authenticator app passwordless sign-in
Flip cardA passwordless authentication method where users approve a notification on their Microsoft Authenticator app, often using a PIN or biometric gesture (fingerprint, facial recognition) on their mobile device.
- Eliminates the need for a password.
- Leverages biometrics or PIN on the mobile device.
- Provides a seamless and secure sign-in experience.
Memory trick: The Authenticator app is your phone's biometric bouncer.
Code Compliance
Flip cardThe practice of ensuring that software code adheres to predefined organizational standards, security policies, and regulatory requirements throughout its development lifecycle.
- Encompasses secure coding practices and architectural patterns.
- Includes managing dependencies and approved component usage.
- Aims to reduce vulnerabilities and ensure maintainability.
Memory trick: Code Compliance: The rules for writing good, safe code.
Authentication
Flip cardThe process of verifying the identity of a user, system, or entity trying to access a resource.
- Answers the question 'Are you who you say you are?'.
- Typically involves credentials like passwords, biometrics, or tokens.
- Precedes authorization.
Memory trick: Authentication Asks, 'Are You Really You?'
Regulatory Adherence
Flip cardThe practice of ensuring that an organization's operations, policies, and practices comply with all relevant laws, regulations, and industry standards.
- Involves understanding and implementing legal requirements.
- Often includes reporting and demonstrating compliance.
- Can result in fines or legal action if not met.
Memory trick: Regulatory Adherence means playing by the rules, just like following a recipe perfectly.
Integrity
Flip cardThe security principle that ensures information is accurate, complete, and protected from unauthorized modification or destruction.
- Maintains data trustworthiness.
- Prevents unauthorized alteration.
- Crucial for regulatory compliance (e.g., HIPAA).
Memory trick: Integrity: 'Is this data the real deal, or has someone messed with it?'
Role-Based Access Control (RBAC)
Flip cardAn access control mechanism where permissions are associated with roles, and users are assigned to roles.
- Simplifies access management.
- Ensures consistent permissions across users in the same role.
- Commonly used in enterprise environments.
Memory trick: Roles make access simple and organized.
Data Retention and Deletion
Flip cardPolicies and practices governing how long data is stored and the secure methods used for its disposal when no longer needed or legally required.
- Essential for compliance with privacy regulations (GDPR, CCPA).
- Minimizes risk by not retaining data longer than necessary.
- Involves secure deletion methods to prevent recovery.
Memory trick: Retention: Remember to Release and Remove.
Data Encryption at Rest
Flip cardData encryption at rest is the practice of encrypting data when it is stored on persistent storage media, such as hard drives, databases, or cloud storage, to protect it from unauthorized access.
- Protects data when it's not actively being used or transmitted.
- Makes data unreadable without the associated decryption key.
- Crucial for compliance and data breach mitigation.
Memory trick: Data is encrypted while resting, moving, or processing.
Managed Identity
Flip cardAn Azure Active Directory feature that provides Azure services with an automatically managed identity to authenticate to other Azure services without managing credentials.
- Eliminates the need to store credentials in code.
- Supports system-assigned and user-assigned identities.
- Used by Azure services (VMs, App Services, Functions) to access other Azure services (Key Vault, Storage, SQL Database).
Memory trick: Managed Identity: Machines Authenticate Smoothly.
Microsoft Entra Provisioning
Flip cardAutomates the creation, maintenance, and removal of user identities and roles across various cloud and on-premises applications.
- Automates identity lifecycle management
- Connects Microsoft Entra ID to HR systems and other applications
- Supports both cloud and on-premises applications
Memory trick: Provisioning is like a smooth conveyor belt for user accounts.
Azure Key Vault
Flip cardA cloud service for securely storing and accessing secrets, cryptographic keys, and SSL/TLS certificates.
- Centralizes secret management.
- Reduces risk of accidental secret exposure.
- Integrates with Azure services and applications.
Memory trick: Key Vault: 'The safe for all your digital secrets in Azure.'
Availability
Flip cardThe security principle that ensures authorized users can reliably access information and systems when needed, without interruption.
- Achieved through redundancy, backups, and disaster recovery.
- Protects against denial-of-service attacks and system failures.
- One of the core pillars of information security (CIA triad).
Memory trick: Availability: Always open for business.
Microsoft Entra PIM for OT Access
Flip cardLeveraging Microsoft Entra PIM to provide just-in-time, time-bound access to jump servers or secure workstations, which then connect to sensitive Operational Technology (OT) systems, ensuring strict control and auditing.
- Enforces temporary, just-in-time access for OT system users.
- Requires activation of a privileged role before accessing a jump server.
- Provides granular auditing of privileged access attempts and durations.
Memory trick: PIM is the time-locked vault key for your factory floor.