Microsoft Security, Compliance, and Identity Fundamentals (SC-900) flashcards
111 free flashcards. Tap a card to flip it.
Microsoft Entra B2C
Flip cardA customer identity and access management (CIAM) solution that handles customer sign-up, sign-in, and profile management for web and mobile applications.
- Designed for millions of customer identities.
- Supports social identity providers (Google, Facebook, etc.).
- Customizable user experiences and self-service features.
Memory trick: B2C is the customer's welcome mat and identity vault.
Auditability
Flip cardAuditability refers to the ability to track, record, and review all actions and events within a system, ensuring that an accurate and complete historical record exists for accountability, compliance, and forensic analysis.
- Creates a verifiable trail of activities.
- Essential for compliance and incident response.
- Records who, what, when, and where.
Memory trick: Audits ensure a clear paper trail.
Threat Protection
Flip cardA comprehensive security approach that involves identifying, preventing, detecting, and responding to cyber threats and malicious activities.
- Includes antivirus, anti-malware, firewall, intrusion detection.
- Aims to safeguard systems and data from various cyberattacks.
- Often involves continuous monitoring and analysis of security data.
Memory trick: Threat Protection: The watchful guard against bad guys.
Cybersecurity Resilience
Flip cardThe ability of an organization to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources.
- Focuses on maintaining critical functions during an attack.
- Includes prevention, detection, response, and recovery.
- Aims for continued operation, possibly in a degraded state.
Memory trick: Resilience is like a flexible tree, bending in the storm but not breaking.
Multifactor Authentication (MFA)
Flip cardAn authentication method that requires the user to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN.
- Adds an extra layer of security beyond just a password
- Common factors include something you know (password), something you have (phone), something you are (fingerprint)
- Significantly reduces the risk of credential compromise
Memory trick: More factors mean more fortress.
Compliance Manager
Flip cardA Microsoft Purview solution that helps organizations manage their compliance posture, providing a dashboard for assessments, improvement actions, and risk scoring.
- Centralized dashboard for compliance
- Maps to various regulations and standards
- Provides improvement actions and risk scoring
Memory trick: Manage your compliance, score your progress.
Auto-labeling Policies
Flip cardA Microsoft Purview Information Protection feature that automatically applies sensitivity labels to content based on content inspection, predefined conditions, or machine learning, without user intervention.
- Automates content classification
- Applies sensitivity labels based on conditions
- Enforces protection policies (encryption, access control)
Memory trick: The robot labels, the data is safe.
Microsoft Purview Information Protection (MPIP)
Flip cardA solution that helps organizations discover, classify, label, and protect sensitive information wherever it lives or travels.
- Enables automatic and manual labeling
- Applies protection like encryption and access restrictions
- Works across Microsoft 365 services and beyond
Memory trick: Information protection secures all your secrets.
eDiscovery (Premium)
Flip cardA Microsoft Purview solution that provides end-to-end workflow to identify, preserve, collect, process, review, and export content in response to internal and external investigations.
- Manages legal holds
- Collects data from various sources (email, chat)
- Provides advanced review and analytics for legal cases
Memory trick: Find the evidence, build the case.
Service Trust Portal
Flip cardA public portal that provides access to Microsoft's compliance, trust, and security information, including audit reports, compliance guides, and certifications.
- Primary source for Microsoft's compliance documentation.
- Includes audit reports (e.g., SOC, ISO).
- Helps customers understand Microsoft's security and privacy practices.
Memory trick: Trust the Service for official papers.
Insider Risk Management
Flip cardA Microsoft Purview solution that helps organizations detect, investigate, and act on malicious and inadvertent insider activities to minimize internal risks.
- Detects risky user behaviors
- Correlates various signals (e.g., downloads, emails)
- Helps investigate and remediate insider threats
Memory trick: Watch for the patterns, catch the insiders.
Microsoft Purview Data Loss Prevention (DLP)
Flip cardA solution that identifies, monitors, and automatically protects sensitive information across Microsoft 365 services and beyond.
- Prevents accidental or malicious sharing of sensitive data
- Uses sensitive information types to detect data
- Applies policies to block, notify, or audit sharing attempts
Memory trick: Don't Let Personal data out!
Microsoft Purview Information Barriers (IB)
Flip cardA compliance solution that prevents individuals or groups from communicating with each other in Microsoft Teams, SharePoint, and Exchange Online.
- Segments users into groups
- Enforces communication restrictions between segments
- Used for ethical walls and conflict-of-interest scenarios
Memory trick: Information Barriers build walls between conversations.
Information Barriers
Flip cardA Microsoft Purview capability that allows organizations to restrict communication and collaboration between specific groups of users to avoid conflicts of interest or maintain confidentiality.
- Prevents unauthorized communication between user segments
- Enforces regulatory compliance (e.g., finance, legal)
- Applies to Microsoft Teams, Exchange Online, SharePoint Online
Memory trick: Build walls between teams to keep secrets safe.
Microsoft Purview Insider Risk Management (IRM)
Flip cardA solution that helps organizations detect, investigate, and act on malicious and inadvertent activities by users that could pose a risk to data or compliance.
- Uses machine learning to identify risky user behaviors
- Integrates with various Microsoft 365 services
- Helps mitigate data leakage, intellectual property theft, and fraud
Memory trick: Insider Risks are Managed, not ignored.
Microsoft Purview Data Lifecycle Management (DLM)
Flip cardA set of capabilities that help organizations manage data throughout its lifecycle, from creation to disposition, ensuring compliance and minimizing risk.
- Includes retention policies and labels
- Manages data for compliance and operational needs
- Ensures data is kept for required periods and then deleted
Memory trick: Data Lives, then it's Managed.
eDiscovery Premium
Flip cardAn advanced Microsoft Purview solution that provides an end-to-end workflow for managing legal and investigative matters, including identifying, preserving, collecting, processing, reviewing, and analyzing electronically stored information (ESI).
- Manages custodians and legal holds.
- Processes data for review (deduplication, near-duplicates).
- Provides advanced review and analytics tools.
Memory trick: eDiscovery is for complex legal cases.
Communication Compliance
Flip cardA Microsoft Purview solution that helps organizations detect, capture, and review inappropriate messages across communication channels to address regulatory compliance and internal policy violations.
- Monitors various communication channels (email, Teams)
- Detects policy violations (harassment, sensitive content)
- Provides a workflow for review and remediation
Memory trick: Listen to the chatter, catch the bad words.
Microsoft Purview Data Map
Flip cardA foundational capability of Microsoft Purview that provides a unified map of an organization's data assets across hybrid and multi-cloud environments, enabling data discovery, classification, and governance.
- Automatically scans and catalogs data assets.
- Provides a metadata-rich inventory of data.
- Powers other Purview solutions like Data Loss Prevention and Information Protection.
Memory trick: Map your data for total control.
Data Lifecycle Management (DLM)
Flip cardA Microsoft Purview capability that helps organizations manage their data throughout its lifecycle, from creation to disposition, by defining and enforcing retention and deletion policies.
- Manages data from creation to deletion
- Applies granular retention/deletion policies
- Works across various Microsoft 365 services
Memory trick: Lifecycle rules for every data type, automatically.
Records Management
Flip cardA Microsoft Purview solution that helps organizations meet legal, regulatory, and business obligations for retaining and disposing of information.
- Manages retention labels and policies.
- Supports immutable retention (records cannot be deleted).
- Enables automated disposal after a set period or event.
Memory trick: Manage Records for their entire life.
Microsoft Purview Communication Compliance
Flip cardA solution that helps organizations detect, investigate, and act on inappropriate messages in Microsoft 365 communications.
- Uses machine learning to identify policy violations
- Monitors various communication channels (Teams, Exchange)
- Helps address regulatory compliance and ethical conduct
Memory trick: Communicate Compliantly, or face the consequences.
Data Loss Prevention (DLP)
Flip cardA Microsoft Purview capability that helps prevent sensitive information from being accidentally or maliciously shared outside the organization or with unauthorized internal users.
- Detects sensitive information (e.g., PII, credit cards)
- Monitors data across various locations (email, documents)
- Enforces policies to block or warn against sharing
Memory trick: Don't let the sensitive data escape!
Azure Sentinel
Flip cardMicrosoft's cloud-native SIEM solution that provides intelligent security analytics and threat intelligence across the enterprise. It collects data, detects threats, investigates alerts, and responds to incidents.
- Cloud-native SIEM and SOAR.
- Uses AI and machine learning for threat detection.
- Centralized security monitoring for Azure and beyond.
Memory trick: Sentinel watches Azure with intelligence.
Azure Active Directory Identity Protection
Flip cardA feature of Azure AD that detects identity-based risks, such as compromised accounts and suspicious sign-ins.
- Detects real-time and offline identity risks.
- Integrates with Conditional Access policies.
- Provides risk-based remediation actions (MFA, password reset, block).
Memory trick: Azure AD IP is the 'bouncer' for your cloud identities, stopping suspicious sign-ins.
Microsoft 365 Defender for Office 365
Flip cardA component of Microsoft 365 Defender that protects Microsoft 365 services and collaboration tools from advanced threats like phishing, malware, and zero-day exploits.
- Protects email (Exchange Online).
- Scans links (Safe Links) and attachments (Safe Attachments).
- Extends protection to SharePoint, OneDrive, and Teams.
Memory trick: Defender for O365: Office Online Overcomes Obstacles.
Microsoft Defender for Cloud Apps (CASB)
Flip cardA Cloud Access Security Broker (CASB) that extends visibility and control over cloud applications, discovers shadow IT, and enforces data protection policies.
- Discovers and identifies all cloud apps (sanctioned/unsanctioned).
- Enforces DLP and compliance policies in cloud apps.
- Provides granular control over user activities in cloud apps.
Memory trick: Cloud Apps Defender: Catch All, Control All, Comply All.
Azure Web Application Firewall (WAF)
Flip cardA cloud-native service that protects web applications from common web-based exploits and vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 risks.
- Protects web applications
- Defends against OWASP Top 10 attacks
- Integrates with Application Gateway or Front Door
Memory trick: WAF is your web app's bouncer for bad traffic.
Microsoft 365 Defender for Cloud Apps
Flip cardA Cloud Access Security Broker (CASB) that provides deep visibility, strong data controls, and enhanced threat protection for cloud apps.
- Monitors user activities in cloud apps.
- Detects shadow IT.
- Enforces data loss prevention policies.
Memory trick: Cloud Apps: See All, Control All, Protect All.
Azure AD Identity Protection
Flip cardA feature of Azure Active Directory that detects identity-based risks, including compromised credentials, suspicious sign-ins, and risky users. It provides risk reports and automated responses like blocking access or enforcing multi-factor authentication.
- Detects identity-based risks (e.g., impossible travel).
- Provides risk scores for users and sign-ins.
- Offers automated remediation actions.
Memory trick: Identity Protection guards users from risky behavior.
Microsoft Sentinel
Flip cardA scalable, cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.
- Collects security data from diverse sources.
- Uses AI for threat detection.
- Automates incident response with playbooks.
Memory trick: Sentinel: See Everything, Investigate, Execute, Learn.
Microsoft Purview Information Protection
Flip cardA solution that helps discover, classify, label, and protect sensitive information across its lifecycle.
- Integrates with Microsoft 365 apps and services.
- Enables manual, recommended, or automatic labeling.
- Applies encryption, visual markings, and access restrictions.
Memory trick: Purview IP is the 'librarian' for your sensitive M365 documents, classifying and locking them up.
Microsoft Intune
Flip cardA cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM) to protect organizational data.
- Manages corporate-owned and personal devices (BYOD).
- Applies configuration policies and deploys applications.
- Protects organizational data across devices.
Memory trick: Intune's all in for securing your devices, from phones to PCs.
Microsoft Sentinel (SIEM/SOAR)
Flip cardA cloud-native SIEM and SOAR solution for intelligent security analytics and threat intelligence.
- Collects data from all enterprise sources.
- Uses AI and machine learning for threat detection.
- Automates incident response with playbooks.
Memory trick: Sentinel is the 'brain' of your security, watching everything and reacting smartly.
Azure SQL Database Advanced Threat Protection
Flip cardA security feature for Azure SQL Database that detects anomalous database activities indicating unusual and potentially harmful attempts to access or exploit databases.
- Detects SQL injection
- Identifies unusual access patterns
- Part of Microsoft Defender for SQL
Memory trick: SQL ATP protects your database with advanced threat detection.
Azure Front Door WAF
Flip cardA cloud-native web application firewall that protects web applications from common web-based attacks.
- Integrated with Azure Front Door for global traffic routing.
- Protects against OWASP Top 10 vulnerabilities.
- Offers managed rulesets and custom rules.
Memory trick: Front Door WAF guards web apps from common web attacks.
Microsoft Defender for Containers
Flip cardA cloud-native solution that provides security for containerized environments, including vulnerability assessment for images, runtime threat protection for Kubernetes, and hardening recommendations.
- Scans container images for vulnerabilities
- Runtime threat protection for AKS/Kubernetes
- Security recommendations for container hosts
Memory trick: Defender for Containers secures your whole container pipeline.
Microsoft Defender for Cloud (CWP)
Flip cardThe Cloud Workload Protection (CWP) part of Microsoft Defender for Cloud provides advanced threat protection for various workloads, including virtual machines, databases, storage, containers, Kubernetes, and serverless functions.
- Protects a broad range of cloud workloads.
- Integrates into CI/CD for DevSecOps.
- Offers vulnerability scanning and runtime protection.
Memory trick: Defender for Cloud protects apps from code to cloud.
Microsoft Defender for IoT
Flip cardA unified security solution for discovering, monitoring, and protecting Internet of Things (IoT) and Operational Technology (OT) devices.
- Provides agentless monitoring for OT/ICS networks
- Detects vulnerabilities and threats specific to industrial environments
- Integrates with Microsoft Sentinel for centralized security operations
Memory trick: IoT's Defender secures the factory floor.
Microsoft Defender for Servers
Flip cardA plan within Microsoft Defender for Cloud that provides advanced threat protection for Windows and Linux virtual machines and physical servers, including features like just-in-time VM access, file integrity monitoring, and adaptive application controls.
- Protects Azure VMs and on-premises servers
- Includes Just-in-Time (JIT) VM access
- Provides File Integrity Monitoring (FIM)
Memory trick: Defender for Servers protects your virtual machines like a strong guard.
Azure Security Center (Free Tier)
Flip cardNow part of the foundational capabilities of Microsoft Defender for Cloud, this tier provides basic security posture management for Azure resources, including security recommendations, continuous security assessment, and some advanced protections like Just-in-Time VM access.
- Provides security recommendations.
- Includes continuous security assessment.
- Offers Just-in-Time (JIT) VM access.
- Adaptive network hardening.
Memory trick: Defender for Cloud's free tier secures the basics for VMs.
Microsoft Defender for Cloud (Free Tier)
Flip cardThe no-cost tier of Microsoft Defender for Cloud that provides continuous security assessment, security recommendations, and Secure Score for Azure resources.
- Free of charge
- Focuses on basic CSPM for Azure
- Provides Secure Score and recommendations
Memory trick: Free tier gives you the basic security overview for your cloud.
Microsoft Defender for Cloud Apps
Flip cardA Cloud Access Security Broker (CASB) that extends visibility and control over cloud applications.
- Discovers shadow IT and assesses cloud app risk.
- Protects sensitive information with data loss prevention (DLP).
- Detects anomalous behavior and mitigates cyberthreats.
Memory trick: Defender for Cloud Apps is your cloud's 'security guard' for everything in the sky.
Microsoft Defender for Cloud
Flip cardA cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that strengthens the security posture of your cloud resources.
- Provides secure score.
- Offers security recommendations.
- Detects and protects against threats across hybrid cloud workloads.
Memory trick: Defender for Cloud: Defend, Discover, Dashboard.
Microsoft Defender for Office 365
Flip cardA security solution that protects organizations from malicious threats posed by email messages, links (URLs), and collaboration tools. It includes advanced anti-phishing, anti-spam, and anti-malware capabilities, along with safe attachments and safe links.
- Protects email, links, and collaboration tools.
- Offers advanced anti-phishing, anti-spam, anti-malware.
- Includes Safe Attachments and Safe Links features.
Memory trick: Defender for Office 365 keeps mail safe and clean.
Microsoft Sentinel Playbooks
Flip cardAutomated, predefined response procedures in Microsoft Sentinel (powered by Azure Logic Apps) used to orchestrate and automate security tasks.
- Enable Security Orchestration, Automation, and Response (SOAR)
- Can be triggered by alerts or incidents
- Perform actions like blocking, isolating, enriching data, and notifying
Memory trick: Playbooks play out the security plan.
Microsoft Defender for Endpoint
Flip cardAn enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats.
- Provides Endpoint Detection and Response (EDR).
- Includes vulnerability management and attack surface reduction.
- Automates security incidents and responses.
Memory trick: Each Defender component protects its unique domain.
Microsoft 365 Defender
Flip cardA unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.
- Protects Microsoft 365 services.
- Offers Extended Detection and Response (XDR).
- Includes Defender for Endpoint, Identity, Office 365, and Cloud Apps.
Memory trick: Defender protects M365's entire digital life.
Microsoft Defender for Cloud (CSPM)
Flip cardA unified security management system that strengthens the security posture of your cloud resources and provides advanced threat protection.
- Provides a Secure Score for continuous security posture assessment
- Offers actionable recommendations to remediate vulnerabilities
- Covers Azure, hybrid, and multi-cloud environments
Memory trick: Defender for Cloud keeps your cloud fit.
Microsoft Defender for Endpoint (MDE)
Flip cardAn enterprise endpoint security platform for preventative protection, post-breach detection, automated investigation, and response.
- Supports Windows, macOS, Linux, Android, and iOS.
- Includes Endpoint Detection and Response (EDR) capabilities.
- Offers vulnerability management and attack surface reduction.
Memory trick: Defender for Endpoint is the 'global bodyguard' for all your devices, no matter the OS.
Microsoft Defender for Identity
Flip cardA cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.
- Monitors Active Directory traffic for suspicious behavior
- Detects advanced attacks like Golden Ticket, Pass-the-Hash
- Provides insights into user and entity behavior analytics (UEBA)
Memory trick: Defender for Identity watches the AD tree.