Azure Identity & Security Flashcards
6 cards from real AZ-300 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Azure Identity & Security flashcards as text
Which Azure service provides a unified view of security posture across Azure and hybrid workloads with built-in threat detection?
Answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud (formerly Azure Security Center) provides continuous security assessment, threat detection, and a Secure Score for Azure and hybrid environments.
What is the purpose of Azure AD Application Proxy?
Answer: Provide secure remote access to on-premises web applications without a VPN via Azure AD authentication
Azure AD Application Proxy allows remote users to securely access on-premises web applications through Azure AD, without requiring VPN or exposing the app to the internet.
Which feature should you enable in Azure to get a Secure Score that benchmarks your environment against security best practices?
Answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud calculates a Secure Score by assessing your resources against security controls, providing prioritized recommendations.
What does 'just-in-time (JIT) VM access' in Microsoft Defender for Cloud do?
Answer: Locks down management ports and allows access only when requested for a limited time
JIT VM access closes RDP/SSH ports by default and opens them only for approved requests with a specific time window, reducing attack surface.
Which Azure feature allows you to enforce that all subscriptions in a management group comply with organizational policies and RBAC assignments by default?
Answer: Azure Blueprints
Azure Blueprints package RBAC assignments, policies, and ARM templates into repeatable deployable packages, enforcing governance standards across subscriptions.
What is the 'defense in depth' strategy as applied to Azure workload security?
Answer: Applying security controls at multiple layers (network, host, application, data) so no single failure exposes all assets
Defense in depth applies overlapping security controls at physical, network, host, application, and data layers so an attacker must bypass multiple barriers.