โ† All AZ-700 Flashcard Decks

Network Security and Compliance Flashcards

5 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 5 Network Security and Compliance flashcards as text
  1. Which Azure service is used to protect applications from Distributed Denial of Service (DDoS) attacks?

    Answer: Azure DDoS Protection

    Azure DDoS Protection is a service specifically designed to safeguard Azure applications and resources from Distributed Denial of Service (DDoS) attacks. It provides always-on traffic monitoring and automatic mitigation capabilities to detect and block malicious traffic before it can impact the availability of your services. This ensures business continuity even under attack.

  2. What principle is implemented when only the minimum permissions needed to perform a task are granted?

    Answer: Least Privilege

    The principle of Least Privilege dictates that users, processes, or systems should only be granted the minimum necessary permissions to perform their required tasks. This security best practice reduces the potential impact of a compromise, as an attacker gaining access to a low-privilege account would have limited ability to cause damage. It minimizes the attack surface and improves overall security posture.

  3. Which Azure security service allows administrators to set policies for access to Azure resources based on conditions such as user location or device state?

    Answer: Conditional Access in Azure Active Directory

    Conditional Access in Azure Active Directory allows administrators to implement policies that control access to Azure resources based on specific conditions. These conditions can include user location, device compliance, application sensitivity, and sign-in risk. This enables organizations to enforce stronger security requirements, such as multi-factor authentication, only when necessary, enhancing security without hindering productivity.

  4. Which Azure tool allows you to visualize network security group (NSG) rules to understand their effects on network traffic?

    Answer: Network Watcher

    Azure Network Watcher is a suite of tools designed to monitor, diagnose, and visualize network performance and security in Azure. Specifically, its 'NSG flow logs' and 'IP flow verify' features allow you to visualize and understand how Network Security Group (NSG) rules are affecting network traffic. This helps in troubleshooting connectivity issues and ensuring security policies are correctly applied.

  5. In the Zero Trust security model, which of the following is a core concept?

    Answer: Verifying each access request as though it originates from an open network

    A core concept of the Zero Trust security model is 'never trust, always verify.' This means that every access request, whether from inside or outside the network, is treated as if it originates from an untrusted environment. It requires strict identity verification, device validation, and least privilege access for every connection, rather than assuming trust based on network location.