Security, Compliance & Identity Concepts Flashcards
9 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 9 Security, Compliance & Identity Concepts flashcards as text
What is the main purpose of Microsoft Security, Compliance, and Identity solutions?
Answer: To protect and secure data, identities, and systems
Microsoft's security, compliance, and identity solutions are fundamentally designed to create a robust protective framework. Their main purpose is to safeguard an organization's critical data, ensure the integrity of user identities, and secure the underlying systems and infrastructure against various cyber threats.
What is the role of identity management in cloud security?
Answer: To ensure only authorized individuals access resources and data
In cloud security, identity management is paramount for controlling who can access what resources. Its role is to verify user identities and enforce access policies, ensuring that only authorized individuals and services can interact with sensitive data and applications within the cloud environment.
Why is compliance important in security?
Answer: It helps avoid penalties and fosters trust with customers
Compliance is crucial in security because it ensures an organization adheres to relevant laws, regulations, and industry standards. Meeting compliance requirements helps avoid significant legal penalties and fines, while also building trust and credibility with customers and stakeholders by demonstrating a commitment to data protection.
What is the purpose of encryption in security?
Answer: To ensure only authorized parties can access and read data
The primary purpose of encryption in security is to protect data confidentiality. By transforming data into an unreadable format, encryption ensures that even if unauthorized parties gain access, they cannot understand or use the information, making it accessible only to those with the correct decryption key.
What does Microsoft Defender for Identity do?
Answer: It secures and monitors user identities and activities
Microsoft Defender for Identity is a cloud-based security solution specifically designed to protect user identities and detect advanced threats. It monitors user activities and behaviors across an organization's network, identifying suspicious actions and potential attacks like credential theft or lateral movement.
Why is Multi-Factor Authentication (MFA) critical in securing user identities?
Answer: It enhances security by requiring multiple verification methods
Multi-Factor Authentication (MFA) is critical for securing user identities because it adds multiple layers of verification beyond just a password. By requiring users to provide two or more distinct proofs of identity, such as a password and a code from a phone, MFA significantly reduces the risk of unauthorized access even if a password is compromised.
What is the significance of data loss prevention (DLP) in security?
Answer: It helps prevent unauthorized sharing of sensitive data
Data Loss Prevention (DLP) is significant in security as it actively prevents sensitive information from leaving the organization's control. DLP solutions identify, monitor, and protect confidential data, ensuring it is not accidentally or maliciously shared, transferred, or accessed by unauthorized individuals, thus safeguarding critical assets.
How does Azure Security Center help with security management?
Answer: It helps detect and manage security threats across resources
Azure Security Center (now part of Microsoft Defender for Cloud) helps with security management by providing unified security management and advanced threat protection across hybrid cloud workloads. It continuously assesses the security posture of resources, detects threats, and offers recommendations to strengthen defenses and respond to incidents.
What role does risk management play in Microsoft’s security framework?
Answer: It helps identify and mitigate potential security risks
In Microsoft's security framework, risk management plays a vital role by systematically identifying, assessing, and mitigating potential security risks. This proactive approach helps organizations understand their vulnerabilities and implement appropriate controls to reduce the likelihood and impact of security incidents, ensuring a more resilient security posture.