Book Image

Microsoft Azure Security Technologies Certification and Beyond

By : David Okeyode
Book Image

Microsoft Azure Security Technologies Certification and Beyond

By: David Okeyode

Overview of this book

Exam preparation for the AZ-500 means you’ll need to master all aspects of the Azure cloud platform and know how to implement them. With the help of this book, you'll gain both the knowledge and the practical skills to significantly reduce the attack surface of your Azure workloads and protect your organization from constantly evolving threats to public cloud environments like Azure. While exam preparation is one of its focuses, this book isn't just a comprehensive security guide for those looking to take the Azure Security Engineer certification exam, but also a valuable resource for those interested in securing their Azure infrastructure and keeping up with the latest updates. Complete with hands-on tutorials, projects, and self-assessment questions, this easy-to-follow guide builds a solid foundation of Azure security. You’ll not only learn about security technologies in Azure but also be able to configure and manage them. Moreover, you’ll develop a clear understanding of how to identify different attack vectors and mitigate risks. By the end of this book, you'll be well-versed with implementing multi-layered security to protect identities, networks, hosts, containers, databases, and storage in Azure – and more than ready to tackle the AZ-500.
Table of Contents (19 chapters)
1
Section 1: Implement Identity and Access Security for Azure
7
Section 2: Implement Azure Platform Protection
12
Section 3: Secure Storage, Applications, and Data

Questions

As we conclude, here is a list of questions for you to test your knowledge regarding this chapter's material. You will find the answers in the Assessments section of the Appendix:

  1. You need to deploy the Azure Firewall service in a virtual network in Azure. What should you do first?

    a. Create a new subnet in the virtual network.

    b. Create an NSG and associate it with the virtual network.

    c. Delete and recreate the virtual network.

    d. Configure DDoS protection for the virtual network.

  2. You have a web app named customapp. You need to protect customapp using a WAF. What should you do?

    a. Deploy Azure Front Door.

    b. Add an extension to customapp.

    c. Deploy Azure Firewall.

    d. Deploy DDoS Protection.

  3. You deployed an Azure VM named web-vm1 in an Azure virtual network subnet. You need to ensure that all outbound traffic from the VM is routed through a network virtual appliance. What should you configure?

    a. A user-defined route

    b. A network security group

    c. An application...