Book Image

Microsoft Security, Compliance, and Identity Fundamentals Exam Ref SC-900

By : Dwayne Natwick
Book Image

Microsoft Security, Compliance, and Identity Fundamentals Exam Ref SC-900

By: Dwayne Natwick

Overview of this book

Cloud technologies have made building a defense-in-depth security strategy of paramount importance. Without proper planning and discipline in deploying the security posture across Microsoft 365 and Azure, you are compromising your infrastructure and data. Microsoft Security, Compliance, and Identity Fundamentals is a comprehensive guide that covers all of the exam objectives for the SC-900 exam while walking you through the core security services available for Microsoft 365 and Azure. This book starts by simplifying the concepts of security, compliance, and identity before helping you get to grips with Azure Active Directory, covering the capabilities of Microsoft’s identity and access management (IAM) solutions. You'll then advance to compliance center, information protection, and governance in Microsoft 365. You'll find out all you need to know about the services available within Azure and Microsoft 365 for building a defense-in-depth security posture, and finally become familiar with Microsoft's compliance monitoring capabilities. By the end of the book, you'll have gained the knowledge you need to take the SC-900 certification exam and implement solutions in real-life scenarios.
Table of Contents (24 chapters)
1
Section 1: Exam Overview
3
Section 2: The Key Concepts of Security, Compliance, and Identity
7
Section 3: The Microsoft Identity Management Solutions
11
Section 4: The Microsoft Security Solutions for Microsoft 365 and Azure
17
Section 5: The Microsoft Compliance Monitoring Capabilities within Microsoft 365 and Azure

Describe Azure Network Security Groups

Now that you understand the network segmentation and the components that make up your network, we can discuss the security features to protect the network. The first of these is the NSG. An NSG is a security solution within Azure that is associated with a subnet or network interface within the VNet to enforce a list of inbound and outbound rules. The NSG provides protection at the network security layer.

Figure 8.1 shows the architecture for an NSG when used to enforce rules across the entire subnet. The NSG is associated with the subnet and therefore has allow or deny rules that can protect resources within that subnet. In Figure 8.1, this is illustrated with a Linux and a Windows virtual machine to protect management ports 22 and 3389 respectively on the left side of the diagram. On the right, these ports are open to the internet and are exposed to potential attacks:

Figure 8.1 – NSG architecture

There are...