Infrastructure Security Flashcards
7 cards from real SC-100 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Infrastructure Security flashcards as text
A company needs to secure administrative access to Azure VMs without exposing RDP or SSH ports to the internet. Which service provides browser-based secure access?
Answer: Azure Bastion
Azure Bastion provides secure RDP and SSH connectivity to VMs directly through the Azure portal without exposing management ports to the internet.
An architect needs to enforce that Azure resources in a subscription can only be deployed to approved geographic regions. Which Azure construct achieves this?
Answer: Azure Policy with allowed locations definition
Azure Policy's built-in 'Allowed locations' definition denies deployment of resources to any region not explicitly listed in the policy parameters.
When designing security for Azure Virtual Desktop, which control ensures that session host VMs are not directly accessible from the internet?
Answer: NSG with no inbound internet rules and RDP Shortpath over private network
AVD session hosts should have NSGs blocking direct internet inbound access, with connections routed through AVD's reverse connect transport or RDP Shortpath over managed networks.
A security architect needs to detect unauthorized changes to critical Azure resource configurations in real time. Which service provides this capability?
Answer: Azure Activity Log alerts via Azure Monitor
Azure Activity Log captures all control-plane operations, and Azure Monitor alert rules can trigger notifications when critical resource configurations are modified.
Which Microsoft Defender for Cloud feature continuously assesses Azure resources against CIS, NIST, and PCI DSS benchmarks and reports compliance status?
Answer: Regulatory Compliance dashboard
The Regulatory Compliance dashboard in Defender for Cloud maps resource configurations to industry standards and shows pass/fail status per control.
An organization needs to ensure that secrets used by Azure functions are never stored in application code or configuration files. What is the recommended approach?
Answer: Use Azure Key Vault references with managed identity
Azure Key Vault references combined with managed identity allow Azure Functions to retrieve secrets at runtime without storing them in code or configuration.
A cybersecurity architect is reviewing the shared responsibility model for Azure IaaS. Which security responsibility remains solely with the customer?
Answer: Guest OS patching and configuration
In the IaaS model, Microsoft manages physical infrastructure and hypervisor, but guest OS patching, configuration, and application security are the customer's responsibility.