~/azure-az-204 · Implement Azure security ▊
← Microsoft Certified: Azure Developer Associate
AZURE · objective · 20% of the exam
Implement Azure security — Microsoft Certified: Azure Developer Associate
The official AZURE documentation our Implement Azure security practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
The Key Vault Crypto Service Encryption User role is needed by the server identity to be able to use the key for encryption and decryption
-
Temporary disks and ephemeral OS disks are encrypted at rest with platform-managed keys when you enable end-to-end encryption.
-
Microsoft — Azure Key Vault VM extension for Windows - Azure Virtual Machines | Microsoft Learn
A VM with an assigned managed identity .
-
Azure Disk Encryption will continue to use the original encryption key, even after it has been auto-rotated. Rotating an encryption key won't break Azure Disk
-
Microsoft — Network Security Perimeter - Azure SQL Database | Microsoft Learn
Any attempts made to communicate with Azure resources that aren't inside the perimeter is blocked.
-
Microsoft — Secure with Microsoft Entra Logins - Azure SQL Managed Instance | Microsoft Learn
Grant the Microsoft Entra user the db_datareader database role by using the following T-SQL syntax