← Microsoft Certified: Security, Compliance, and Identity Fundamentals
AZURE · objective · 37% of the exam
Describe the capabilities of Microsoft security solutions — Microsoft Certified: Security, Compliance, and Identity Fundamentals
The official AZURE documentation our Describe the capabilities of Microsoft security solutions practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Microsoft — Microsoft security baseline for Microsoft Sentinel | Microsoft Learn
PA-7: Follow just enough administration (least privilege) principle Features Azure RBAC for Data Plane
-
Microsoft — Azure security baseline for Azure DDoS Protection | Microsoft Learn
Service can be deployed into customer's virtual network False Stores customer content at rest False
-
Microsoft — Azure security baseline for Azure Firewall Manager | Microsoft Learn
Select a Certificate Authority (CA) certificate stored in Azure Key Vault in your Firewall Premium policy so you can enable Azure Firewall for TLS inspection.
-
Microsoft — Conditional Access - Require approved app or app protection policy - Microsoft Entra ID | Microsoft Learn
Require one of the selected controls under grant controls is like an OR clause.
-
Microsoft — Azure Security Benchmark v3 - Data protection | Microsoft Learn
HSM-protected keys in Managed HSM: FIPS 140-2 Level 3
-
Microsoft — Role of Azure Information Protection in securing data | Microsoft Learn
Azure Information Protection (AIP) provides customers with the ability to classify, label their data, and protect it using encryption.
-
Microsoft — Set up information protection capabilities - Microsoft 365 admin | Microsoft Learn
Use Microsoft Purview Message Encryption to protect the information in email messages.
-
Microsoft — Token Protection Deployment Guide - Windows - Microsoft Entra ID | Microsoft Learn
Warning Not configuring the Client Apps condition, or leaving Browser selected might cause applications that use MSAL.js, such as Teams Web to be blocked.
-
Conditional Access filters for applications only work with custom security attributes of type "string".