
寫在前面
因為sc-900是英文考試(或是有中文版本但我不知道),我復習和刷題也是看的英文材料,因此該筆記會以英文為基礎,遇到比較少見的單詞時我會標注翻譯,
該筆記單純旨在通過考試,對實踐的幫助不大,sc-900,依我拙見,也不是一個能學到很多知識的考試,想要了解網路安全基礎概念的朋友,可以了解一下ISC^2最近發布的CC(certified in cybersecurity)考試,之后我也會發布cc的學習筆記,
SC-900
- 60分鐘
- 40-60道題
- 滿分1000分,700分以上合格
筆記
評分相關
secure score: 網路安全系數
compliance score: 員工是否遵從規定,按程式行事
功能相關
Azure Active Directory(Azure AD):
- cloud-based identity and access management service
Azure AD identity protection
- automate the detection and remediation of identity-based risk
- investigate risks using data in the portal
MS defender:
- MS Defender for Identity:
- cloud-based solution that leverage(借助) on-premises Active Directory Domain Service(AD DS) to identify, detect, ... risks
- MS Defender for Endpoint:
- 一般跟裝備(device)有關的就選這個
- secure score就存在這
- automatic investigation and regulation
- attack surface reduction
- MS Defender for Office 365:
- protect from malicious threats posted by email messages, links, ...
- real-time report
- MS Defender for Cloud:
- manage security for a multi-cloud environment(微軟,谷歌,亞馬遜結合到一起管理)
- assess security posture, identify threats, harden resource
- MS Defender for Cloud App:
- Cloud Access Security Broker(CASB) that supports various deployment modes
- CASB四大要素: visibility, compliance, data security, threat protection
- 達到GDPR和PCI的要求
- Cloud Access Security Broker(CASB) that supports various deployment modes
Azure Firewall:
- network-level and application-level
- protect machine and network
Azure Web Application Firewall(WAF):
- application-level filtering
- SSL termination
- centralized protection from common exploits&vulnerabilities
Azure Baston:
- secure RDP&SSH connectivity to the virtual machine
Network Security Group(NSG):
- filter network traffic to and from Azure Resource
Azure Sentinel(哨兵):
- security information and event management(SIEM)
- SIEM: collect info from diverse source, and analyzes it for signs of a security incident
- security orchestration automated response(SOAR)
- workbook: interactive dashboards that allow users to explore and analyze
- playbook: automated response
MS purview compliance portal:
- manage compliance requirement
- 3 controls:
- MS-managed control
- customer-managed control
- shared control
- insider risk management: sensitive data leak, confidentiality violation
- 一般沒見過的題就選它
privileged identity management(PIM):
- time-based and approval-based role activation
- e.g. just-in-time access
- premium P2 subscription
virtual network:
- network segmentation
customer lockbox:
- used by MS engineers when they need to access some user's data
eDiscovery:
- digital investigation that attempts to find evidence in email, ... for a criminal proceeding
規定相關
MS service Trust Portal:
- detail how MS complies with the regulatory standard and implements controls to protect the organization
- 一般來說,如果題目中提到document,就選trust portal
Azure Policy:
- enforce(實行) standard, and assess compliance
Zero Trust:
- assume breach
- verify explicitly
- least privilege
Privacy Principle:
- Control
- Security
- Legal
- Transparency
- No content-based targeting
- Benefit
Microsoft Cloud Adoption Framework for Azure:
- collection of documentation providing guidance
密碼學相關
Symmetric encryption
- use the same key to encrypt and decrypt files
Asymmetric encryption
- private key to sign a document(digital signature)
- public key to verify authentication
Azure MFA(multi-factor authentication)
- text message
- authentication app
- phone call
Self-service password reset(SSPR):
- 忘記密碼自己解決
- 啟動條件:
- Assign an Azure AD license
- Enable SSPR for user
- Register an authentication method
Federation:
- enable access to service across the organization
Single-Sign on:
- 登錄一次,其他相關程式免登錄
Password Hash Synchronization:
- enables password sync with active directory
有用鏈接
刷題:
https://www.examtopics.com/exams/microsoft/sc-900/view/
https://learn.microsoft.com/zh-cn/certifications/exams/sc-900/practice/assessment?assessment-type=practice&assessmentId=11
免費考試:
https://msftstudentcert.cloudreadyskills.com/course/sc900
寫在后面
以上為本人復習時整理,如有遺漏知識點(肯定有很多),歡迎大家評論補充,提前祝大家考試通過
轉載請註明出處,本文鏈接:https://www.uj5u.com/qita/549981.html
標籤:其他
上一篇:淺析DNS Rebinding
下一篇:ICA:1靶場
