AZ-500 · Domain 4
Manage Security Operations
About 25% of the exam
Defender for Cloud layers
- Foundational posture
- free recommendations and secure score
- Paid posture plan
- graph, attack paths, agentless scanning
- Workload plans
- threat detection per resource type
- Regulatory compliance
- standards mapped onto your estate
- Multicloud connectors
- other providers appear as resources
- Arc onboarding
- servers outside Azure become managed
- Alerts
- suspicious activity worth investigating
- Incidents
- related alerts grouped together
Posture management tells you what is weak while workload protection tells you what is happening right now
Posture management
- Secure score summarizes control coverage
- Recommendations backed by policy definitions
- Agentless scanning reads disk snapshots
- Exemptions waive a scope with justification
- Governance rules assign owners and deadlines
- Drift returns without preventive policy
Compliance reporting
- A default benchmark applies to every subscription
- Add the standards you actually report against
- Custom initiatives cover internal control sets
- Evidence exported for the auditor
- Score per control, not per resource
- Other providers appear in the same view
Workload protection plans
- Server plan for endpoint detection
- Storage plan detects suspicious access
- Vault plan flags unusual key access
- Resource manager plan watches control operations
- Container plan covers images and runtime
- Database plans cover injection and exfiltration
Recommendations and remediation
- Quick fix remediates many resources together
- Automation triggers a workflow on recommendation
- Suppression quiets a known benign case
- Exemption differs from suppression in intent
- Preventive policy stops the drift returning
- Owner and due date drive closure
The cloud security graph
What it is
- Relationships between resources and identities
- Queried through the security explorer
- Requires the paid posture plan
Attack paths
- Chains exposure to a sensitive target
- Breaking one link removes the path
- Prioritized by reachable impact
Uses
- Find exposed machines holding secrets
- Find identities with excessive permissions
- Answer questions before an incident
Sentinel architecture
Ingest
- Connectors bring each source in
- The workspace stores and queries data
- Normalization gives a common schema
Detect
- Scheduled analytics rules run queries
- Entity mapping enriches the incident
- Watchlists add business context
Respond
- Automation rules order the actions
- Playbooks run the external steps
- Workbooks visualize the results
Analytics and hunting
- Test a rule against historical data
- Threshold tuning prevents alert floods
- Reference a watchlist to exclude noise
- Threat intelligence indicators enrich matches
- Advanced hunting spans endpoint and identity
- Custom models can score the data
Automation in Sentinel
- Rules trigger on creation or update
- The order value decides which runs first
- Playbooks enrich, notify or contain
- Conditions keep automation narrowly scoped
- Entities let playbooks act precisely
- Log every automated decision
Log cost and retention
- Analytics tier
- full query and alerting features
- Basic tier
- cheap ingest, limited querying
- Search jobs
- retrieve from cheaper tiers later
- Archive
- long retention at low cost
- Commitment tier
- discount for predictable daily volume
- Table plan
- chosen per table, not workspace
- Cross-workspace query
- one query across several workspaces
- Retention setting
- regulatory need drives the period
Operations mistakes
- Alerts with no automation or owner
- Noisy rule disabled instead of tuned
- Connector enabled but table never queried
- Free posture assumed to include the graph
- Retention shorter than the investigation window
- Servers outside Azure never onboarded
Service names to know
- Posture and workload protection
- Defender for Cloud
- Event management and response
- Microsoft Sentinel
- Onboard servers outside Azure
- Azure Arc
- Query language for logs
- the Kusto query language
- Normalized detection schema
- the advanced security model
- Prebuilt content packages
- the content hub
- Automated response workflow
- a Sentinel playbook
- Business context list
- a watchlist
Know the order
- Connect the source
- Normalize
- Detect
- Automate
- Review and tune
Connecting a source without a detection and a runbook buys storage cost and a false sense of coverage
Reference strip: posture, protection, graph, Sentinel, economics
Posture
- Secure score and recommendations
- Agentless vulnerability scanning
- Governance rules with owners
- Exemptions recorded with justification
Protection
- Plans per resource type
- Alerts grouped into incidents
- Just in time management access
- Connectors for other providers
Graph
- Relationships across the estate
- Attack paths to sensitive assets
- Security explorer queries
- Paid plan required
Sentinel
- Connectors into the workspace
- Analytics rules and entity mapping
- Automation rules and playbooks
- Workbooks and hunting queries
Economics
- Analytics, basic and archive
- Commitment tiers for volume
- Search jobs on cold data
- Retention driven by regulation
Quick exam traps
- Trap: The free posture tier includes the security graph and attack paths
- Trap: A suppression rule and an exemption do the same thing
- Trap: Servers outside Azure are protected without being onboarded
- Trap: Every Sentinel table is queryable at the same price
- Trap: An automation rule with a higher order value runs first
- Trap: A recommendation prevents the non-compliant resource being created
- Trap: Enabling a connector is the same as having a detection
cybercertprep.com · original revision sheet written from the public body of knowledge