SC-100 · Domain 2
Design security operations, identity, and compliance capabilities
About 27% of the exam
Identity building blocks
- Entra ID
- the directory and token issuer
- Conditional Access
- the policy engine for access
- Identity Protection
- user and sign in risk signals
- Privileged Identity Management
- eligible roles with time bound activation
- Identity Governance
- access packages and reviews
- Lifecycle workflows
- joiner, mover and leaver automation
- Managed identities
- workload credentials the platform rotates
- Workload identity federation
- external tokens exchanged, nothing stored
Privileged access design
- Enterprise access model
- control, management and data planes
- Tier zero
- anything that can control identity
- Privileged workstation
- hardened device, restricted outbound access
- Just in time
- activate with approval and expiry
- Access reviews
- recertify who still needs it
- Phishing resistant methods
- security keys and certificate sign in
- Emergency accounts
- excluded, monitored and tested regularly
Directory synchronization servers sit in tier zero because they can write credentials, so they are administered from privileged workstations by privileged accounts only
Conditional Access patterns
- Require compliant or hybrid joined devices
- Scope privileged roles to management applications
- Sign in frequency for sensitive applications
- Token protection binds tokens to devices
- User actions cover registration events
- Network signals from the secure access service
Hybrid identity choices
- Password hash sync
- survives on premises outages
- Pass through authentication
- validates against domain controllers live
- Federation
- an external provider issues tokens
- Hybrid join
- devices get seamless single sign on
- Group writeback
- cloud groups pushed into the directory
- Account state
- disabled accounts block cloud sign in
Delegation at scale
- Administrative units scope roles regionally
- Restricted units protect privileged accounts
- Custom roles for narrow tasks
- Provisioning driven by personnel system data
- Cross domain provisioning to software services
Operations metrics
- Mean time to detect and respond
- Dwell time from compromise to detection
- Alert fidelity and false positive rate
- Coverage against relevant adversary techniques
- Automation rate for repeatable actions
The operations platform
Sentinel
- Connectors for cloud and syslog sources
- Analytics rules and hunting queries
- Automation rules trigger playbooks
- Content hub packages versioned solutions
- Commitment tiers control ingestion cost
Defender XDR
- Correlates identity, endpoint, mail and cloud
- Incidents rather than isolated alerts
- Automated investigation and response
- Advanced hunting across the estate
- Feeds Sentinel where both run
Posture management
- Secure score across clouds and workloads
- A regulatory compliance dashboard per standard
- Attack path analysis over the graph
- Governance rules assign owners and dates
- Exemptions only for documented accepted risk
Compliance tooling
- Compliance Manager tracks improvement actions
- Assessments map controls to standards
- Purview covers labeling and governance
- Azure Policy enforces the technical controls
- Boundary offerings address data residency
Detection engineering
- Prioritize gaps in relevant techniques
- Normalize sources to a common schema
- Severity aligned to incident classification
- Validate detections with safe adversary emulation
- Suppress known good using watchlists
- Record telemetry gaps as engineering work
Response automation
- Automation rules route and tag incidents
- Playbooks revoke sessions and disable accounts
- Human approval for disruptive actions
- Orchestration spans tools, automation runs tasks
- Avoid blanket auto closure of alerts
Governance and risk concepts
- Risk appetite
- how much risk leadership accepts
- Risk tolerance
- the threshold for one category
- Risk velocity
- how fast the impact arrives
- Three lines
- operations, oversight, independent assurance
- Key risk indicator
- an early warning with thresholds
- Loss expectancy
- compare control cost against savings
Designing the operations capability
- Define what must be detected
- Inventory and connect the sources
- Normalize and retain sensibly
- Build and tune the analytics
- Automate the safe responses
- Measure detection and response times
- Review coverage every quarter
- Ingestion cost shapes retention design
- Coverage beats volume every time
- Playbooks need owners and testing
- Regulated incidents carry reporting deadlines
Service to purpose
- Identity Protection
- risk signals for access policy
- Privileged Identity Management
- time bound privileged activation
- Identity Governance
- access packages and reviews
- Defender for Cloud
- posture and workload protection
- Sentinel
- collection, detection and orchestration
- Purview
- information protection and governance
- Compliance Manager
- control tracking and scoring
Licensing hints
- Risk based policies
- require the premium identity tier
- Privileged Identity Management
- the premium identity tier too
- Access reviews
- governance capabilities licensed separately
- Defender plans
- enabled per resource type
- Sentinel
- priced by data ingested
Reference strip: identity, privilege, operations, posture, compliance
Identity
- Conditional Access decides everything
- Managed identities remove secrets
- Lifecycle workflows handle leavers
Privilege
- Eligible, never standing
- Approval, expiry and audit
- Hardened workstations for tier zero
Operations
- Connect, normalize, detect, automate
- Measure detection and response
- Emulate to validate detections
Posture
- Secure score across clouds
- Attack paths beat single findings
- Owners and dates on recommendations
Compliance
- Dashboards per regulatory standard
- Improvement actions carry owners
- Residency handled by boundaries
Quick exam traps
- Trap: A permanent owner assignment is fine as long as it is reviewed
- Trap: A high secure score proves the environment is not compromised
- Trap: Defender for Cloud and Sentinel do the same job
- Trap: Conditional Access can be satisfied by a device declaring itself compliant
- Trap: Automating closure of low severity alerts is always a saving
- Trap: Compliance Manager scores are assurance that controls actually operate
- Trap: Password hash synchronization sends plaintext passwords to the cloud
cybercertprep.com · original revision sheet written from the public body of knowledge