SC-100 · Domain 3
Design security solutions for infrastructure
About 27% of the exam
Landing zones and governance
- Management groups
- policy inherited by every subscription
- Platform subscriptions
- identity, management and connectivity separated
- Online group
- internet facing workloads with dedicated controls
- Corp group
- workloads needing private connectivity only
- Deny effects
- reject non compliant deployments outright
- Deploy if not exists
- add the missing setting automatically
- Remediation identity
- the assignment needs its own role
Network design
- Hub and spoke
- shared services in a central network
- Forced tunneling
- default route pointed at the firewall
- Firewall network rules
- address, port and protocol filtering
- Firewall application rules
- domain name filtering for outbound web
- Route server
- dynamic routing with virtual appliances
- Bastion
- administrative sessions without public addresses
- Translation gateway
- one fixed outbound address, no inbound
- Peering pitfalls
- a route can bypass the firewall
Private access to services
- Private endpoints replace public service access
- Public network access set to disabled
- Private zones resolve the private address
- On premises resolvers forward those zones
- Never hardcode the private addresses
- Service endpoints are the older pattern
Defender for Cloud plans
- Servers plan adds endpoint and vulnerability coverage
- Agentless scanning reads disk snapshots
- Containers plan covers registries and clusters
- Storage, database and key vault plans
- The benchmark is assigned on enablement
- Compliance dashboard maps to standards
Hybrid and multicloud
- Arc projects servers into the platform
- Policy and posture follow those machines
- Connectors assess other cloud accounts
- Federation replaces stored cross cloud keys
- One benchmark spans several clouds
Endpoint and workload defense
- Attack surface reduction rules block behaviors
- Device isolation preserves memory for investigation
- Guest configuration reports on host hardening
- Update management tracks missing patches
- Just in time access closes management ports
Perimeter services, chosen by need
- Application gateway with firewall
- regional web filtering and termination
- Global entry with firewall
- edge filtering close to users
- Azure Firewall
- central egress and network filtering
- Network security groups
- subnet and interface level rules
- Application security groups
- rules that follow workload roles
- Denial of service protection
- volumetric defense at the edge
Layer seven inspection and network layer filtering answer different questions, so a scenario naming rule sets and domain names is pointing at different services
Securing management access
- Remove public management addresses
- Route administration through bastion
- Require privileged workstations
- Enforce Conditional Access on management
- Activate roles just in time
- Log every session centrally
- Review access and alerts regularly
- Site to site tunnels can bypass the design
- Scope address spaces to exclude management
- Directory sign in extensions cover virtual machines
- Break glass paths documented and tested
Storage and key protection
- Disable shared key access entirely
- Assign data roles instead of keys
- Firewall the account to known networks
- Soft delete and purge protection enabled
- Managed hardware modules for strict requirements
- Rotation policies generate new key versions
Operational technology and devices
- Passive sensors on mirrored traffic only
- Discovery of unmanaged industrial devices
- Protocol anomalies raised as alerts
- Findings routed into the operations platform
- Certificate based identity for device provisioning
Infrastructure design errors
- Public addresses allowed by exception creep
- Routes added that skip inspection
- Policy applied per subscription, not inherited
- Recommendations left without owners or dates
- Vaults deletable by a single administrator
Policy effect to outcome
- Audit
- record without blocking anything
- Deny
- reject the deployment outright
- Modify
- adjust properties during deployment
- Deploy if not exists
- create the missing companion resource
- Append
- add required fields automatically
- Exemption
- a documented, time bound exception
Connectivity chosen by need
- Site to site tunnel
- quick encrypted link over internet
- Dedicated circuit
- private bandwidth with a lead time
- Network peering
- direct traffic between two networks
- Bastion
- browser based administrative sessions
- Private endpoint
- a service reached privately
Hardening a subscription, step by step
- Place it under the right management group
- Apply the inherited policy set
- Enable the relevant protection plans
- Remove public exposure
- Route egress through inspection
- Onboard telemetry to the workspace
- Assign owners to the findings
- Inheritance prevents drift as estates grow
- Deny beats detecting after the fact
- Agentless scanning avoids agent gaps
- Exemptions expire, they do not accumulate
Reference strip: governance, network, posture, endpoints, secrets
Governance
- Management groups carry policy
- Deny at the top
- Remediation needs an identity
Network
- Hub, firewall, forced routing
- Private endpoints over public
- Watch for bypass routes
Posture
- The benchmark is assigned automatically
- A compliance dashboard per standard
- Owners and due dates
Endpoints
- Surface reduction rules first
- Isolate without powering off
- Patch state tracked centrally
Secrets
- No shared keys
- Soft delete and purge protection
- Rotate on a policy
Quick exam traps
- Trap: A private endpoint alone stops public access to the service
- Trap: Network security groups can filter by domain name
- Trap: Applying policy per subscription is equivalent to inheritance
- Trap: Deploy if not exists works without a managed identity
- Trap: Machines connected through Arc cannot be covered by posture management
- Trap: Isolating a device requires shutting it down
- Trap: Soft delete alone prevents a key from being purged
cybercertprep.com · original revision sheet written from the public body of knowledge