Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

Flash card Module 9- Manage Security Operation in Azure

142 views

Published on

Flash card Module 9- Manage Security Operation in Azure

Published in: Technology
  • Be the first to comment

  • Be the first to like this

Flash card Module 9- Manage Security Operation in Azure

  1. 1. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Flash Card – Manage security operation in Azure Prepared by Lai
  2. 2. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Azure Security Center Monitoring service that provide threat protection across services in Azure & on-prem Free Tier Limited to assessment & recommendation of Azure resources Standard Tier Full suite of security related services including continuous monitoring, threat detection, just in time access control for ports & more
  3. 3. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Azure Security Center View Security Alert Workflow automation
  4. 4. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Stop brute force attack Disable public IP address & use VPN Use two factor authentication Limit login attempt Increase password length & complexity Implement Captcha Limit amount of time that the ports are open Enable JIT VM access (restrict access to management ports when not in use & approved IP add that can access these ports) -STANDARD TIER-
  5. 5. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Protect against malware Install antimalware – Microsoft Antimalware for Azure Cloud Services & VM Use firewall to block network traffic Integrate antimalware solution with Azure Security Center to monitor the status of the anti malware protection Up to date latest OS fixes and version Antimalware available as an extension
  6. 6. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Azure Active Directory Cloud based identity service. Built in support for synchronization with existing on-prem AD or standalone Authentication SSO MFA
  7. 7. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Encryption Encrypt raw storage -Azure storage Service Encryption Encrypt VM disk -Azure Disk Encryption (bitlocker or dm- crypt) Encrypt database -Transparent data encryption (encrypt/decryption of the database, backup & transaction log files Encrypt secret Use Azure Key Vault to protect secret key
  8. 8. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Protect Network Azure Firewall Managed, cloud based, network security service that protect Azure Virtual Network Resources . Stateful Azure Application Gateway Is a load balancer that include Web Application Firewall (WAF). Designed to protect HTTP traffic Network Virtual Appliance Similar like hardware firewall appliances
  9. 9. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Virtual network Security Filter network traffic to & from Azure resources in an Azure virtual network. Network Security Group (NSG) VPN Secure comm channel between on-prem & cloud
  10. 10. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Protect Shared Document Classify and optionally protect doc & email by applying label Azure Information Protection (AIP)
  11. 11. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Azure Monitor Log Extract valuable info about your infra from log data Gather Monitoring & Diagnostic info about the health of services Visualize & analyze the causes of the problem Collect Metric - How resource is performing & consuming Collect Log - Show when resources are created or modified
  12. 12. © 2019 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. Thank You

×