Memory hook: Filter traffic, protect secrets, find exposure.
Must remember
Virtual networks/subnets segment network placement; NSGs filter permitted traffic at supported subnet/interface boundaries. Azure Firewall provides managed centralized network filtering; WAF addresses supported web-layer attacks; DDoS Protection addresses supported denial-of-service exposure. They work at different layers and are not interchangeable.
Azure Bastion provides managed remote access to supported VMs without exposing their RDP/SSH ports directly to the internet. Key Vault stores/manages supported secrets, keys and certificates with access control. A vault does not automatically rotate every application secret or eliminate the need to grant the application permission.
Defender for Cloud combines cloud security posture management and supported workload-protection plans. CSPM assesses configurations and recommendations; workload protection detects/protects specific workloads under enabled plans. Security standards and policies help assess alignment, but a score or recommendation list is not proof that every risk is resolved.
Shared responsibility changes with IaaS/PaaS/SaaS. The provider handles more infrastructure in managed services, while customer data, access and configuration responsibilities remain. Select controls from the threat and resource type, then validate effective behavior.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Protect a web app from common HTTP attacks | WAF at an appropriate supported ingress. |
| Central network filtering | Azure Firewall. |
| Find cloud misconfigurations | Defender for Cloud posture assessment. |
Traps
- WAF does not replace every network firewall function.
- A high posture score does not guarantee no compromise.
Active recall
1. NSG versus WAF?
Network traffic filtering versus web application request protection.
2. What is Bastion for?
Managed remote VM access without directly exposing the VM’s remote-admin ports publicly.
3. What does Key Vault hold?
Supported secrets, cryptographic keys and certificates.
4. CSPM versus workload protection?
Configuration/posture assessment versus protection/detection for specific workloads.
5. What remains a customer responsibility in SaaS?
Appropriate identities, data use and supported configuration, among other responsibilities.