1/45
Comprehensive set of vocabulary flashcards covering key security, compliance, identity, Entra, Defender, Purview, and Sentinel concepts for the SC-900 exam.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Shared Responsibility Model
A cloud security model where Microsoft secures physical datacenters, hardware, and foundational platform, while customers always retain responsibility for their data, identities, accounts, endpoint configuration, and access decisions.
Defense in Depth
A security strategy using multiple independent layers of defense—physical, identity and access, perimeter, network, compute, application, and data—so that if one control fails, another limits damage.
Zero Trust
A security model guided by three principles: verify explicitly, use least privilege, and assume breach. Trust is evaluated continuously using identity, device, location, risk, application, and data signals.
Encryption
A reversible process that uses a key to protect data confidentiality both at rest and in transit.
Hashing
A one-way cryptographic process that generates a unique value used to support integrity checks and password verification.
Governance, Risk, and Compliance (GRC)
A framework where Governance sets direction and accountability, Risk Management identifies and treats uncertainty, and Compliance demonstrates alignment with laws, regulations, contracts, and internal requirements.
Authentication
The process of proving who or what an identity is.
Authorization
The process that determines what resources or actions an identity is allowed to access.
Federation
A configuration that creates a trust relationship between identity systems, allowing users to access resources across organizational boundaries.
Microsoft Entra ID
Microsoft's cloud identity and access management service that manages authentication, authorization, SSO, application access, devices, and identity governance.
Workload Identities
Identity types that represent non-human applications and services, commonly implemented as service principals or managed identities.
Hybrid Identity
An identity configuration that connects on-premises directories with Microsoft Entra ID to provide a consistent identity across local and cloud resources.
Multifactor Authentication (MFA)
An authentication process that requires two or more different factor categories: knowledge (e.g., passwords), possession (e.g., phones/security keys), or inherence (e.g., biometrics).
Self-Service Password Reset (SSPR)
A Microsoft Entra capability that allows users to reset or unlock their own accounts after completing identity verification.
Conditional Access
An if-then policy engine in Microsoft Entra that evaluates contextual signals (user, app, device, location, risk) to enforce decisions like allow, block, require MFA, or limit session access.
Entitlement Management
A Microsoft Entra identity governance feature that packages resources along with approval and lifecycle access rules into access packages.
Access Reviews
A feature in Microsoft Entra identity governance used to periodically reconfirm that user access to resources or groups is still required.
Privileged Identity Management (PIM)
A service that controls privileged administrative roles by providing just-in-time, time-limited, and approval-capable role activation.
Microsoft Entra ID Protection
An identity security service that detects and helps remediate identity risks, specifically identifying risky users and risky sign-ins.
Azure DDoS Protection
A network defense service designed to mitigate large-scale, volumetric network attacks.
Azure Firewall
A managed, stateful network firewall service that filters traffic across Azure resources.
Web Application Firewall (WAF)
A security solution that protects web applications from common web vulnerabilities and attacks, such as SQL injection and cross-site scripting.
Network Security Groups (NSG)
Azure security controls used to allow or deny inbound and outbound network traffic at the subnet or network interface level.
Azure Bastion
A service providing secure, browser-based RDP and SSH connectivity directly to virtual machines without exposing public IP addresses.
Azure Key Vault
A centralized cloud service for securely storing and managing application secrets, encryption keys, and certificates.
Microsoft Defender for Cloud
A cloud-native security management tool combining Cloud Security Posture Management (CSPM) and cloud workload protection across Azure, multi-cloud, and on-premises environments.
Cloud Security Posture Management (CSPM)
A capability in Microsoft Defender for Cloud that assesses resource configurations against standards, provides a posture score, and gives recommendations for hardening.
Microsoft Sentinel
A cloud-native SIEM and SOAR solution used for centralizing, analyzing, hunting, and automatically responding to security data across the enterprise.
SIEM (Security Information and Event Management)
A technology category that aggregates and correlates security data from across an organization to support threat detection, investigation, and hunting.
SOAR (Security Orchestration, Automation, and Response)
A capability that uses automated workflows (such as playbooks) to orchestrate and execute response actions to security incidents.
Microsoft Defender XDR
An integrated security operations solution that correlates threat signals across endpoints, identities, email/collaboration, and cloud apps into unified incidents.
Microsoft Defender for Endpoint
A component of Microsoft Defender XDR that delivers security, threat prevention, and response for client devices and servers.
Microsoft Defender for Office 365
A security product that protects organizations against threats in email, links, and collaboration tools.
Microsoft Defender for Identity
A security solution that monitors identity signals from Active Directory environments to identify and investigate advanced threats.
Microsoft Defender for Cloud Apps
A cloud access security broker (CASB) offering visibility, governance, and protection across SaaS application usage.
Microsoft Defender Vulnerability Management
A solution that discovers, assesses, prioritizes, and helps remediate software weaknesses and misconfigurations on endpoints.
Service Trust Portal
A Microsoft resource site providing audit reports, compliance documentation, and trust publications.
Microsoft Purview
A comprehensive suite of capabilities designed to bring together data security, data governance, risk management, and compliance.
Compliance Manager
A tool in Microsoft Purview that maps controls to compliance requirements, tracks improvement actions, and calculates a compliance score.
Content Explorer
A Microsoft Purview tool that allows authorized users to view items containing sensitive information types or applied sensitivity/retention labels.
Activity Explorer
A Microsoft Purview capability that tracks and displays user actions taken on labeled or sensitive content.
Sensitivity Labels
Purview tags used to classify and protect content by enforcing encryption, visual markings, access restrictions, or container settings.
Data Loss Prevention (DLP)
A security policy engine in Microsoft Purview that monitors sensitive data and can audit, warn, block, or restrict risky sharing and usage across workloads.
Retention Policies
Broad lifecycle rules applied across entire locations or workloads to preserve or delete content based on organizational requirements.
Retention Labels
Item-level lifecycle controls applied directly to specific files or emails to manage their retention or deletion schedules.
Records Management
A specialized Purview compliance capability that provides stricter lifecycle and retention governance controls specifically for declared records and regulatory records.