Directory and configuration changes involving users, groups, applications, roles, and policies.
17
New cards
What is Microsoft Defender for Endpoint?
An endpoint-security platform providing prevention, detection, investigation, vulnerability visibility, and response capabilities.
18
New cards
What is Microsoft Defender for Cloud?
A cloud-security platform providing security-posture management and workload protection.
19
New cards
What is the cloud shared-responsibility model?
The cloud provider secures the underlying infrastructure, while the customer remains responsible for areas such as identities, data, configuration, and workloads depending on the service model.
20
New cards
What is cloud IAM?
Policies and controls that determine which identities can perform actions on cloud resources.
21
New cards
What is a cloud misconfiguration?
An insecure or unintended configuration that exposes resources, identities, services, or data.
22
New cards
Why can activity in an unusual cloud region be suspicious?
It may indicate compromised credentials, unauthorized resource creation, or attacker evasion, although business context must be verified.
23
New cards
Why are cloud access keys sensitive?
They can provide programmatic access to cloud resources and may remain valid without interactive MFA.
24
New cards
Why should hardcoded credentials be avoided?
They may be exposed through source code, repositories, configuration files, logs, or system images.
25
New cards
What should be reviewed for a risky cloud sign-in?
User, IP address, location, device, application, authentication method, MFA result, Conditional Access result, session activity, and subsequent resource acces