Memory hook: Identity plus network plus data control; then evidence.
Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.
Scope/version: SC-500 is the current Cloud and AI Security Engineer path. AZ-500 retired in August 2026; the new exam includes substantial AI and agent-security content.
Must remember by domain
| Domain | Rapid revision |
|---|---|
| Identity/governance | Entra roles administer identity; Azure RBAC authorizes resource actions; data roles authorize service data. App registration defines an app, service principal represents it in a tenant. Delegated API permissions include user context; application permissions are app-only. PIM, Conditional Access and consent controls reduce exposure differently. |
| Keys/policy | Key Vault keys, secrets and certificates have different operations. Data-plane RBAC/access policy and management access are separate. Soft delete allows recovery; purge protection prevents early permanent purge. Rotation must preserve decryptability and client compatibility. Policy enforces supported configurations; locks protect management changes; backup protection needs explicit recovery controls. |
| Storage/databases | Grant minimum SAS/data roles and firewall/private endpoint access. Network permission alone cannot read data. SQL TDE encrypts files, TLS protects connections, Always Encrypted protects selected client-controlled columns, RLS filters rows and masking changes display. Enable audit/Defender plans for the actual database/storage service. |
| Networking | NSGs filter supported subnet/NIC flows; ASGs group targets; Network Manager centralizes supported policy. Firewall provides centralized network/application inspection; WAF inspects HTTP; VPN encrypts hybrid tunnels. Private Link resource, DNS, approval and public-access policy are separate. Private Access adds identity-aware access to supported private applications. |
| AI security | Remove SharePoint/source oversharing before assistants make it easy to discover. Purview DSPM for AI surfaces supported exposure/use. Agent ID needs owners, scoped access, Conditional Access and lifecycle. API Management AI Gateway controls supported model API policy; Foundry guardrails and deterministic tool authorization protect other boundaries. |
| Servers/apps | Bastion/JIT limit management exposure. Secure Boot/vTPM/integrity and encryption protect different layers. Arc extends management; Machine Configuration checks supported guest settings. Defender for Servers/Containers needs correct plans/onboarding. Registry scanning, workload identity, Kubernetes authorization/networking, app authentication and API/WAF policy complement each other. |
| Posture/operations | CSPM identifies misconfiguration/attack paths; workload protection detects supported threats; EASM finds external exposure. Connect AWS/GCP with scoped connectors. Sentinel needs source generation → connector/AMA/DCR → correct table → detection → incident → authorized automation. Security Copilot workspaces/plugins/agents require roles and evidence validation. |
Response order and traps
Confirm the exposed identity/data/path → contain narrowly → preserve evidence → remediate root permission/configuration → validate under the affected principal → monitor recurrence. Content Hub installation does not configure every connector. A private endpoint does not close public access automatically. A secure score is a prioritization signal, not certification that the environment is safe.
Last-pass self-check
1. Which permission plane lets an app read a Key Vault secret?
The selected Key Vault data-plane authorization model, plus a permitted network path.
2. Does a model gateway authorize every agent tool?
No. Downstream tools need independent validated permissions and action controls.
3. CSPM versus workload protection?
Posture/exposure assessment versus service-specific threat detection/protection.
4. What does a playbook require beyond an automation rule?
A compatible trigger and authorized Logic Apps/connector identity with appropriate target rights.
5. What must be checked after remediating overshared AI data?
Actual source access, retrieval filtering, cached/indexed copies and cross-tenant/user behavior.
Sources
- Official exam scope and version
- Azure documentation
- Microsoft Foundry documentation
- Microsoft Learn training
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Microsoft Entra ID and Azure RBAC
Memory hook: Entra identifies the principal; Azure RBAC authorises an action at a scope.
Must remember
- A Microsoft Entra tenant is an identity directory. An Azure subscription is a billing/resource-management boundary associated with a tenant. Management groups organise subscriptions; resource groups organise resources. Do not treat tenant and subscription as synonyms.
- Manage users, groups, properties, assigned licences and guest access deliberately. Security groups organise access; dynamic membership uses rules when licensing/features permit. B2B guests retain an external identity relationship. Self-service password reset needs appropriate eligibility, authentication methods and configuration.
- An Azure role assignment is principal + role definition + scope. Scope can be management group, subscription, resource group or resource, with inheritance. Inspect effective assignments rather than only the nearest resource. Entra directory roles and Azure resource roles are different permission systems.
- Owner can manage resources and access; Contributor manages resources but does not normally grant Azure roles; Reader reads management information. Data-plane roles, such as Storage Blob Data Reader, authorise data operations separately. Management-plane access is not always data access.
- System-assigned managed identity follows one resource's lifecycle; user-assigned identity is an independent reusable resource. Both avoid embedded secrets for supported authentication. Grant the identity's service principal only the required target roles.
- PIM supports time-bound/eligible privileged access; Conditional Access evaluates sign-in conditions and grant controls with appropriate licensing. MFA strengthens authentication; it does not create a missing resource role assignment. Keep a monitored emergency-access design.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| App needs storage access without stored credentials | Managed identity plus an appropriate data role. |
| User can manage a storage account but cannot read blobs | Check data-plane permissions. |
| Temporary privileged operations | Eligible/time-bound access using PIM where available. |
Traps
- Entra administrator is not automatically Owner of every Azure subscription.
- Contributor and Owner differ in access-management privileges.
- A role at a parent scope can remain effective after a narrower assignment is removed.
02 · Subscriptions, Policy and Cost Governance
Memory hook: RBAC decides who may act; Policy evaluates what configuration is acceptable.
Must remember
- A management-group hierarchy applies governance across subscriptions. Resources belong to resource groups and subscriptions, but not every resource type supports every move. Check dependencies, provider registration, quotas and move validation before changing scope.
- Azure Policy definitions evaluate resource properties; initiatives group policies; assignments apply them at scopes with exclusions/exemptions. Effects include audit, deny, modify and deployIfNotExists. Existing noncompliant resources may need a remediation task and suitable managed-identity permissions.
- A CanNotDelete lock blocks management-plane deletion; ReadOnly can block management operations that look like reads but use POST. Locks are inherited and are not a universal data-plane protection mechanism. A privileged user able to remove a lock can change its protection.
- Tags support ownership and cost allocation, but tags do not automatically inherit from resource group to resource. Policy can enforce or add supported tags. Keep a naming/tagging convention and handle untaggable/shared resources explicitly.
- Cost Management analyses spending; budgets notify configured thresholds; Advisor recommends improvements. A budget is not a universal immediate resource shutdown. Billing latency, reservations/savings commitments and shared costs affect interpretation.
- Resource groups are useful for lifecycle management, but deleting a group is a broad action. Review dependencies and locks first. Region affects resource availability, residency and price; the resource group's metadata location does not force every contained resource into that Region.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prevent unsupported regions at deployment | Azure Policy deny at the appropriate scope. |
| Let a team manage resources but not grant roles | Contributor, constrained to the required scope. |
| Find an oversized idle workload | Usage evidence plus Advisor/Cost Management recommendations. |
Traps
- Audit reports a problem; it does not block it.
- A tag on a group is not automatic tag inheritance.
- A budget alert is not a guaranteed spending cap.
03 · Storage Access, Encryption and Redundancy
Memory hook: Network reachability, authorisation and encryption are separate storage controls.
Must remember
- Storage accounts expose supported services such as blobs, files, queues and tables. Choose the account kind/features, Region and redundancy before relying on a capability. Names and endpoints have service-specific scope rules.
- Prefer Entra/managed-identity authorisation where supported. Account keys are broad credentials; rotate them with a staged client update. A SAS delegates selected operations for a time window and resource scope. User-delegation SAS uses Entra-backed delegation for supported Blob access; service/account SAS have different signing and capabilities.
- A stored access policy can centrally control/revoke associated supported service SAS permissions; it does not apply to every SAS type. Time skew, expiry, signed permissions, protocol and network restrictions can explain an otherwise valid token's failure.
- SAS recall: service SAS is signed with an account key and can reference a stored access policy; account SAS is signed with an account key and can cover supported account/service operations; user-delegation SAS is signed with an Entra-backed delegation key for supported Blob access. Stored access policies do not apply to account SAS or user-delegation SAS. Choose scope and revocation requirements before choosing the token type.
- Storage firewalls restrict network access. A service endpoint uses supported service networking and VNet rules; a private endpoint gives a private IP path and requires correct private DNS. Neither substitutes for authorisation. Disable public access deliberately when the requirement demands it.
- LRS replicates within one location; ZRS spans zones in a Region; GRS/GZRS add asynchronous geographic replication; RA variants allow supported secondary reads. Geo-replication lag affects possible data loss. Redundancy is not backup against authorised deletion.
- Storage encryption protects at-rest data; customer-managed keys add key lifecycle and access responsibilities. Object replication between supported blob accounts has prerequisites and scope; it is not a universal synchronisation of every storage service.
- Use Storage Explorer for interactive data management and AzCopy for scripted transfer. Choose an authentication method and validate source/destination permissions; success transferring a subset does not prove the entire dataset reconciles.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Temporary restricted blob access | A suitably scoped SAS, preferably user delegation when it fits. |
| Private IP access from a VNet | Private endpoint plus DNS and data authorisation. |
| Regional AZ resilience without a second Region | ZRS where supported. |
Traps
- A private endpoint does not automatically disable the public endpoint.
- RA-GRS secondary data may lag.
- A management role can lack permission to read stored data.
04 · Virtual Machines, Disks and Scale Sets
Memory hook: Size for the bottleneck, place for failure and distinguish stopped from deallocated.
Must remember
- Choose VM family/size using CPU, memory, storage throughput, networking and compatibility. Availability differs by Region and quota. Resizing may require restart/deallocation or a compatible host allocation; check disk and NIC limits too.
- Managed disks have performance and redundancy options. OS disks, data disks and temporary disks have different purposes; temporary storage is not durable business data. Snapshots capture disk state, but application consistency may require additional coordination.
- Availability sets distribute supported VMs across fault/update domains; availability zones distribute across zonal failure domains. A VM Scale Set manages a group of instances with selected orchestration, upgrade and autoscale behaviour. Health probes and application readiness affect safe replacement.
- Stopped within the guest can leave compute allocated and billed; deallocated releases allocation, though retained disks, snapshots and other resources can still bill. Public/private address behaviour depends on address configuration and lifecycle.
- Encryption at host protects supported host-side storage paths; disk encryption and guest/application encryption solve related but distinct requirements. Use trusted boot/security features where the workload and VM generation support them.
- Moving a resource group/subscription is a management-scope operation; moving to another Region generally involves a supported relocation/redeployment process. Validate dependencies, identity/role assignments, network addresses, extensions and backup settings after any move.
- Use Bastion or appropriate controlled administration paths. VM extensions and cloud-init/custom-data mechanisms help configure guests, but failed bootstrap scripts need logs and exit-status investigation. Never assume the portal's running state means the app is ready.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Scale a replaceable VM fleet | VM Scale Sets with health-aware policy. |
| Survive a zone loss | Sufficient working capacity across zones and resilient state. |
| Stop paying for allocated compute during a pause | Deallocate, then account for retained resources. |
Traps
- Guest shutdown and deallocation differ.
- Temporary disk data must be reproducible.
- A Region move is not merely changing a resource-group label.
05 · App Service and Container Platforms
Memory hook: Separate image storage, execution, application configuration and the hosting plan.
Must remember
- ACR stores container images/artifacts. Authenticate pushes/pulls with appropriate identities and roles; prefer immutable image digests for a known release. Registry access does not grant the running application permission to its database.
- Container Instances runs container groups without managing a cluster. Container Apps provides managed application environments, revisions, ingress and event-driven scaling capabilities. AKS gives Kubernetes orchestration with greater platform control and responsibility; it is not the default answer for every container.
- Size container CPU/memory and configure health/startup behaviour. Container Apps scaling rules and minimum replicas affect availability, cold starts and cost. Separate revision traffic from image publishing; pushing an image alone is not necessarily deployment.
- An App Service plan determines shared compute capacity, Region and pricing tier; apps run within it. Scale up changes plan capability; scale out changes instance count. Apps sharing a plan can compete for its resources.
- Deployment slots support staged releases and swaps on eligible tiers. Mark environment-specific settings as slot settings where needed. Warm up and validate the target before swapping; external database changes require their own compatibility plan.
- Configure custom-domain ownership, DNS records and TLS bindings separately. VNet integration primarily handles supported outbound access; private endpoints support private inbound access. Access restrictions, DNS and the destination's permissions still matter.
- Backup support depends on plan/features and configuration; define a restore test. Managed identity and Key Vault references reduce stored credentials. Inspect app logs and dependency/network failures before simply increasing plan size.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Run a small container without managing nodes | Container Instances or Container Apps, according to application/scaling needs. |
| Test a web release before moving users | App Service deployment slot. |
| App needs private database access | Supported VNet integration plus routes, DNS and authorisation. |
Traps
- A registry is not a container runtime.
- VNet integration is not equivalent to private inbound access.
- A slot swap does not reverse database writes.
06 · Virtual Networks, Routes and Secure Access
Memory hook: Check the effective route and the effective rule in both directions.
Must remember
- VNets contain address spaces and subnets. Plan non-overlapping ranges and future growth; supported peering requires compatible addresses. Peering connects VNets but is not automatically transitive through a third VNet.
- Azure selects routes using prefix specificity and route-source precedence for equal prefixes; inspect effective routes when system, BGP and user-defined routes interact. A UDR can direct traffic to a virtual appliance, but the appliance must forward it and the return path must work.
- For ordinary equal-prefix comparisons, remember UDR → BGP → system; first compare the destination prefix length. A matching
/24normally beats a/16regardless of that general source order. Service-specific routes have exceptions: service-endpoint routes cannot simply be overridden by a UDR. Inspect the effective route rather than treating the mnemonic as universal. - Azure reserves the first four and last IPv4 addresses of each subnet. A
/27contains 32 addresses, leaving 27 usable; service-specific subnet sizing can require more than the generic minimum. Subnet capacity planning must include service reservations and scale-out needs. - NSGs are stateful network filtering with priority-ordered allow/deny rules. They can apply at subnet and NIC scopes; evaluate the effective combination. Application security groups group supported VM interfaces for rule targeting; they are not application-layer WAFs.
- Public IP addresses have SKU/allocation/zone properties. NAT Gateway supports explicit outbound SNAT for associated subnets; consider port use and destination patterns. Do not assume new workloads receive default outbound internet access.
- Bastion provides managed administration through supported private VM access without exposing a public management port on each VM. It still needs the required deployment/network configuration and authorised users.
- Service endpoints extend supported service access from a VNet using its public service endpoint and service-side rules. Private endpoints use a private IP for a specific resource/subresource; DNS must resolve appropriately. Endpoint creation and resource approval are separate checks.
- Diagnose with Network Watcher tools, Connection Monitor, effective security rules/routes, name resolution and application listener checks. Existing stateful flows may not behave like brand-new test connections after a rule change.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| One private PaaS resource endpoint | Private Link/private endpoint with private DNS. |
| Traffic must traverse a network appliance | UDR plus forwarding and a symmetric return path. |
| VM administration without a VM public IP | Bastion where appropriate. |
Traps
- Peering is not automatically transitive.
- A service endpoint does not put the service itself inside your subnet.
- An NSG allow does not create a route.
07 · Azure Monitor, Logs and Alerts
Memory hook: Metrics quantify, logs explain, traces connect and alerts start a response.
Must remember
- Azure Monitor combines metrics and logs; Log Analytics workspaces hold queryable log data. Activity Log records management-plane events; resource/application logs require relevant collection configuration. Diagnostic settings route supported categories to selected destinations.
- Azure Monitor Agent uses data collection rules for supported guest telemetry. VM, Storage and Network Insights provide focused views; Application Insights adds application performance and tracing with suitable instrumentation. Guest memory/disk metrics are not automatically identical to platform metrics.
- KQL pipelines transform tables:
wherefilters,projectselects columns,summarizeaggregates,bin()groups time intervals, and joins combine data. Example:Heartbeat | summarize LastSeen=max(TimeGenerated) by Computerfinds each computer's latest recorded heartbeat; absence can mean collection failure, not only host failure. - Alert rules define signal, scope, evaluation and condition. Action groups define notifications/actions. Alert processing rules modify processing such as suppression under selected conditions; they do not change the source telemetry. Use dynamic thresholds where appropriate and test missing-data behaviour.
- Network Watcher and Connection Monitor help inspect path and connectivity. Logs, effective routes/rules and an application test answer different questions. Narrow time windows and correlation IDs reduce noise; retention and ingestion volume affect cost.
- Monitor the collection pipeline itself. Permissions, network access, workspace configuration and data collection rules can break visibility. Avoid logging secrets and unnecessary personal data, and define retention according to operational/evidence requirements.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Who changed an Azure resource? | Activity Log and relevant audit evidence. |
| Notify an operations group on a metric breach | Alert rule linked to an action group. |
| Investigate recurring connection failures | Connection Monitor plus route, rule and application evidence. |
Traps
- No logs can mean no collection.
- Action groups do not define the alert threshold.
- Average response time can conceal severe tail latency.
08 · Azure Backup and Site Recovery
Memory hook: Backup restores a point; replication supports failover; neither is proven until tested.
Must remember
- Recovery Services vaults and Backup vaults support different workload/protection scenarios. Select the vault type, Region, redundancy and policy supported by the resource. A vault existing does not mean a backup is configured or healthy.
- Backup policies control schedule/retention; backup instances/items and recovery points show actual protection. App-consistent recovery requires supported coordination. Soft delete and immutability settings can protect backups but also affect deletion and retention obligations.
- Restore to the intended location or an isolated validation environment as supported. Check encryption-key access, identity permissions, networking, data consistency and application startup. Monitor job failures, missing recovery points and restore results, not just policy assignments.
- Site Recovery replicates supported workloads for disaster recovery. Recovery plans coordinate sequencing and automation. A test failover validates a separate test environment; planned and unplanned failover have different source availability and data-loss implications.
- RPO measures tolerable lost data/time; RTO measures time to useful service. Replication lag, application dependencies, DNS, certificates, secrets and capacity all affect the measured result. Failback needs reverse protection/synchronisation and deliberate traffic control.
- Keep recovery responsibilities documented, practise drills and review costs for replicas, snapshots, storage and reserved recovery capacity. Replication can preserve infrastructure availability while still copying logical corruption.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Recover data before an accidental deletion | A suitable retained backup/recovery point. |
| Move a supported workload to a DR Region during outage | Site Recovery failover with a tested recovery plan. |
| Validate DR without disrupting production | Test failover in an isolated network. |
Traps
- Replication is not historical backup.
- A successful backup job does not measure restore time.
- A vault lock/immutability policy must match retention and deletion requirements.
09 · Defender, Key Vault and Preventive Controls
Memory hook: Posture finds exposure; workload protection detects threats; prevention still needs correctly scoped policy.
Must remember
- Distinguish app registrations (application definitions) from enterprise applications/service principals (tenant instances). OAuth delegated/application permissions and consent have different implications. Review grants, publisher trust, owners and overprivileged roles; use PIM and Conditional Access where appropriate.
- Key Vault separates keys, secrets and certificates. Configure its authorisation model, network access, soft delete/purge protection and lifecycle deliberately. Rotation needs compatible clients and recovery planning. Defender for Key Vault and CSPM secret discovery provide different detection capabilities.
- Defender for Cloud CSPM assesses posture and attack paths; workload protection plans cover supported services. Enable the required plans and connectors rather than assuming every workload is protected by default. Regulatory-compliance views organise evidence, not automatic legal certification.
- For servers, use supported trusted-launch/secure-boot/vTPM/integrity features, encryption, JIT access and Bastion. Arc brings supported hybrid/multicloud resources into management; Defender for Servers supports vulnerability/EDR and agentless capabilities according to plan/configuration. Machine Configuration evaluates/enforces supported guest baselines.
- Protect containers with image/runtime assessment, registry restrictions, workload identity, Kubernetes RBAC/network controls and secure configuration. Secure Functions, Logic Apps and App Service using identities, authentication and network restrictions. API Management policies and WAF protect different application boundaries.
- Secure storage and SQL with identity/data permissions, firewalls/private endpoints, encryption, auditing and appropriate Defender plans. Network Manager/security admin rules, Firewall, Virtual WAN controls and Entra Private Access serve distinct access/inspection needs; verify effective rules and routes.
- EASM discovers externally visible assets/exposure; vulnerability management identifies supported weaknesses. Connect AWS/GCP environments through supported Defender connectors with scoped permissions. Remediation should prioritise exploitable paths and business impact, then verify the fix.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Find risky combinations of permissions and exposure | CSPM/attack-path analysis with workload context. |
| Limit administrative port exposure | JIT and controlled access such as Bastion. |
| Detect unexpected public assets | External Attack Surface Management. |
Traps
- Enabling one Defender plan does not enable all protection.
- Compliance score is not proof of complete security.
- A secret rotation can break clients if retrieval/cache behaviour is ignored.
10 · AI Data Exposure and Agent Security
Memory hook: An agent can combine every permission it receives; constrain its identity, context and tools.
Must remember
- Review overexposed SharePoint data and source permissions before deploying search/assistant experiences. Retrieval can make existing oversharing easier to exploit. Purview DSPM for AI helps discover/classify relevant risk and data-use patterns; remediation still needs ownership and access changes.
- Agent identities require lifecycle, owners, least privilege and access reviews. Entra Agent ID and supported Conditional Access controls help govern agent access; inspect blast radius and related signals through Defender XDR where supported. Do not share a broad human administrator identity with agents.
- Copilot Studio agents need supported real-time protection and controlled connectors/actions. Manage deployed agents through relevant administration surfaces, including Microsoft 365 admin centre where applicable. A published agent can expose tools even when its chat interface looks harmless.
- API Management AI Gateway can centralise supported model access policies, token/rate controls and observability. It does not make every downstream tool action authorised. Foundry guardrails and tool-access constraints should be tested against direct/indirect prompt injection and sensitive-data leakage.
- Enable appropriate Defender for AI service/workload protection and inspect the Data and AI security dashboard. Correlate risky data, identity and runtime signals rather than treating a single filter as a complete defence.
- Log AI interactions with minimisation/redaction, provenance and retention controls. Validate outputs before commands/queries/actions; require approvals for consequential operations. Test tenant separation, revoked access, poisoned retrieval and tool-result injection, not only offensive user prompts.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Assistant exposes documents too broadly | Repair source permissions and retrieval authorisation. |
| Agent needs one business operation | A scoped agent identity/tool permission. |
| Need central model API policy and usage controls | A supported API Management AI Gateway design. |
Traps
- Existing document oversharing becomes an AI risk.
- A model refusal is not a substitute for denied tool permission.
- Agent identity governance must continue after initial deployment.
11 · Sentinel, Incident Automation and Security Copilot
Memory hook: Collect the right evidence, correlate it, then authorise every response action.
Must remember
- Sentinel uses supported workspaces, data connectors, analytics content and incident workflows. Assign appropriate Sentinel/workspace roles. Content Hub solutions supply supported connectors/rules/workbooks; installing content is not the same as configuring data collection.
- Syslog/CEF, Windows Security events and WEF require the correct collection pipeline, agent/forwarder and data collection rules. Custom logs need appropriate tables/schema and ingestion configuration. Verify arrival, parsing, timestamps and retention before relying on detections.
- Analytics rules correlate events into alerts/incidents under their configuration. Automation rules coordinate incident handling; playbooks use Logic Apps for response. Scope managed identities and target permissions, add approvals where needed and make actions idempotent.
- Define retention for relevant data stores based on investigation and cost needs. A missing event may reflect connector permissions, DCR configuration, network, parser or retention failure. Query Purview Audit through supported Defender XDR capabilities for the relevant audit scenario.
- Security Copilot workspaces, roles, plugins and supported agents control who can use which capabilities. Enable only needed plugins and review their data/action access. Microsoft and Security Store agents need the same ownership, evaluation and permission discipline as other automation.
- Treat generated investigation summaries as assistance that requires evidence validation. Preserve source links, analyst decisions and response audit. A confidently worded recommendation is not authorisation to isolate a business-critical service without the defined response process.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| No Windows events appear in Sentinel | Inspect collection rules, forwarding/agent, connector and workspace arrival. |
| Repeated incident needs a standard response | Automation rule plus a scoped, tested playbook. |
| Copilot must use one external capability | Enable the specific plugin with reviewed permissions. |
Traps
- Content installation does not prove telemetry is flowing.
- A playbook can have broader permissions than its trigger author.
- AI-generated incident analysis can contain unsupported conclusions.
12 · SQL Security and Compliance Controls
Memory hook: Authentication identifies; permissions authorise; encryption and masking protect different exposures.
Must remember
- Configure Entra or SQL authentication as supported. Logins, database users, roles and object permissions have different scopes. Use least privilege through T-SQL or supported tools; distinguish failure to authenticate from successful login with insufficient database rights.
- TDE protects supported database files/backups at rest; TLS protects connections; object-level encryption and Always Encrypted address different threat models. Always Encrypted keeps selected data encryption under client control; secure enclaves enable supported confidential computations with additional requirements.
- Firewall rules, service endpoints and private links restrict access paths. A permitted network connection still needs database authentication and permissions. Key Vault/key rotation and recovery must preserve the ability to decrypt retained data.
- Dynamic data masking changes how selected users see results; it is not a robust boundary against a principal able to infer/query underlying data broadly. Row-level security filters accessible rows using defined policy logic; test administrative and application contexts.
- Classification labels identify sensitive data; audits record configured operations. Change tracking/CDC serve change-consumption purposes and are not identical to security audit. Ledger adds tamper-evidence capabilities; it does not replace backup or prove every business input was truthful.
- Review access, audit retention and export destinations, privileged identities and incident procedures. A data breach investigation needs identity, query and configuration context, not only a screenshot of enabled encryption.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Protect database files at rest | TDE with sound key management. |
| Keep selected plaintext from the database service boundary | Evaluate Always Encrypted and application compatibility. |
| Different users may access different rows | Row-level security with tested policy logic. |
Traps
- Masking is not encryption.
- TDE does not prevent an authorised query from returning plaintext.
- Network allow rules do not grant SQL permissions.