SlideShare a Scribd company logo
1 of 10
Download to read offline
(DDoS) attack: Large scale attacks to bring your apps down
Result: App goes down or become slow. Huge bill because of unlimited auto scaling.
Two Azure DDoS offerings:
DDoS Protection Basic: Protects against common network layer attacks
Intelligently identifies and blocks DDoS attacks
Enabled by default
No extra cost
DDoS Protection Standard:
Mitigates 60 different DDoS attack types
Provides attack analytics, metrics, alerting and reporting
Get quick support from DDoS Protection Rapid Response (DRR) team
Get a Cost guarantee ( Receive service credit if DDoS attack results in scale-out)
Enable it on the Azure virtual network
DDoS Protection Standard + Web Application Firewall = Powerful combination that protects at:
Network layer (Layer 3 and 4, Azure DDoS Protection Standard)
Application layer (Layer 7, WAF)
Azure DDoS
Azure DDoS
97
Managed network security service to control traffic in and out of a
Azure Virtual Network
Stateful: Once traffic in is allowed, traffic out is automatically allowed
Centralized Configuration: With one Azure firewall, you can control traffic to
multiple virtual networks (having hundreds of resources) across multiple
subscriptions
Example : If your enterprise has 10 virtual networks (across multiple subscriptions) with 100 VMs,
you can control traffic with one Azure Firewall
Integrates with Azure Monitor: Provides logging and analytics
(REMEMBER) Web application firewall (WAF)
Restrict traffic into web applications
OWASP etc
Supported by Azure Application Gateway, Azure Content Delivery Network
Azure Firewall
Azure Firewall
98
Azure Firewall is an external firewall - outside your Virtual Network
Network Security Group (NSG) is like a internal firewall inside your Virtual Network
right before your resources
Multiple inbound and outbound security rules:
Allow or block traffic based on source/destination IP address, protocol and port
Restrict traffic between resources such as virtual machines and subnets
Attached with subnets and network interfaces
Usecases : Allow access to web server only on port 80 and port 443
(HTTP/HTTPS)
Restrict database access only to web servers. Do NOT allow direct access to
database from outside world/other servers.
Restrict outbound traffic from VMs to download so ware packages and system
updates
Network Security Groups (NSG)
Network Security Groups (NSG)
99
"A chain is only as strong as its weakest link" - Secure at all levels:
Physical security: Control access to physical infrastructure (Responsibility of
Microso )
Perimeter: Azure DDoS Protection + Azure Firewall
Network: Restrict internet access (inbound and outbound)
Restrict communication between resources
Compute:Secure access to virtual machines
Implement endpoint protection
Ensure that OS and so ware patches are applied
Application: Think of security from day one!
Implement security best practices depending on language and framework
Store secrets in Azure Key Vault
Data: Encrypt data at rest and in transit
Best Practice: Implement security at all levels!
Security Best Practice - Defense in depth
Security Best Practice - Defense in depth
100
Cloud Computing
Public Cloud
You host everything in the cloud (You DO NOT need a data center anymore)
No Capital Expenditure required
Hardware resources are owned by Azure (Microso )
Hardware failures and security of the data center are managed by Azure (Microso )
Summary: Hardware owned by Azure and shared between multiple tenants
Tenants: Customers who rent infrastructure (You, Me and other enterprises)
Private Cloud
You host everything in your own data center
Needs Capital Expenditure
Incur staffing and maintenance expenses for infrastructure
Delivers higher level of security and privacy
Hybrid Cloud :
Combination of both (Public & Private)
Use Public Cloud for some workloads and Private cloud for others
Example: Connecting an on-premise app to Azure Cosmos DB
Provides you with flexibility: Go on-premises or cloud based on specific requirement
Cloud Computing: Public vs Private vs Hybrid clouds
Cloud Computing: Public vs Private vs Hybrid clouds
101
Options: VPN and Azure ExpressRoute
VPN: Encrypted connection from on-
premises to Azure over internet
Needs VPN device or gateway on-premises
Need Azure VPN gateway in the Azure Virtual
Network
Encrypted communication over Internet (public)
Azure ExpressRoute: Private connectivity to
Azure Virtual Network
Provides very high bandwidth
Very high security (private connection)
Traffic does NOT go over internet
Traffic is NOT encrypted by the connection
Hybrid Cloud: Connecting Azure with on-premises
Hybrid Cloud: Connecting Azure with on-premises
102
Organizing and Managing
Organizing and Managing
Azure Resources
Azure Resources
103
( )
Hierarchy: Management Group(s) > Subscription (s) >
Resource Group (s) > Resources
Resources: VMs, Storage, Databases
Resource groups: Organize resources by grouping them into
Resource groups
Subscriptions: Manage costs for resources provisioned for
different teams or different projects or different business units
Management groups: Centralized management for access,
policy, and compliance across multiple subscriptions
Remember:
No hierarchy in resource groups BUT management groups can
have a hierarchy
Azure Resource Hierarchy
Azure Resource Hierarchy
https://docs.microso .com/
104
Resource Group: Logical container for resources
Associated with a single subscription
Can have multiple resources
(REMEMBER) A resource can be associated with one and only one resource group
Can have resources from multiple regions
Deleting it deletes all resources under it
Tags assigned to resource group are not automatically applied
to resources
HOWEVER, Permissions/Roles assigned to user at the resource group level
are inherited by all resources in the group
Resource Groups (like Management Groups) are free
Resource Groups
Resource Groups
105
You need a Subscription to create resources in Azure
Subscription links Azure Account to its resources
An Azure Account can have multiple subscriptions and multiple
account administrators
When do you create a new subscription?
I want to manage different access-management policies for different environments:
Create different subscriptions for different environments
Manage distinct Azure subscription policies for each environment
I want to manage costs across different departments of an organization:
Create different subscriptions for different departments
Create separate billing reports and invoices for each subscription (or department) and manage costs
I'm exceeding the limits available per subscription
Example: VMs per subscription - 25,000 per region
Subscriptions
Subscriptions
106

More Related Content

Similar to AZ900-AzureFundamentals-part-11.pdf

Power of the cloud - Introduction to azure security
Power of the cloud - Introduction to azure securityPower of the cloud - Introduction to azure security
Power of the cloud - Introduction to azure securityBruno Capuano
 
SC-900 Capabilities of Microsoft Security Solutions
SC-900 Capabilities of Microsoft Security SolutionsSC-900 Capabilities of Microsoft Security Solutions
SC-900 Capabilities of Microsoft Security SolutionsFredBrandonAuthorMCP
 
Azure governance v4.0
Azure governance v4.0Azure governance v4.0
Azure governance v4.0Marcos Oikawa
 
Cloudmod4
Cloudmod4Cloudmod4
Cloudmod4kongara
 
Presentation on Openstack in null Bhopal Chapter
Presentation on Openstack in null Bhopal ChapterPresentation on Openstack in null Bhopal Chapter
Presentation on Openstack in null Bhopal ChapterHemraj Singh Chouhan
 
AZ-900 Azure Fundamentals.pdf
AZ-900 Azure Fundamentals.pdfAZ-900 Azure Fundamentals.pdf
AZ-900 Azure Fundamentals.pdfssuser5813861
 
Azure Fundamentals Part 3
Azure Fundamentals Part 3Azure Fundamentals Part 3
Azure Fundamentals Part 3CCG
 
Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!
Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!
Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!Caroline Johnson
 
Cloud Security_Module2.ppt
Cloud Security_Module2.pptCloud Security_Module2.ppt
Cloud Security_Module2.pptArunKumbi1
 
Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...
Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...
Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...Ts. Mohd Shahrul Zharif Bin Sharudin
 
DDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS ShieldDDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS ShieldAmazon Web Services
 
Cloud Computing - Security Benefits and Risks
Cloud Computing - Security Benefits and RisksCloud Computing - Security Benefits and Risks
Cloud Computing - Security Benefits and RisksWilliam McBorrough
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security OverviewAlert Logic
 
366864108 azure-security
366864108 azure-security366864108 azure-security
366864108 azure-securityober64
 
Literature Review: Security on cloud computing
Literature Review: Security on cloud computingLiterature Review: Security on cloud computing
Literature Review: Security on cloud computingSuranga Nisiwasala
 
Cloud Security: A Comprehensive Guide
Cloud Security: A Comprehensive GuideCloud Security: A Comprehensive Guide
Cloud Security: A Comprehensive GuideHTS Hosting
 

Similar to AZ900-AzureFundamentals-part-11.pdf (20)

Power of the cloud - Introduction to azure security
Power of the cloud - Introduction to azure securityPower of the cloud - Introduction to azure security
Power of the cloud - Introduction to azure security
 
SC-900 Capabilities of Microsoft Security Solutions
SC-900 Capabilities of Microsoft Security SolutionsSC-900 Capabilities of Microsoft Security Solutions
SC-900 Capabilities of Microsoft Security Solutions
 
Azure governance v4.0
Azure governance v4.0Azure governance v4.0
Azure governance v4.0
 
Cloudmod4
Cloudmod4Cloudmod4
Cloudmod4
 
Presentation on Openstack in null Bhopal Chapter
Presentation on Openstack in null Bhopal ChapterPresentation on Openstack in null Bhopal Chapter
Presentation on Openstack in null Bhopal Chapter
 
AZ-900 Azure Fundamentals.pdf
AZ-900 Azure Fundamentals.pdfAZ-900 Azure Fundamentals.pdf
AZ-900 Azure Fundamentals.pdf
 
Azure Fundamentals Part 3
Azure Fundamentals Part 3Azure Fundamentals Part 3
Azure Fundamentals Part 3
 
Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!
Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!
Explaining The Differences Between Single-Tenant and Multi-Tenant Clouds!
 
Cloud Security_Module2.ppt
Cloud Security_Module2.pptCloud Security_Module2.ppt
Cloud Security_Module2.ppt
 
Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...
Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...
Harvard Extension School: Cloud Security Final Project - HIPAA Compliance Aud...
 
Unit-II-part 3.pdf
Unit-II-part 3.pdfUnit-II-part 3.pdf
Unit-II-part 3.pdf
 
DDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS ShieldDDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS Shield
 
Cloud Computing - Security Benefits and Risks
Cloud Computing - Security Benefits and RisksCloud Computing - Security Benefits and Risks
Cloud Computing - Security Benefits and Risks
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security Overview
 
Quiz 1 cloud computing
Quiz 1 cloud computing Quiz 1 cloud computing
Quiz 1 cloud computing
 
CLOUD COMPUTING.pptx
CLOUD COMPUTING.pptxCLOUD COMPUTING.pptx
CLOUD COMPUTING.pptx
 
Azure for AWS Developers
Azure for AWS DevelopersAzure for AWS Developers
Azure for AWS Developers
 
366864108 azure-security
366864108 azure-security366864108 azure-security
366864108 azure-security
 
Literature Review: Security on cloud computing
Literature Review: Security on cloud computingLiterature Review: Security on cloud computing
Literature Review: Security on cloud computing
 
Cloud Security: A Comprehensive Guide
Cloud Security: A Comprehensive GuideCloud Security: A Comprehensive Guide
Cloud Security: A Comprehensive Guide
 

More from ssuser2dbaee

AZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdfAZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdfAZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdfAZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdfAZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdfAZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdfAZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdfAZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdfAZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdfAZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdfssuser2dbaee
 
NetApp CIFS Audit.docx
NetApp CIFS Audit.docxNetApp CIFS Audit.docx
NetApp CIFS Audit.docxssuser2dbaee
 
Netapp_Aggregates.docx
Netapp_Aggregates.docxNetapp_Aggregates.docx
Netapp_Aggregates.docxssuser2dbaee
 

More from ssuser2dbaee (11)

AZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdfAZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdf
 
AZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdfAZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdf
 
AZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdfAZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdf
 
AZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdfAZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdf
 
AZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdfAZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdf
 
AZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdfAZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdf
 
AZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdfAZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdf
 
AZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdfAZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdf
 
AZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdfAZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdf
 
NetApp CIFS Audit.docx
NetApp CIFS Audit.docxNetApp CIFS Audit.docx
NetApp CIFS Audit.docx
 
Netapp_Aggregates.docx
Netapp_Aggregates.docxNetapp_Aggregates.docx
Netapp_Aggregates.docx
 

Recently uploaded

"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 

Recently uploaded (20)

"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 

AZ900-AzureFundamentals-part-11.pdf

  • 1. (DDoS) attack: Large scale attacks to bring your apps down Result: App goes down or become slow. Huge bill because of unlimited auto scaling. Two Azure DDoS offerings: DDoS Protection Basic: Protects against common network layer attacks Intelligently identifies and blocks DDoS attacks Enabled by default No extra cost DDoS Protection Standard: Mitigates 60 different DDoS attack types Provides attack analytics, metrics, alerting and reporting Get quick support from DDoS Protection Rapid Response (DRR) team Get a Cost guarantee ( Receive service credit if DDoS attack results in scale-out) Enable it on the Azure virtual network DDoS Protection Standard + Web Application Firewall = Powerful combination that protects at: Network layer (Layer 3 and 4, Azure DDoS Protection Standard) Application layer (Layer 7, WAF) Azure DDoS Azure DDoS 97
  • 2. Managed network security service to control traffic in and out of a Azure Virtual Network Stateful: Once traffic in is allowed, traffic out is automatically allowed Centralized Configuration: With one Azure firewall, you can control traffic to multiple virtual networks (having hundreds of resources) across multiple subscriptions Example : If your enterprise has 10 virtual networks (across multiple subscriptions) with 100 VMs, you can control traffic with one Azure Firewall Integrates with Azure Monitor: Provides logging and analytics (REMEMBER) Web application firewall (WAF) Restrict traffic into web applications OWASP etc Supported by Azure Application Gateway, Azure Content Delivery Network Azure Firewall Azure Firewall 98
  • 3. Azure Firewall is an external firewall - outside your Virtual Network Network Security Group (NSG) is like a internal firewall inside your Virtual Network right before your resources Multiple inbound and outbound security rules: Allow or block traffic based on source/destination IP address, protocol and port Restrict traffic between resources such as virtual machines and subnets Attached with subnets and network interfaces Usecases : Allow access to web server only on port 80 and port 443 (HTTP/HTTPS) Restrict database access only to web servers. Do NOT allow direct access to database from outside world/other servers. Restrict outbound traffic from VMs to download so ware packages and system updates Network Security Groups (NSG) Network Security Groups (NSG) 99
  • 4. "A chain is only as strong as its weakest link" - Secure at all levels: Physical security: Control access to physical infrastructure (Responsibility of Microso ) Perimeter: Azure DDoS Protection + Azure Firewall Network: Restrict internet access (inbound and outbound) Restrict communication between resources Compute:Secure access to virtual machines Implement endpoint protection Ensure that OS and so ware patches are applied Application: Think of security from day one! Implement security best practices depending on language and framework Store secrets in Azure Key Vault Data: Encrypt data at rest and in transit Best Practice: Implement security at all levels! Security Best Practice - Defense in depth Security Best Practice - Defense in depth 100
  • 5. Cloud Computing Public Cloud You host everything in the cloud (You DO NOT need a data center anymore) No Capital Expenditure required Hardware resources are owned by Azure (Microso ) Hardware failures and security of the data center are managed by Azure (Microso ) Summary: Hardware owned by Azure and shared between multiple tenants Tenants: Customers who rent infrastructure (You, Me and other enterprises) Private Cloud You host everything in your own data center Needs Capital Expenditure Incur staffing and maintenance expenses for infrastructure Delivers higher level of security and privacy Hybrid Cloud : Combination of both (Public & Private) Use Public Cloud for some workloads and Private cloud for others Example: Connecting an on-premise app to Azure Cosmos DB Provides you with flexibility: Go on-premises or cloud based on specific requirement Cloud Computing: Public vs Private vs Hybrid clouds Cloud Computing: Public vs Private vs Hybrid clouds 101
  • 6. Options: VPN and Azure ExpressRoute VPN: Encrypted connection from on- premises to Azure over internet Needs VPN device or gateway on-premises Need Azure VPN gateway in the Azure Virtual Network Encrypted communication over Internet (public) Azure ExpressRoute: Private connectivity to Azure Virtual Network Provides very high bandwidth Very high security (private connection) Traffic does NOT go over internet Traffic is NOT encrypted by the connection Hybrid Cloud: Connecting Azure with on-premises Hybrid Cloud: Connecting Azure with on-premises 102
  • 7. Organizing and Managing Organizing and Managing Azure Resources Azure Resources 103
  • 8. ( ) Hierarchy: Management Group(s) > Subscription (s) > Resource Group (s) > Resources Resources: VMs, Storage, Databases Resource groups: Organize resources by grouping them into Resource groups Subscriptions: Manage costs for resources provisioned for different teams or different projects or different business units Management groups: Centralized management for access, policy, and compliance across multiple subscriptions Remember: No hierarchy in resource groups BUT management groups can have a hierarchy Azure Resource Hierarchy Azure Resource Hierarchy https://docs.microso .com/ 104
  • 9. Resource Group: Logical container for resources Associated with a single subscription Can have multiple resources (REMEMBER) A resource can be associated with one and only one resource group Can have resources from multiple regions Deleting it deletes all resources under it Tags assigned to resource group are not automatically applied to resources HOWEVER, Permissions/Roles assigned to user at the resource group level are inherited by all resources in the group Resource Groups (like Management Groups) are free Resource Groups Resource Groups 105
  • 10. You need a Subscription to create resources in Azure Subscription links Azure Account to its resources An Azure Account can have multiple subscriptions and multiple account administrators When do you create a new subscription? I want to manage different access-management policies for different environments: Create different subscriptions for different environments Manage distinct Azure subscription policies for each environment I want to manage costs across different departments of an organization: Create different subscriptions for different departments Create separate billing reports and invoices for each subscription (or department) and manage costs I'm exceeding the limits available per subscription Example: VMs per subscription - 25,000 per region Subscriptions Subscriptions 106