nerdexam
Microsoft

SC-100 · Question #132

For a Microsoft cloud environment, you are designing a security architecture based on the Microsoft Cloud Security Benchmark. What are three best practices for identity management based on the Azure…

The correct answer is A. Manage application identities securely and automatically. C. Protect identity and authentication systems. E. Use a centralized identity and authentication system. The Microsoft Cloud Security Benchmark defines specific Identity Management (IM) controls. The three that map directly to Azure Security Benchmark best practices are: IM-3 - Manage application identities securely and automatically (A), which covers managed identities and…

Design security operations, identity, and compliance capabilities

Question

For a Microsoft cloud environment, you are designing a security architecture based on the Microsoft Cloud Security Benchmark. What are three best practices for identity management based on the Azure Security Benchmark? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • AManage application identities securely and automatically.
  • BManage the lifecycle of identities and entitlements.
  • CProtect identity and authentication systems.
  • DEnable threat detection for identity and access management.
  • EUse a centralized identity and authentication system.

How the community answered

(27 responses)
  • A
    89% (24)
  • B
    4% (1)
  • D
    7% (2)

Explanation

The Microsoft Cloud Security Benchmark defines specific Identity Management (IM) controls. The three that map directly to Azure Security Benchmark best practices are: IM-3 - Manage application identities securely and automatically (A), which covers managed identities and service principals; IM-2 - Protect identity and authentication systems (C), which addresses securing Azure AD itself against compromise; and IM-1 - Use a centralized identity and authentication system (E), which means leveraging Azure AD as the single identity plane across all resources. Option B (lifecycle/entitlements) is more aligned with Privileged Access Management controls, and Option D (threat detection for IAM) is categorized under logging and threat detection controls, not core identity management best practices.

Topics

#Identity Management#Azure Security Benchmark#Security Best Practices#Security Architecture Design

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice