Permissions | Networking | Security | Subscriptions | General |
---|---|---|---|---|
No, only security groups
Can individual user accounts modify prod or non-prod subscription?
|
Express Route circuits
The name of the circuits between Azure and On-Prem?
|
Through central Event Hubs
How are diagnostic logs for CosmosDB sent to Splunk?
|
End of each month
How often are resources in Sandbox subscriptions deleted?
|
costcenter
What is the one required tag on all resource groups?
|
No
Can I create a public IP in a connected subscription?
|
PAN, Palo Alto Networks
The name of the firewall between Azure and On-Prem
|
NSGs, network security groups
What is the name of the firewall used at the subnet level in Azure Vnets?
|
SaveSB : True
What tag will prevent Sandbox resources from being deleted?
|
IPAM
What is the name of the front-end API for Infoblox?
|
Add-Role Assignment runbook
How do I change permissions on a connected subscription?
|
/23
The largest address space that can be provisioned in a connected subscription
|
Firewall/ Whitelisting/ Service Endpoint
How do you restrict traffic to a PaaS instance, such as Key Vault?
|
No
Can you connect to the Starbucks Network from a disconnected subscription?
|
Add-EventHub Access runbook
How do I grant central event hub access to my SPN?
|
Sbux Contributor
What is the custom role with modify access on connected subscriptions?
|
Service Endpoints
These endpoints limit traffic to certain PaaS instances from only connected virtual networks/subnets
|
SPNs, service principals
Key Vault access should be limited to these kind of accounts
|
Self-Managed
What is another name for a disconnected subscription?
|
No
Is it ok to keep keys and secrets in my code on our Enterprise Github?
|
No, they need to be granted specific access policies in the vault
Can a user granted Read access to a Key Vault resource through IAM view keys and secrets in that vault?
|
What is
What is a UDR?
|
VirtualNetwork
What NSG tag should be used for communication with Starbucks Networks?
|
Only if the NSGs are configured properly
Can all subnets in connected subscriptions communicate with each other?
|
In a secure location, like Key Vault, or CyberArk
Where should keys/ secrets be kept?
|