Instiq

1Manage identity, access, and governance

Practice questions →Glossary →
  • 1.1Securing access with Microsoft Entra ID

    Learn the identity foundations of SC-500: Privileged Identity Management (PIM), conditional access, multifactor authentication (MFA) and passwordless, application identities (enterprise apps / app registrations) and OAuth consent management, and managed identities for Azure resources—implemented through least privilege and Zero Trust.

  • 1.2Protecting secrets and keys with Azure Key Vault

    Learn Azure Key Vault for safely storing secrets, keys, and certificates: deployment, the access models (RBAC vs access policies), network restriction (firewall / private endpoint), managing keys/secrets/certificates, and threat detection via Defender CSPM secret scanning and Defender for Key Vault.

  • 1.3Enforcing security and compliance through governance

    Learn to enforce controls with Azure Policy (built-in/custom definitions), evaluate regulatory compliance and configure security standards/recommendations with Microsoft Defender for Cloud, apply resource locks, manage built-in/custom roles and remediate over-privileged access (RBAC), use Azure Backup security features, and implement security controls via infrastructure as code.