
Sign up to save your podcasts
Or

Course 29 - AZ-500 Microsoft Azure Security Technologies | Episode 14: Securing Data and Applications in Microsoft Azure

Overview- Focus: Protecting cloud data and applications using Azure-native tools.
- Balance of theory (security principles, SDLC) and hands-on labs for exam readiness.
1. Database and Storage SecurityAzure Cosmos DB- Defense-in-Depth:
- Network: Firewalls, Virtual Networks
- Encryption: At rest & in transit
- Authorization:
- Master Keys (full access, high risk)
- Resource Tokens (time-bound, limited access for untrusted clients)
Azure Data Lake (Gen 2)- Hierarchical Namespace: Supports structured, fine-grained access
- POSIX-style ACLs: Manage permissions on files & directories
- Azure AD Authentication: Ensures secure query execution for services like Data Lake Analytics
2. Application Security and LifecycleSecure SDLC Practices- Threat modeling during design phase
- Static and dynamic code analysis for vulnerabilities (e.g., SQL injection)
- Security champions embedded in agile teams
Azure App Service Security- Authentication & Access Control: OAuth 2.0, RBAC
- Secrets Management: Azure Key Vault integration
- Infrastructure Protection:
- Web Application Firewall (WAF)
- Azure DDoS Protection (Basic & Standard tiers) for layer 7 and volumetric attacks
3. Practical Implementation & Exam Prep- Cosmos DB Labs: SQL queries, diagnostic logging, SAS token management
- App Service Labs: Custom domain setup, SSL/TLS binding
- Exam-Style Scenarios:
- Revoking compromised SAS tokens
- Assigning database roles to Azure AD users
- Ensuring proper access segregation and secure network configuration
Key Takeaways- Apply defense-in-depth at database, storage, and application layers
- Prefer resource-limited access over full-access keys for security
- Integrate SDLC security practices and Azure-native protection services
- Practice hands-on labs to reinforce exam-relevant configurations
You can listen and download our episodes for free on more than 10 different platforms:https://linktr.ee/cybercode_academy ...more
View all episodes
By CyberCode Academy
Course 29 - AZ-500 Microsoft Azure Security Technologies | Episode 14: Securing Data and Applications in Microsoft Azure

Overview- Focus: Protecting cloud data and applications using Azure-native tools.
- Balance of theory (security principles, SDLC) and hands-on labs for exam readiness.
1. Database and Storage SecurityAzure Cosmos DB- Defense-in-Depth:
- Network: Firewalls, Virtual Networks
- Encryption: At rest & in transit
- Authorization:
- Master Keys (full access, high risk)
- Resource Tokens (time-bound, limited access for untrusted clients)
Azure Data Lake (Gen 2)- Hierarchical Namespace: Supports structured, fine-grained access
- POSIX-style ACLs: Manage permissions on files & directories
- Azure AD Authentication: Ensures secure query execution for services like Data Lake Analytics
2. Application Security and LifecycleSecure SDLC Practices- Threat modeling during design phase
- Static and dynamic code analysis for vulnerabilities (e.g., SQL injection)
- Security champions embedded in agile teams
Azure App Service Security- Authentication & Access Control: OAuth 2.0, RBAC
- Secrets Management: Azure Key Vault integration
- Infrastructure Protection:
- Web Application Firewall (WAF)
- Azure DDoS Protection (Basic & Standard tiers) for layer 7 and volumetric attacks
3. Practical Implementation & Exam Prep- Cosmos DB Labs: SQL queries, diagnostic logging, SAS token management
- App Service Labs: Custom domain setup, SSL/TLS binding
- Exam-Style Scenarios:
- Revoking compromised SAS tokens
- Assigning database roles to Azure AD users
- Ensuring proper access segregation and secure network configuration
Key Takeaways- Apply defense-in-depth at database, storage, and application layers
- Prefer resource-limited access over full-access keys for security
- Integrate SDLC security practices and Azure-native protection services
- Practice hands-on labs to reinforce exam-relevant configurations
You can listen and download our episodes for free on more than 10 different platforms:https://linktr.ee/cybercode_academy ...more