- 9 more key points in Pro version
- 4 more common mistakes in Pro version
- 4 more exam tips in Pro version
- 42 more related questions in Pro version
Summary
This objective covers designing security solutions that align with the Cloud Adoption Framework (CAF), Azure landing zones, and DevSecOps practices. It emphasizes a holistic approach, considering people, process, and technology to address business risks and cloud adoption plans, while recognizing distinct responsibilities between platform and workload teams. Design a resiliency strategy for ransomware and other attacks by prioritizing business-critical assets and implementing controls to limit an attacker's movement and impact. Aligning solutions with MCRA and Zero Trust priorities requires a holistic approach that considers all assets – identities, endpoints, applications, infrastructure, networks, data, and operations – as a single system. Align solutions with the Microsoft Cloud Security Benchmark by mapping controls to organizational risks and compliance obligations. The MCSB provides prescriptive recommendations and controls for Azure and multicloud environments; however, their effective implementation requires governance, validation, and should not be adopted as an unexamined checklist. MCSB spans control domains such as network, identity, privileged access, data protection, asset management, logging, incident response, posture, and endpoint security. AI workload design should apply relevant identity, network, data protection, logging, and governance controls. A benchmark recommendation can guide a target control but does not by itself prove that the control is implemented effectively. Security recommendations must be prioritized by exposure and business criticality. Compensating controls require documented risk reasoning and validation. Design secure backup and restore solutions by implementing controls that protect recovery data and processes from compromise and ensure successful application restoration.
Key Points
- CAF provides a framework for aligning security with business goals and cloud adoption plans.
Common Mistakes
- Platform controls, established at the landing zone level, provide consistent enterprise guardrails, while workload teams retain responsibility for workload-specific security.
Exam Tips
- Focus on the interconnectedness of CAF, landing zones, and DevSecOps. Understand the distinct roles of platform and workload teams.