Questions
As you work through this book, it’s useful to reflect on what you’ve learned and challenge yourself with questions. Here’s some on what we covered in this chapter:
- Which of the following Azure AD groups isn’t provisioned as part of an MDI deployment?
- Azure ATP <tenant name> Administrators
- Azure ATP <tenant name> Viewers
- Azure ATP <tenant name> Responders
- Azure ATP <tenant name> Viewers
- True or false: this book encouraged the use of PIM for Groups to manage MDI administrative access, but this is restricted to the Azure AD Premium P2 license.
- True
- False
- Why are exclusions by detection rule preferred to global excluded entities, where possible?
- Exclusions by detection rule reduce blind spots in detections, compared to global excluded entities.
- Global exclusions do not support domains.
- Global exclusions are more difficult to set up.
- Which of these isn’t a type of activity you’d find in an MDI security...