Lesson 11 · Domain 2: Azure Architecture & Services (35–40% of exam) · Review

Security Models: Retrieval Practice

Lesson 10's quiz caught three specific gaps: the defense-in-depth layer order, which Defender for Cloud pillar owns the secure score, and spotting Zero Trust in a scenario rather than just reciting its definition. No new material here — this lesson locks in those three with fresh scenarios, not the same wording twice.

Continues from: Lesson 10: Security Models, same primary source (Microsoft Learn — Describe Azure identity, access, and security, units 7–9).

The three things to lock in

Defense-in-depth, as a castle

Picture concentric rings around a keep, outermost to innermost: Physical (the walls) → Identity & access (guards at the gate) → Perimeter (the moat — stops a mass assault, like DDoS, before it reaches you) → Network (roads and checkpoints inside the walls — controls movement between things already let in) → Compute (the buildings) → Application (what happens inside them) → Data (the vault, always innermost).

The perimeter/network mix-up: perimeter keeps external attacks out at the edge; network controls traffic between your own resources once they're already inside.

Defender for Cloud, as a timeline

Continuously assess ("what's wrong right now?" — raw vulnerability findings) → Secure ("how do I improve, and how do I know if I'm improving?" — turns findings into recommendations and rolls them into the secure score) → Defend ("am I being attacked right now?" — real-time alerts and threat protection).

The secure score belongs to Secure, not Assess — scoring is the trackable-improvement step that happens after raw findings come in.

Spotting Zero Trust in a scenario

The tell is any phrase that removes network location as the deciding factor: "regardless of where the request comes from," "even on an unmanaged device," "evaluated on its own risk every time." If a scenario is about layered structure instead (walls, rings, "if one thing fails the next catches it"), that's defense-in-depth, not Zero Trust.

Practice

Same three ideas, new scenarios — plus one question mixed in from Lesson 9 to keep you from over-applying "Zero Trust" to anything security-shaped.

If any of these still feel like a coin flip, say which number — that's more useful to me than "I got some wrong," since each question targets a different piece of the confusion.
← Lesson 10: Security Models Lesson 12: Checkpoint →