Free

Secure a Storage Account

This IT Pro Challenge lab shows learners fundamental web application concepts and Microsoft Azure Resource group services. Learners will use the Microsoft Azure Portal and an existing Azure Resource Group to create an action group, add an email alert action and a webhook action for the action group, and create an alert rule.

0
45
M
Time
Beginner
difficulty
1
ceu/cpe

Course Content

No items found.
No items found.
Course Description

This 45-minute virtual IT Pro Challenges lab will teach three best practices to secure a Microsoft Azure storage account. If you run the lab on an Apple machine, you will need to have Microsoft Remote Desktop ready for the 3rd lab section. You will learn the following:

  • Requiring access only through HTTPS.
  • Generating a shared access signature (SAS), granting full access to queues and tables in a Web App.
  • Setting firewall rules, limiting network access to an Azure virtual network.

Learners will gain hands-on experience in safeguarding a storage container’s contents while allowing customers with access permission to obtain and work with their data.

Should you know how to navigate through a Microsoft Azure Resource group that includes a storage account and a Web app, then you will be primed to take this virtual lab. Understanding some of the concepts around HTTPS and network security will reinforce your hands-on experiences in the lab. You will need to set aside a full 45-minutes as you cannot stop the lab in the middle and return to it. You can, however, attempt the lab more than once if needed. When you start the lab, you will see a preconfigured Azure Resource group. You will launch a virtual machine to complete the third exercise and have Microsoft Remote Desktop installed on an Apple.

System Administrators, Network Operations Specialists, and Cyber Security Engineers must know how to safeguard storage on the cloud to comply with regulations and to protect privacy. Microsoft Azure provides multi-level security solutions for blob storage: data protection, identity, and access management, and networking. HTTPS secures data while generating a shared SAS safeguards access. Firewalls reinforce network security. This lab advances knowledge of all three aspects to manage access to an Azure storage account.

Understanding the Scenario:

You are a system administrator for a company that provides web hosting services for customers. You need to secure a Storage Account that may hold sensitive data. You start by requiring a secure transfer for the Storage Account. You then generate a secure access signature (SAS) and configure a Web App to use the SAS. Finally, you limit access to the Storage Account to an Azure virtual network.

Require Secure Connections:

In this section, you log into the lab environment and set the preconfigured blob image to require a secure connection through HTTPS. HTTPS protocols are compatible with a REST API, that secures all access to Azure Storage Accounts. This RESTful API allows Azure to make requests for or receive data from any other machine. Using a ‘GET’ request to the storage account retrieves an image, and tests whether a secure connection is required. To get a valid result, you may need to refresh the browser; you can see the page with the new code instead of a cached version of the old code.

Generate a Shared Access Signature:

A SAS provides admittance to data resources in a storage account by another user, service, or account. In this exercise, you create a SAS connection string that links a preconfigured Web app to the storage account. You test this set up by navigating to the Web App page and generating and obtaining messages from the storage account.

Set Firewall Rules:

You set firewall rules allowing access to the storage account from a particular subnet, an Azure virtual network. You leave the Azure machine outside of this subnet. In checking your work, you validate an access denied message occurs when attempting to view the image blob on the Azure machine. Then you open the storage image in a VM passing trusted username and password credentials through the firewall. From the VM, you can see the blob image in the storage account.

Summary:

Successful completion of the lab will give you tools to secure storage data, access, and network connectivity. In this lab, you will master:

  • Configuring secure connections.
  • Generating a shared access signature (SAS).
  • Limiting access to a Storage Account through firewall rules.

You will have learned the skills to use the tools to give customers confidence about the security of their contents stored in the Azure cloud.

This course is part of a Career Path:
No items found.

Instructed by

No items found.
Provider
Cybrary Logo
Certification Body
Certificate of Completion

Complete this entire course to earn a Secure a Storage Account Certificate of Completion

Coming mid-July
Cybrary Reimagined.
Level up with structured, role-aligned career paths.
ALL NEW!
Cybrary Reimagined.
Celebrate Cybersecurity Awareness Month with our buy 2, get 1 offer!
Level up with structured, role-aligned career paths.
Valid until October 31. Elevate your skills today!
Start Now

Heading

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This is some text inside of a div block.
Share

Purpose Statement

Cybrary Career Paths are comprehensive training programs designed to prepare you for the most in-demand roles in the cybersecurity workforce. Each path follows a Learn, Practice, Prove model and includes different activity types aligned to key topics within the path’s security domain. As you progress through the path, your progress will be measured in real time using Experience Points (XP) that serve as a comprehensive capability score for each topic. Upon completing all of the requirements for a path, you will be rewarded with a shareable digital badge via Credly.
This is some text inside of a div block.
This is some text inside of a div block.
M
Time
This is some text inside of a div block.
difficulty
This is some text inside of a div block.
ceu/cpe

Overview

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Frequently Asked Questions
No items found.
What Will I Learn?
Foundations
Focused on the core IT competencies that cybersecurity professionals need to succeed in any career path.
Defensive Security
Focused on trying to find the bad guys. Topics such as threat intelligence, threat hunting, network monitoring, incident response. Defensive security is a reactive measure taken once a vulnerability is found through prevention, detection, and response.
Engineering and Operations
Focused on building and operating information systems.
Governance, Risk, and Compliance
Focused on the core IT competencies that cybersecurity professionals need to succeed in any career path.
Leadership and Management
Focused on program design and oversight. Covers project and program management.
Offensive Security
Focused on validating security controls by trying to break them (i.e. penetration testing or ethical hacking). Topics such as Kali Linux, metasploit, scanning, and privilege escalation. Offensive security seeks out the problem or vulnerability through ethical hacking and finds a solution to disable the operation.
Offensive Security
Focused on the core IT competencies that cybersecurity professionals need to succeed in any career path.
Path Outline

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Course Outline

No items found.
No items found.
No items found.

What Our Learners Are Saying

Join 3 million+ users, including 96% of Fortune 1000 companies who use our platform to upskill their teams. See what the buzz is about - start learning for free!

No items found.