MIME-Version: 1.0 Content-Type: multipart/related; boundary="----=_NextPart_01DCDC62.5BE9D8B0" This document is a Single File Web Page, also known as a Web Archive file. If you are seeing this message, your browser or editor doesn't support Web Archive files. Please download a browser that supports Web Archive. ------=_NextPart_01DCDC62.5BE9D8B0 Content-Location: file:///C:/54C8A112/07-azure-security-engineer.htm Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset="windows-1252"

# Role Deep Dive: Azure Security Engineer

 

---

 

## Role Overview

 

Azure Security Engineers design, implement, and mainta= in the security posture of Azure environments. They protect data, identities, applications, and infrastructure from threats. They implement zero-trust architecture, manage identity security, configure network defenses, and respond to security incidents.

 

**Alternative Titles:** Clo= ud Security Engineer, Azure Security Architect, Cloud Security Analyst, Information Security Engineer

 

**Typical Salary Range:** $= 110,000 – $180,000 (US)

 

---

 

## Core Responsibilities

 

### 1. Identity & Access Security (25% of role)

- Implement and manage Microsoft Entra ID security fea= tures

- Design and enforce Conditional Access policies<= /o:p>

- Implement Privileged Identity Management (PIM)<= /o:p>

- Configure MFA for all users (pa= sswordless where possible)

- Manage application permissions and consent

- Implement identity protection and risk policies=

 

**Granular Tasks:**

- **Conditional Access Policies (Build in this order):**

  1. Block leg= acy authentication protocols (IMAP, POP, SMTP)

  2. Require M= FA for all users (with exclusions for break-glass accounts)

  3. Require M= FA for Azure management (all admin portals)

  4. Block acc= ess from untrusted countries

  5. Require c= ompliant device for corporate resources

  6. Require M= FA + compliant device for privileged roles

  7. Block sig= n-in for high-risk users (Identity Protection)

  8. Require M= FA for medium-risk sign-ins (Identity Protection)

  9. Require t= erms of use for guest access

  10. Session controls: limited access for unmanaged devices

 

- **PIM Configuration:**

  - All admin = roles: eligible (not permanent), require MFA on activation, require approval, max 8-hour activation

  - Owner/Cont= ributor on subscriptions: eligible, require approval + ticket number

  - Key Vault Contributor: eligible, 1-hour max

  - Break-glass accounts: permanent Global Admin (2 accounts, 30-char passwords, stored in physical safe)

  - Configure = access reviews: quarterly review of all PIM-eligible assignments

 

- **Identity Protection:**<= o:p>

  - User risk = policy: High risk → block sign-in, force password reset

  - Sign-in ri= sk policy: Medium risk → require MFA, High risk → block=

  - Risky user= s: investigate, dismiss false positives, confirm compromised → reset password + revoke sessions

  - Configure = risk detections: impossible travel, anonymous IP, malware-linked IP, unfamiliar sign-in properties

 

- **Application Security:**=

  - Review app registrations: minimize permissions (delegated > application)=

  - Admin cons= ent workflow: users can request, admins approve

  - Restrict third-party app consent (require admin approval for new apps)

  - Credential management: certificate-based > secret-based for service principals=

  - Rotate sec= rets every 90 days (automated via Key Vault)

 

### 2. Network Security (20% of role)

- Implement zero-trust network architecture=

- Configure Azure Firewall (Standard and Premium)=

- Implement WAF policies (App Gateway / Front Door)

- Configure NSGs with least-privilege rules=

- Implement Private Endpoints for all PaaS services

- Configure DDoS Protection

- Implement DNS security

 

**Granular Tasks:**

- **Zero-Trust Network Architectur= e:**

  - Verify exp= licitly: authenticate and authorize every request (MFA, Conditional Access, RBAC)

  - Use least privilege: minimal access, just-in-time, PIM

  - Assume bre= ach: microsegmentation, Private Endpoints, blast radius containment

  - All PaaS s= ervices: Private Endpoints (disable public access)

  - All manage= ment: Bastion (no public RDP/SSH), JIT VM access

  - All outbou= nd: Azure Firewall (inspect, filter, log)

  - All web tr= affic: WAF (Prevention mode)

  - Network segmentation: separate subnets per tier, NSGs deny-all default

 

- **Azure Firewall Premium:**

  - TLS inspec= tion: inspect encrypted traffic (deploy certificates, configure key vault)

  - IDPS: enab= le signature mode (alert + deny), tune rules (disable false positives)

  - Web catego= ries: block gambling, malware, phishing categories

  - URL filter= ing: allow specific URLs within FQDNs

  - DNS proxy:= enable, configure custom DNS servers, use FQDN in network rules

 

- **WAF Policy:**

  - OWASP 3.2 = rule set

  - Prevention= mode (not detection) for production

  - Custom rul= es: block specific IP ranges, geo-filter (allow only company countries)

  - Exclusions: exclude specific request fields from WAF inspection (e.g., large file uploa= ds)

  - Rate limit= ing: limit requests per IP (e.g., 1000/minute)

 

- **NSG Hardening:**

  - Default: d= eny all inbound, allow all outbound

  - Add only s= pecific allow rules with narrow source/dest/port

  - Use Servic= e Tags instead of IP ranges (Storage, Sql, AppService)

  - Use ASGs f= or workload grouping

  - No "A= llow Any" rules (no 0.0.0.0/0 inbound)

  - Review and= clean up unused rules monthly

 

### 3. Data Protection & Encryption (15% of role)<= o:p>

- Implement encryption at rest (AES-256, customer-mana= ged keys)

- Implement encryption in transit (TLS 1.2+, enforce H= TTPS)

- Implement encryption in use (Confidential Computing)=

- Configure Azure Key Vault (secrets, keys, certificat= es)

- Implement data classification and protection

- Configure database security (TDE, Always Encrypted, Dynamic Data Masking)

 

**Granular Tasks:**

- **Key Vault Security:**

  - RBAC autho= rization model (not access policies)

  - Private En= dpoint for all access

  - Firewall: = deny public access, allow specific VNets<= /p>

  - Soft delet= e: enabled (default), purge protection: enabled

  - Audit logg= ing: send to Log Analytics + Storage Account

  - Key rotati= on: auto-rotate on creation (set rotation policy)

  - Certificate auto-renewal: integrate with DigiCert/GlobalSign

  - HSM-backed= keys for cryptographic operations (Premium or Managed HSM)

 

- **Encryption at Rest:**

  - Platform-m= anaged keys (PMK): default, no management overhead

  - Customer-m= anaged keys (CMK): store in Key Vault, full control, rotation

  - Customer-m= anaged keys with auto-rotate: set rotation policy in Key Vault

  - When to us= e CMK: regulatory requirements, key custody requirements, multi-tenant isolation

 

- **SQL Database Security:*= *

  - TDE (Trans= parent Data Encryption): enabled by default (PMK). Use CMK for compliance.

  - Always Enc= rypted: encrypt columns client-side. DB never sees plaintext. Use with Key Vault.

  - Dynamic Da= ta Masking: mask SSN, credit card in results (e.g., XXX-XX-1234)

  - Row-Level Security: filter rows by user context

  - Auditing: = log all database events to Storage Account + Log Analytics

  - Microsoft = Defender for SQL: vulnerability assessment, threat detection

  - Firewall: = deny public access, allow only from VNets/Private Endpoints

 

- **Data Classification:**<= o:p>

  - Microsoft = Purview Information Protection: classify and label data

  - Sensitivity labels: Public, Internal, Confidential, Highly Confidential

  - Auto-classification: scan and label based on content (SSN, credit card patterns)

  - DLP (Data = Loss Prevention): prevent sharing of sensitive data

 

### 4. Threat Detection & Response (15% of role)

- Configure Microsoft Defender for Cloud

- Implement Microsoft Sentinel (SIEM + SOAR)

- Configure threat detection across all services<= /o:p>

- Create incident response playbooks

- Conduct threat hunting

 

**Granular Tasks:**

- **Defender for Cloud:**

  - Enable all Defender plans (Servers, App Service, SQL, Storage, Containers, Key Vault, = DNS, IoT, Databases)

  - Review Sec= ure Score weekly, remediate critical recommendations

  - Configure = email notifications for critical alerts

  - Enable JIT= VM access for all internet-facing VMs

  - Export ale= rts to Sentinel for centralized investigation

 

- **Sentinel Setup:**<= /o:p>

  - Data conne= ctors: Entra ID, Microsoft 365, Azure Activity, Security Alerts, DNS, Firewall

  - Third-party connectors: Palo Alto, Cisco, Fortinet, Okta

  - Analytics = rules:

    - Schedule= d: failed logins from same IP > 10 in 5 minutes

    - Fusion: multi-stage attack detection (correlate across signals)

    - ML-based: anomaly detection on user behavior

  - Playbooks = (Logic Apps):

    - Auto-blo= ck IP: alert → add IP to NSG deny rule / Firewall block list

    - Disable = user: alert → disable Entra ID account → revoke sessions

    - Isolate = VM: alert → add NSG rule blocking all inbound/outbound

    - Notify t= eam: alert → Teams message → ServiceNow ticket

  - Hunting qu= eries: proactively search for indicators of compromise

  - Watchlists= : VIP users, known malicious IPs, authorized admin machines

  - Workbooks: security operations dashboard

 

- **Incident Response Process:**

  1. Detect: a= lert from Defender/Sentinel/custom analytics

  2. Triage: a= ssess severity, scope, impact

  3. Contain: = isolate affected resources (NSG rules, disable accounts)

  4. Investiga= te: review logs, timeline, related alerts

  5. Remediate= : fix vulnerability, rotate credentials, patch systems

  6. Recover: = restore services, verify clean state

  7. Post-inci= dent: root cause analysis, update policies, update playbooks

 

### 5. Governance & Compliance (15% of role)<= /o:p>

- Implement Azure Policy for security enforcement=

- Configure compliance assessments (Defender for Cloud= )

- Implement regulatory compliance (ISO 27001, SOC 2, H= IPAA, PCI DSS, GDPR, NIST)

- Conduct security assessments and audits

- Manage security baselines

 

**Granular Tasks:**

- **Key Security Policies:*= *

  - Deny public endpoints on PaaS services (Storage, SQL, Key Vault)

  - Require en= cryption at rest (audit resources without encryption)

  - Require HT= TPS only on App Service

  - Deny resou= rce creation in non-approved regions

  - Require ta= gs (DataClassification, Owner)

  - Audit diag= nostic settings (ensure logging enabled)

  - Deny privi= leged containers in AKS

  - Require SQ= L TDE enabled

  - Audit NSG = rules allowing unrestricted inbound access

 

- **Compliance Dashboard:**=

  - Defender f= or Cloud → Regulatory Compliance

  - Map contro= ls to Azure Policy

  - Track comp= liance percentage per standard

  - Export com= pliance report for auditors

  - Assign rem= ediation tasks to resource owners

 

### 6. Application Security (10% of role)

- Secure App Service and AKS deployments

- Implement API security (APIM, OAuth2, rate limiting)=

- Review application architecture for security

- Implement secure development practices

 

**Granular Tasks:**

- App Service: HTTPS only, min TLS 1.2, disable FTP, d= isable remote debugging, managed identity, private endpoint

- AKS: private cluster, network policies (Calico/Ciliu= m), workload identity, pod security standards, secret store CSI driver, image scanning

- APIM: validate JWT, rate limit, CORS policy, IP filt= ering, client certificate auth

- Container security: scan images (Defender for Contai= ners), sign images, pin digests

 

---

 

## Azure Services Used Daily

 

| Category | Services |

|---|---|

| Identity | Entra ID, PIM, Identity Protection, Condi= tional Access, Managed Identity |

| Network | Azure Firewall, WAF, NSG, Private Link, Ba= stion, DDoS Protection, Front Door |

| Data Protection | Key Vault, Managed HSM, TDE, Always Encrypted, Dynamic Data Masking, Purview |

| Threat Detection | Defender for Cloud, Sentinel, Def= ender for Endpoint, Identity Protection |

| Governance | Azure Policy, Blueprints, Management Gr= oups, RBAC |

| Compliance | Microsoft Purview, Compliance Manager, Regulatory Compliance |

 

---

 

## Security Architecture Checklist

 

### Identity

- [ ] MFA enabled for all u= sers

- [ ] Conditional Access po= licies enforced

- [ ] PIM for all privilege= d roles

- [ ] = Passwordless authentication available

- [ ] Legacy authentication= blocked

- [ ] Break-glass accounts configured (2 accounts, stored securely)

- [ ] Guest access reviewed quarterly

- [ ] Access reviews for all privileged roles

 

### Network

- [ ] Private Endpoints for= all PaaS services

- [ ] Azure Firewall in hub= -spoke

- [ ] WAF on all web entry = points (Prevention mode)

- [ ] NSGs with least-privi= lege rules

- [ ] No public RDP/SSH (Ba= stion only)

- [ ] DDoS Protection for public-facing workloads

- [ ] Network segmentation (separate subnets per tier)

 

### Data

- [ ] Encryption at rest (C= MK for sensitive data)

- [ ] Encryption in transit= (TLS 1.2+)

- [ ] Key Vault for all secrets/keys/certificates

- [ ] Data classification implemented

- [ ] Database security (TD= E, masking, auditing, RLS)

- [ ] Immutable storage for= audit logs

 

### Monitoring

- [ ] Defender for Cloud en= abled on all resources

- [ ] Sentinel for SIEM + S= OAR

- [ ] Diagnostic settings o= n all resources

- [ ] Alert rules for criti= cal events

- [ ] Incident response pla= ybooks automated

 

### Governance

- [ ] Azure Policy enforcing security baseline

- [ ] Compliance dashboard = tracked

- [ ] Security baselines ap= plied to all resources

- [ ] Tagging strategy enfo= rced (DataClassification, Owner)

 

---

 

## Certification Path

 

| Certification | Level | Focus |

|---|---|---|

| **SC-900** | Foundational | Security fundamentals |<= o:p>

| **AZ-500** | Associate | **Core cert** — Azure Secur= ity Engineer |

| **SC-100** | Expert | Cybersecurity Architect |=

| **SC-200** | Associate | Security Operations Analyst (Sentinel focus) |

| **SC-300** | Associate | Identity & Access Administrator (Entra ID focus) |

 

### AZ-500 Exam Breakdown

| Domain | Weight |

|---|---|

| Manage identity and access | 20-25% |

| Secure networking | 20-25% |

| Secure compute, storage, and databases | 25-30% |

| Manage security operations | 25-30% |

 

---

 

## Interview Focus Areas

 

1. **How do you implement zero-trust in Azure?**

   → Ver= ify explicitly (MFA, Conditional Access, RBAC), use least privilege (PIM, JIT), assume breach (Private Endpoints, microsegmentation, WAF, blast radius containment).

 

2. **Walk me through your Conditional Access strategy.**

   → Blo= ck legacy auth → MFA for all → MFA for Azure management → geo-block → compliant device → risk-based policies. Report-only mode first, then enforce.

 

3. **How do you secure PaaS servic= es?**

   → Pri= vate Endpoints (no public access), Azure Firewall for outbound, WAF for web entr= y, Managed Identity for auth, CMK for encryption, diagnostic logging, Azure Po= licy to enforce.

 

4. **How do you detect and respond to threats?**

   → Def= ender for Cloud for detection, Sentinel for SIEM+SOAR, automated playbooks for response (block IP, disable user, isolate VM), incident response process (detect-triage-contain-investigate-remediate-recover).

 

5. **How do you manage secrets across the organization?**

   → Key= Vault per environment, RBAC authorization, Private Endpoints, audit logging, auto-rotation, Managed Identity for all service auth, no credentials in cod= e or config.

 

6. **How do you implement compliance (HIPAA/PCI/GDPR)?**

   → Azu= re Policy for compliance controls, Defender for Cloud regulatory dashboard, Private Endpoints, encryption, audit logging to immutable storage, data classification, DLP, access reviews.

 

7. **How do you secure AKS?**

   → Pri= vate cluster, network policies, workload identity, CSI driver for secrets, pod security standards, image scanning, RBAC with Entra ID, Azure Policy for AK= S, Defender for Containers.

 

8. **What is PIM and why is it cri= tical?**

   → Just-in-time privileged access. No permanent admin roles. Eligible assignme= nts require approval + MFA + time limit. Reduces attack surface from compromised admin accounts.

 

9. **How do you handle a security = incident?**

   → Det= ect (alert) → Triage (severity, scope) → Contain (isolate resources) → Investigate (logs, timeline) → Remediate (fix, rotate, patch) → Recover (restore, verify) → Post-incident (RCA, update polici= es).

 

10. **How do you implement encryption strategy?**

    → At= rest: AES-256, PMK default, CMK for sensitive data (Key Vault auto-rotate). In transit: TLS 1.2+ enforced. In use: Confidential Computing (SGX/TEE) for sensitive workloads. Keys in Key Vault/Managed HSM.

------=_NextPart_01DCDC62.5BE9D8B0 Content-Location: file:///C:/54C8A112/07-azure-security-engineer_files/themedata.thmx Content-Transfer-Encoding: base64 Content-Type: application/vnd.ms-officetheme UEsDBBQABgAIAAAAIQDp3g+//wAAABwCAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbKyRy07DMBBF 90j8g+UtSpyyQAgl6YLHjseifMDImSQWydiyp1X790zSVEKoIBZsLNkz954743K9Hwe1w5icp0qv 8kIrJOsbR12l3zdP2a1WiYEaGDxhpQ+Y9Lq+vCg3h4BJiZpSpXvmcGdMsj2OkHIfkKTS+jgCyzV2 JoD9gA7NdVHcGOuJkTjjyUPX5QO2sB1YPe7l+Zgk4pC0uj82TqxKQwiDs8CS1Oyo+UbJFkIuyrkn 9S6kK4mhzVnCVPkZsOheZTXRNajeIPILjBLDsAyJX89nIBkt5r87nons29ZZbLzdjrKOfDZezE7B /xRg9T/oE9PMf1t/AgAA//8DAFBLAwQUAAYACAAAACEApdan58AAAAA2AQAACwAAAF9yZWxzLy5y ZWxzhI/PasMwDIfvhb2D0X1R0sMYJXYvpZBDL6N9AOEof2giG9sb69tPxwYKuwiEpO/3qT3+rov5 4ZTnIBaaqgbD4kM/y2jhdj2/f4LJhaSnJQhbeHCGo3vbtV+8UNGjPM0xG6VItjCVEg+I2U+8Uq5C ZNHJENJKRds0YiR/p5FxX9cfmJ4Z4DZM0/UWUtc3YK6PqMn/s8MwzJ5PwX+vLOVFBG43lExp5GKh qC/jU72QqGWq1B7Qtbj51v0BAAD//wMAUEsDBBQABgAIAAAAIQBreZYWgwAAAIoAAAAcAAAAdGhl bWUvdGhlbWUvdGhlbWVNYW5hZ2VyLnhtbAzMTQrDIBBA4X2hd5DZN2O7KEVissuuu/YAQ5waQceg 0p/b1+XjgzfO3xTVm0sNWSycBw2KZc0uiLfwfCynG6jaSBzFLGzhxxXm6XgYybSNE99JyHNRfSPV kIWttd0g1rUr1SHvLN1euSRqPYtHV+jT9yniResrJgoCOP0BAAD//wMAUEsDBBQABgAIAAAAIQB7 Q7xdjQcAAM8gAAAWAAAAdGhlbWUvdGhlbWUvdGhlbWUxLnhtbOxZX4sbyRF/D+Q7DPMu69+M/iyW D2kkec/etY0lO9xjr9SaaW/PtOhu7VochuB7yksgcHfkJZC3PBzHHdxBjrzkwxhsksuHSHXPaNQt tezdxQQTdgXLTOtX1b+uqq4qdd/97GVKvQvMBWFZz6/fqfkezmZsTrK45z+bjisd3xMSZXNEWYZ7 /hoL/7N7v/3NXXQkE5xiD+QzcYR6fiLl8qhaFTMYRuIOW+IMvlswniIJrzyuzjm6BL0prTZqtVY1 RSTzvQyloPbxYkFm2Jsqlf69jfIRhddMCjUwo3yiVGNLQmPn53WFEGsRUe5dINrzYZ45u5zil9L3 KBISvuj5Nf3nV+/draKjQojKA7KG3Fj/FXKFwPy8oefk8Vk5aRCEQatf6tcAKvdxo/aoNWqV+jQA zWaw0pyLrbPdiIICa4DyR4fuYXvYrFt4Q39zj3M/VB8Lr0G5/mAPPx5HYEULr0E5PtzDh4PuYGjr 16Ac39rDt2v9YdC29GtQQkl2voeuha1mtFltCVkweuyEd8Ng3G4UyrcoiIYyutQUC5bJQ7GWoheM jwGggBRJknlyvcQLNIMojhAlZ5x4JyROIPCWKGMChmuN2rjWhP/qE+gn7VF0hJEhrXgBE7E3pPh4 YsbJUvb8B6DVNyBvf/nlzeuf37z++5uvvnrz+odibq3KkjtGWWzK/fq3P/3nL7/3/v3TX3/9+pt8 6l28MPHvvv/Du3/8833qYcVbU7z99sd3P//49s9//Nd3Xzu09zk6M+FTkmLhPcKX3lOWwgId/PEZ v57ENEHElOhnsUAZUrM49I9kYqEfrRFFDtwA23Z8ziHVuID3Vy8swpOEryRxaHyYpBbwlDE6YNxp hYdqLsPM01UWuyfnKxP3FKEL19wRyiwvj1ZLyLHEpTJKsEXzCUWZRDHOsPTUd+wcY8fqviDEsusp mXEm2EJ6XxBvgIjTJFNyZkXTVuiYpOCXtYsg+Nuyzelzb8Coa9VDfGEjYW8g6iA/xdQy4320kih1 qZyilJoGP0EycZGcrPnMxI2EBE/HmDJvNMdCuGQec1iv4fSHkGbcbj+l69RGcknOXTpPEGMmcsjO owSlSxd2QrLExH4uziFEkfeESRf8lNk7RL2DH1B20N3PCbbc/eFs8AwyrElpGyDqmxV3+PI+Zlb8 TtZ0gbAr1fR5aqXYPifO6BisYiu0TzCm6BLNMfaefe5gMGBLy+Zb0g8SyCrH2BVYD5Adq+o9wwJ6 JdXc7OfJEyKskJ3gmB3gc7reSTxrlKWIH9L8CLxu2nwEpS51BcBjOjs3gY8I9IAQL06jPBagwwju g1qfJMgqYOpduON1zS3/XWWPwb58YdG4wr4EGXxtGUjspsx7bTNF1JpgGzBTBF2GK92CiOX+rYgq rlps5ZRb2Jt26wbojqymJyXZBzugnd4n/N/0Po7d8HG6HrdiK2Vds985lFKOd7qcQ7jd3iZifE4+ /dZmiFbZEwzVZD9v3XY2t52N/3/f2Rzaz7f9zKGu47af8aHPuO1niiOWj9PPbFsY6G7UsUd+3KMP f9KDZz8LQulErik+Efr4R8CvmvkYBpWcPvfE5VngMoFHVeZgAgsXc6RlPM7k74hMJglawhlR3VdK YlGojoW3ZAKOjvSwU7fC01V6yub5kWe9ro4388oqkNyO18JyHI6rZI5utbfHeKV6zTbWx60bAkr2 OiSMyWwSTQeJ9mZQGUkf7oLRHCT0yj4Ki66DRUep37hqjwVQK70CP7s9+LHe88MAREAITuWgRZ8r P+Wu3nhXO/NjevqQMa0IgDZ7EwFbT3cV14PLU6vLQ+0KnrZIGOFmk9CW0Q2eSODHcBGdavQqNK7r 6+7WpRY9ZQo9H4TWlka78z4WN/U1yO3mBpqZmYJm3mXPbzVDCJkZWvb8BRwdw2O6hNgR6pcXojHc v8wkzzf8TTLLkgs5RCLJDa6TTp4NUiIx9yhJe75afukGmukcornVG5AQPllyXUgrnxo5cLrtZLxY 4Jk03W6MKEvnr5Dh81zh/FaL3xysJNkK3D1J5pfeGV3xpwhCLGzXlQHnRMANQj235pzAlViZyLbx t1OYirRr3knpGMrHEV0mqKgoZjLP4TqVl3T0W2kD461YMxjUMElRCM9iVWBNo1rVtKwaOYeDVffD QspyRtLc1kwrq6iq6c5i1gybMrBjy5sVeYPVxsSQ08wKn6fu3ZTb3eS6nT6hrBJg8NJ+jqp7hYJg UNtOZlFTjPfTsMrZxahdOzYL/AC1qxQJI+u3Nmp37FbWCOd0MHijyg9yu1ELQ4tNX6ktre/Ozett dvYCkscQutwVlUK7Es53OYKGaKJ7kjxtwBZ5KYutAU/eipOe/2Ut7AdRI4wqtU44qgTNoFbphP1m pR+GzfoorNeGg8YrKCwySethfm8/hmsMui5u7/X43g1+urmpuTNjaZXpG/qqJq5v8OuNwzf4HoGk 82WrMe42u4NWpdvsjyvBcNCpdKPWoDJsRe3heBiFne74le9daHDQb0ZBa9SptOpRVAlaNUW/0620 g0ajH7T7nVHQf1W0MbDyPH0UtgDzal73/gsAAP//AwBQSwMEFAAGAAgAAAAhAA3RkJ+2AAAAGwEA ACcAAAB0aGVtZS90aGVtZS9fcmVscy90aGVtZU1hbmFnZXIueG1sLnJlbHOEj00KwjAUhPeCdwhv b9O6EJEm3YjQrdQDhOQ1DTY/JFHs7Q2uLAguh2G+mWm7l53JE2My3jFoqhoIOumVcZrBbbjsjkBS Fk6J2TtksGCCjm837RVnkUsoTSYkUiguMZhyDidKk5zQilT5gK44o49W5CKjpkHIu9BI93V9oPGb AXzFJL1iEHvVABmWUJr/s/04GolnLx8WXf5RQXPZhQUoosbM4CObqkwEylu6usTfAAAA//8DAFBL AQItABQABgAIAAAAIQDp3g+//wAAABwCAAATAAAAAAAAAAAAAAAAAAAAAABbQ29udGVudF9UeXBl c10ueG1sUEsBAi0AFAAGAAgAAAAhAKXWp+fAAAAANgEAAAsAAAAAAAAAAAAAAAAAMAEAAF9yZWxz Ly5yZWxzUEsBAi0AFAAGAAgAAAAhAGt5lhaDAAAAigAAABwAAAAAAAAAAAAAAAAAGQIAAHRoZW1l L3RoZW1lL3RoZW1lTWFuYWdlci54bWxQSwECLQAUAAYACAAAACEAe0O8XY0HAADPIAAAFgAAAAAA AAAAAAAAAADWAgAAdGhlbWUvdGhlbWUvdGhlbWUxLnhtbFBLAQItABQABgAIAAAAIQAN0ZCftgAA ABsBAAAnAAAAAAAAAAAAAAAAAJcKAAB0aGVtZS90aGVtZS9fcmVscy90aGVtZU1hbmFnZXIueG1s LnJlbHNQSwUGAAAAAAUABQBdAQAAkgsAAAAA ------=_NextPart_01DCDC62.5BE9D8B0 Content-Location: file:///C:/54C8A112/07-azure-security-engineer_files/colorschememapping.xml Content-Transfer-Encoding: quoted-printable Content-Type: text/xml ------=_NextPart_01DCDC62.5BE9D8B0 Content-Location: file:///C:/54C8A112/07-azure-security-engineer_files/filelist.xml Content-Transfer-Encoding: quoted-printable Content-Type: text/xml; charset="utf-8" ------=_NextPart_01DCDC62.5BE9D8B0--