Agent 365
Purview
Defender
Azure Dev Ops
Cyber Trivia & Accenture
100
  • This cross-tenant governance mechanism in Agent 365 allows enterprise security teams to restrict autonomous agent API execution to specific verified service principles and endpoints.


  • What is Agent Access Control (or Agent-Level Conditional Access)?


100

In Microsoft Purview Information Protection, this specific cryptographic mechanism ensures that encrypted emails and documents remain readable to authorized external tenants via Microsoft Entra federation without manually exchanging keys.

  • What is Azure Information Protection (AIP) Rights Management Service (RMS)?


100

This advanced correlation engine within Microsoft Defender XDR stitches together isolated alerts, telemetry events, and compromised entities into a single unified investigation timeline across endpoints, identities, and cloud apps.


  • What is the Incident Engine (or Automated Investigation and Response / AIR)?


100

To execute build and release jobs that require private network access to internal Azure vNets without exposing public IP addresses, engineers must deploy this self-hosted infrastructure model instead of Microsoft-hosted runners.


  • What is a Self-Hosted Agent (or Self-Hosted Agent Pool)?


100

This specific cyberattack technique involves manipulating domain name resolution to redirect traffic from a legitimate website to an adversary's malicious mirror site without altering the target URL.


  • What is Pharming (or DNS Spoofing / Cache Poisoning)?


200
  • When managing non-human agent identities, Agent 365 relies on this specialized Entra ID object model to separate runtime execution context from human user delegated permissions.


  • What is an Agent Identity Principal (or Workload Identity / Service Principal)?


200

When configuring Purview Data Loss Prevention (DLP) for endpoints, this specialized driver-level component monitors local file system events, screen captures, and USB egress activities directly on the OS.


  • What is the Microsoft Defender Endpoint DLP Agent (or Endpoint DLP Sensor)?


200

In Microsoft Defender for Endpoint, this advanced protection capability executes untrusted or suspicious executables within a dynamic hardware-isolated container to analyze behavioral payload signatures before execution on the host OS.


  • What is Automated Sandbox Analysis (or Deep Analysis / Endpoint Attack Surface Reduction Containers)?


200

In Azure Pipelines, this strategy allows deployment jobs to target individual nodes within an environment sequentially, running health checks between iterations to ensure zero-downtime rolling updates.


  • What is a Deployment Strategy (specifically runOnce, rolling, or canary)?


200

This proprietary Accenture platform integrates security operations, threat intelligence, and cloud posture management across multi-cloud enterprise environments to automate threat remediation.


  • What is Accenture mySecurity (or Accenture Cybersecurity Platform / Total Enterprise Health)?


300
  • To enforce operational boundary limits and prevent infinite API execution loops during complex agent-to-agent orchestrations, Agent 365 evaluates this execution metric against assigned administrative policies.


  • What is standard step/recursion limit (or Agent Run Limits)?

300

Purview Data Map uses this open-source Apache framework standard as its foundational metadata schema to model complex data assets, lineage, and cross-platform data relationships.


  • What is Apache Atlas?


300

When onboarding hybrid or multi-cloud server fleets to Defender for Cloud for runtime protection and posture management, this underlying operational framework must be deployed to project non-Azure nodes into Azure Resource Manager.


  • What is Azure Arc?


300

This feature in Azure Repos allows teams to enforce policies like mandatory pull request reviewers, build validation completion, and work item linking before code can be merged into a protected branch.


  • What are Branch Policies?


300

In symmetric cryptography, this specific operational mode turns a block cipher into a stream cipher by generating a sequence of keystream blocks based on an Initialization Vector (IV) and a counter, widely used in TLS for parallel processing efficiency.


  • What is Counter Mode (CTR) or Galois/Counter Mode (GCM)?


400
  • Agent 365 monitors agent telemetry for this specific attack vector, where an adversary crafts malicious prompts inside ingested data sources to bypass system controls and alter an agent's runtime instructions.


  • What is Indirect Prompt Injection?

400

To apply retention or deletion rules to non-Microsoft data sources—such as Slack, Salesforce, or local file shares—Purview requires the configuration of these dedicated ingestion components.


  • What are Purview Data Connectors?


400

Defender for Identity relies on this specific protocol parser and sensor deployed directly on Active Directory Domain Controllers to inspect network traffic and NTDS event logs for lateral movement vectors like Kerberoasting and Pass-the-Hash.


  • What is the Defender for Identity Sensor (inspecting MRPC/Kerberos/NTLM/LDAP traffic)?


400

To share reusable pipeline templates across multiple repositories within an organization while enforcing strict governance standards, engineers use this YAML construct to reference external repository sources.


  • What is the resources.repositories definition (or Pipeline Resource Templates)?


400

This global network of specialized facilities operated by Accenture Security allows client security teams to simulate live cyberattacks, execute threat hunting exercises, and test incident response playbooks in isolated sandbox environments.


  • What are Accenture Cyber Fusion Centers?


500
  • In high-compliance agent topologies, Agent 365 routes heavy UI-driven agent workloads through this dedicated, isolated runtime infrastructure to ensure memory-level segregation and prevent host privilege escalation.


  • What is Windows 365 for Agents (or Isolated Agent Virtual Nodes)?

500

During advanced eDiscovery processing, Purview uses this natural language processing and machine learning capability to group logically similar documents and remove exact or near-duplicate items from the review set.


  • What is Near-Duplicate Detection and Email Threading (or Predictive Coding/Document Clustering)?


500

To query raw telemetry data across tables like DeviceProcessEvents, IdentityLogonEvents, and EmailEvents within Defender XDR, engineers use this proprietary data manipulation language.


  • What is Kusto Query Language (KQL)?


500

When configuring non-interactive service authentication between Azure DevOps pipelines and Azure Resource Manager without storing static secrets or client certificates, engineers leverage this security federation standard.


  • What is Workload Identity Federation (using OIDC - OpenID Connect)?


500

This sophisticated post-exploitation framework technique relies on loading unmanaged DLLs directly into legitimate Windows process memory spaces (like lsass.exe or svchost.exe) without writing temporary files to the disk to bypass traditional antivirus monitoring.


What is Reflective DLL Injection (or Process Injection / Living off the Land)?

M
e
n
u