Supplement · Microsoft Azure

Labs thiên về validation và decision evidence

Không lab nào yêu cầu tạo resource trả phí. Chỉ đánh dấu PASS trong EVIDENCE.md sau khi lưu command, output và kết luận có thể tái lập.

Safety: dùng local fixtures hoặc tenant sandbox được cấp quyền. Các bước what-if, Policy và RBAC có thể cần Azure login; nếu không có, hoàn thành phần static/tabletop và ghi trạng thái BLOCKED/NOT RUN.

Lab 1 · Bicep static validation

Mục tiêu: phát hiện syntax/type/configuration issue trước deployment.

  1. Tạo Bicep tối thiểu gồm VNet, subnet và diagnostic settings bằng parameter; không hard-code subscription ID/secret.
  2. Chạy az bicep build --file main.bicepaz bicep lint --file main.bicep.
  3. Nếu có sandbox, chạy az deployment sub what-if hoặc resource-group what-if với scope hợp lệ; không execute deployment.
  4. Lưu version, exit code, stdout/stderr, diff dự kiến và kết luận.

PASS: build/lint sạch và what-if (nếu chạy) không có delete/unexpected scope.

Lab 2 · Terraform static validation

Mục tiêu: kiểm tra module không cần provision.

  1. Tạo module Azure nhỏ với provider constraint, typed variables, tags và outputs không nhạy cảm.
  2. Chạy terraform fmt -check -recursive, terraform init -backend=false, terraform validate.
  3. Nếu provider download không khả dụng, ghi BLOCKED thay vì PASS; không dùng output giả.
  4. Review plan assumptions: provider version, state ownership, secret handling và destructive changes.

PASS: fmt/validate exit 0 và assumptions được ghi.

Lab 3 · Azure Policy reasoning

Mục tiêu: thiết kế guardrail có test cases.

  1. Viết policy yêu cầu approved locations hoặc deny public network access cho một resource type.
  2. Tạo bảng ít nhất 6 cases: missing field, compliant, non-compliant, exempt, existing resource và child resource.
  3. Trace condition/effect; xác định alias, mode, scope, assignment parameter và remediation need.
  4. Lập rollout audit → measured impact → exemption → deny.

PASS: mọi case có expected result/rationale và không nhầm Policy với RBAC.

Lab 4 · RBAC/PIM threat review

Mục tiêu: suy ra effective access và giảm standing privilege.

  1. Dựng bảng principals, groups, role definitions, scopes và inherited assignments cho một workload giả lập.
  2. Tìm quyền rộng từ group nesting, subscription scope, custom role wildcard và service principal stale.
  3. Chuyển privileged roles sang PIM eligible với activation duration, MFA, approval và alert.
  4. Thiết kế break-glass test và quarterly access review.

PASS: bảng before/after chỉ rõ access path, owner và residual risk.

Lab 5 · Network/DNS tabletop

Mục tiêu: debug private endpoint theo packet/name path.

  1. Vẽ client → resolver → private DNS zone → private endpoint → service; thêm hub, on-prem forwarder và route.
  2. Inject ba lỗi: zone chưa link, stale public answer và forced-tunnel asymmetric path.
  3. Với mỗi lỗi ghi query/route/effective-rule evidence cần thu và cách phân biệt.
  4. Kiểm tra public network access và egress/SNAT assumptions.

PASS: mỗi hypothesis có falsification evidence và remediation cụ thể.

Lab 6 · Quota và scaling pre-mortem

Mục tiêu: chứng minh scale/DR không bị quota ẩn chặn.

  1. Chọn workload giả lập, liệt kê normal/peak/zone-loss/region-failover capacity.
  2. Lập quota matrix theo subscription, region, VM family hoặc service SKU và deployment API limits.
  3. Tính headroom, provisioning lead time và fallback SKU/region.
  4. Thiết kế alerts tại 70/85/95% và owner cho quota request.

PASS: mọi recovery scenario có capacity source, threshold và escalation.

Lab 7 · DR tabletop

Mục tiêu: kiểm tra runbook end-to-end không thực hiện failover.

  1. Chọn scenario mất primary region và tạo dependency graph.
  2. Gán incident commander, trigger, RTO/RPO, decision checkpoints và communication.
  3. Walk through data recovery, secrets, quota, compute, DNS/traffic, validation và failback.
  4. Ghi timing, assumption thất bại, gap và action owner/deadline.

PASS: elapsed timeline nằm trong/ngoài RTO được chứng minh; tabletop không được ghi là failover test thật.

Lab 8 · Security incident + FinOps review

Mục tiêu: nối detection, containment và cost signal.

  1. Scenario: managed identity bị lạm dụng và log ingestion/cost tăng bất thường.
  2. Viết KQL/pseudocode queries cần dùng, preservation steps, containment order và credential/role recovery.
  3. Lập cost allocation theo owner/environment/service và unit metric; phân biệt attack cost với baseline growth.
  4. Tạo post-incident actions cho alert, least privilege, retention và budget anomaly.

PASS: quyết định containment bảo toàn evidence; cost action không làm mất security telemetry cần thiết.

Tài liệu: Bicep linter · Bicep what-if · Terraform validate · Policy compliance

Evidence integrity và runtime claim boundary

Trạng thái mặc định: cả 8 labs là NOT RUN cho đến khi có artifact thực tế. Planned command, tabletop conclusion hoặc sample output không chứng minh Azure resource đã deploy hay runtime control đã hoạt động.
LabStatus ban đầuEvidence tối thiểu
1. Bicep static validationNOT RUNCommand output
2. Terraform static validationNOT RUNCommand output
3. Azure Policy reasoningNOT RUNTest-case artifact
4. RBAC/PIM threat reviewNOT RUNBefore/after access matrix
5. Network/DNS tabletopNOT RUNHypothesis matrix
6. Quota/scaling pre-mortemNOT RUNQuota matrix
7. DR tabletopNOT RUNExercise timeline
8. Security incident + FinOpsNOT RUNIncident record

Evidence template

Lab:
Date/time (timezone):
Operator:
Environment/scope:
Cost guardrail:
Tool versions:
Inputs and assumptions:
Commands or tabletop injects:
Exit codes:
Raw output/artifact paths:
Expected result:
Observed result:
Conclusion: PASS | FAIL | BLOCKED
Limitations (what this does not prove):
Follow-up owner/date:
← Câu hỏiChecklist →