Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy
A security analyst is monitoring security alerts in Azure Security Center (now Microsoft Defender for Cloud). They notice a high-severity alert indicating 'Suspicious process executed in a container'. They need to quickly understand the scope of the attack, including affected resources and related events, to determine the appropriate response. Which feature in Security Center provides this consolidated view?
- AAsset inventory
- BAlert details page
- CRegulatory Compliance dashboard
- DSecurity recommendations
Show answer & explanationAnswer & explanation
Correct answer: B. Alert details page
The alert details page in Microsoft Defender for Cloud provides comprehensive information about a specific security alert, including affected resources, related entities, attack kill chain details, and recommended actions, enabling quick incident response.
Why the other options are wrong
- A. Asset inventory lists all monitored resources but doesn't provide context for a specific alert.
- C. The Regulatory Compliance dashboard assesses compliance against standards, not individual alerts.
- D. Security recommendations provide actionable steps to improve security posture, not details of an active alert.
Microsoft Defender for Cloud Alert Details
The alert details page within Microsoft Defender for Cloud provides a comprehensive breakdown of a specific security alert, offering context, affected resources, attack timeline, and recommended actions to facilitate investigation and response.
- Consolidates all relevant information for a single alert.
- Includes affected resources and related entities.
- Shows attack kill chain details.
- Provides recommended actions for remediation.
Memory trick: When an alert fires, dive into its details for the full story.