Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security auditor needs to verify that all Azure Key Vaults in a subscription are configured to enable purge protection, which prevents immediate deletion of the vault or its contents. They want to quickly identify any non-compliant Key Vaults. Which service in Azure should the auditor use to assess this configuration against a predefined security standard?

  1. AAzure Monitor
  2. BAzure Activity Log
  3. CMicrosoft Defender for Cloud
  4. DAzure Network Watcher
Show answer & explanation

Correct answer: C. Microsoft Defender for Cloud

Microsoft Defender for Cloud (formerly Azure Security Center) provides a centralized security posture management solution. It continuously assesses Azure resources against security best practices and regulatory standards, identifying misconfigurations like missing purge protection on Key Vaults and providing recommendations for remediation.

Why the other options are wrong

  • A. Azure Monitor collects and analyzes metrics and logs but does not inherently assess compliance against security standards for resource configurations.
  • B. Azure Activity Log records control plane operations (who did what, when) but does not assess the configuration state of resources against security standards.
  • D. Azure Network Watcher provides tools for monitoring, diagnosing, and viewing network performance, not for assessing resource configurations against security standards.

Microsoft Defender for Cloud Security Posture Management

A unified security management system that strengthens the security posture of cloud resources and provides advanced threat protection.

  • Continuously assesses security configurations.
  • Provides security recommendations based on benchmarks and standards.
  • Offers a secure score to quantify security posture.

Memory trick: Defender for Cloud 'defends' your 'posture' by 'checking' everything.

More Manage security operations questions