Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy

A company uses Azure Security Center (now Microsoft Defender for Cloud) to manage its security posture. They have several Azure subscriptions and want to ensure that all virtual machines across these subscriptions are configured with a specific set of security recommendations. Which feature should they use to centrally define and apply these security recommendations?

  1. AAzure Sentinel workbooks
  2. BAzure Monitor Log Analytics workspaces
  3. CAzure Network Watcher
  4. DAzure Policy
Show answer & explanation

Correct answer: D. Azure Policy

Azure Policy allows organizations to create, assign, and manage policies that enforce specific rules and effects over their resources, ensuring compliance with security recommendations across multiple subscriptions.

Why the other options are wrong

  • A. Azure Sentinel workbooks are for data visualization and reporting, not for applying security configurations.
  • B. Log Analytics workspaces are used for collecting and analyzing log data, not for defining security recommendations.
  • C. Azure Network Watcher is for monitoring and diagnosing network-related issues, not for applying security recommendations.

Azure Policy for Security

Azure Policy helps enforce organizational standards and assess compliance at scale. Through its compliance dashboard, it provides an aggregated view to evaluate the overall state of the environment, with the ability to drill down to the per-resource, per-policy, and per-assignment detail.

  • Enforces organizational standards.
  • Assesses compliance at scale.
  • Integrates with Azure Security Center (Microsoft Defender for Cloud).
  • Can prevent resource creation that violates policies.

Memory trick: Govern your cloud with a strict Azure Policy.

More Manage security operations questions