Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy

A company is using Microsoft Defender for Cloud for their Azure environment. They have a custom security policy that requires all virtual machines to have a specific anti-malware solution installed. After deploying a new VM, Defender for Cloud shows a 'Not Compliant' status for this policy. What is the most immediate action a security engineer should take to understand why the VM is non-compliant?

  1. AReview the 'View compliance details' for the specific policy assignment in Defender for Cloud.
  2. BCheck the Azure Activity Log for recent changes to the VM's configuration.
  3. CRe-evaluate the policy assignment to ensure it is correctly scoped to the VM's resource group.
  4. DRemediate the non-compliant VM directly from the Defender for Cloud recommendations.
Show answer & explanation

Correct answer: A. Review the 'View compliance details' for the specific policy assignment in Defender for Cloud.

To understand the specific reason for non-compliance, the most immediate and direct action is to review the compliance details within Defender for Cloud for that particular policy. This will provide granular information about why the VM is considered non-compliant against the policy's definition.

Why the other options are wrong

  • B. The Activity Log might show changes, but the policy compliance details will directly explain the non-compliance against the policy's rules.
  • C. While scoping is important, the 'Not Compliant' status implies the policy *is* applied, and the issue is with the VM's configuration relative to the policy.
  • D. Remediation is a follow-up action; first, the reason for non-compliance needs to be understood.

Defender for Cloud Compliance Details

A feature within Microsoft Defender for Cloud that provides granular information on why a resource is non-compliant with a specific security policy or initiative.

  • Shows specific assessment results against policy definitions.
  • Helps in diagnosing the root cause of non-compliance.
  • Often includes recommended remediation steps.

Memory trick: Compliance Details Reveal the Policy's Secrets.

More Manage security operations questions