Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy

A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). They are concerned about vulnerabilities in container images used in their CI/CD pipelines and misconfigurations in their ARM templates. They need a solution that can automatically scan these artifacts for security issues early in the development process. Which Microsoft Defender for Cloud capability should they leverage?

  1. ADefender for Cloud - Vulnerability Management
  2. BDefender for Cloud - IoT
  3. CDefender for Cloud Apps
  4. DDefender for Cloud - DevOps Security
Show answer & explanation

Correct answer: D. Defender for Cloud - DevOps Security

Microsoft Defender for Cloud - DevOps Security is specifically designed to integrate security into the DevOps pipeline. It provides capabilities like vulnerability scanning for container images and infrastructure-as-code (IaC) template scanning (e.g., ARM templates) directly within Azure DevOps.

Why the other options are wrong

  • A. Defender for Cloud - Vulnerability Management is a broader capability for assessing and managing vulnerabilities across Azure resources, but DevOps Security specifically integrates into the CI/CD pipeline.
  • B. Defender for Cloud - IoT is for securing IoT devices and solutions, which is not relevant to this scenario.
  • C. Defender for Cloud Apps (formerly MCAS) is a Cloud Access Security Broker (CASB) for SaaS applications, not for DevOps pipeline security.

Defender for Cloud - DevOps Security

A capability within Microsoft Defender for Cloud that integrates security into the DevOps workflow, providing visibility and protection across multi-pipeline environments by scanning for vulnerabilities and misconfigurations in code, images, and IaC templates.

  • Integrates with Azure DevOps, GitHub, and GitLab.
  • Scans container images for vulnerabilities.
  • Identifies misconfigurations in Infrastructure-as-Code (IaC) templates.
  • Shifts security left into the development lifecycle.

Memory trick: DevOps Security: Scan code early, fix issues quickly.

More Design security for applications and data questions