Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global enterprise is designing a Zero Trust architecture for its cloud environment, which includes Azure, AWS, and SaaS applications. The security team needs a unified platform to continuously assess the security posture of cloud resources, identify misconfigurations, track compliance against industry benchmarks (e.g., CIS, NIST), and provide recommendations for remediation across all these diverse cloud platforms. Which Microsoft service is BEST suited for this comprehensive multi-cloud security posture management?

  1. AAzure Sentinel
  2. BMicrosoft Defender for Cloud
  3. CAzure Policy
  4. DMicrosoft Purview
Show answer & explanation

Correct answer: B. Microsoft Defender for Cloud

Microsoft Defender for Cloud (formerly Azure Security Center) provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) capabilities across multi-cloud and hybrid environments. It continuously assesses resources, identifies misconfigurations, offers compliance tracking against benchmarks, and provides actionable recommendations, making it ideal for a unified Zero Trust security posture management.

Why the other options are wrong

  • A. Azure Sentinel (now Microsoft Sentinel) is a cloud-native SIEM/SOAR solution for security information and event management, not primarily for continuous security posture assessment and misconfiguration detection across multi-cloud.
  • C. Azure Policy is primarily for enforcing organizational standards and assessing compliance for Azure resources. It does not provide multi-cloud CSPM capabilities for AWS, GCP, or SaaS applications.
  • D. Microsoft Purview focuses on data governance, data classification, and compliance across hybrid and multi-cloud environments, not on overall security posture management and misconfiguration detection of infrastructure and applications.

Microsoft Defender for Cloud (CSPM)

A unified security management platform that provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across multi-cloud and hybrid environments.

  • Continuous security assessment and recommendations.
  • Compliance tracking against industry benchmarks.
  • Covers Azure, AWS, GCP, and on-premises resources.

Memory trick: Defender for Cloud: The all-seeing eye for multi-cloud security.

More Design a Zero Trust strategy and architecture questions