Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium
A medium-sized enterprise is deploying several business-critical applications into Azure. The security architect needs to ensure that all virtual machines (VMs) are configured with a baseline set of security settings, including specific operating system hardening, antivirus software installation, and regular patch management. These configurations must be consistently applied and continuously monitored for drift. Which Azure service combination provides the most effective solution for this scenario?
- AAzure Security Center (Defender for Cloud) and Azure Advisor
- BAzure Network Watcher and Azure Monitor
- CAzure Site Recovery and Azure Backup
- DAzure Policy and Azure Automation
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Policy and Azure Automation
Azure Policy can define and audit security baselines and enforce desired configurations, while Azure Automation can be used to deploy and manage software like antivirus and manage patch updates across VMs, ensuring consistent application and continuous monitoring for drift.
Why the other options are wrong
- A. Security Center provides security posture management and recommendations, and Advisor offers best practice recommendations, but neither directly enforces specific OS hardening or software installation at scale.
- B. Network Watcher monitors network health, and Azure Monitor collects logs and metrics, neither directly enforces VM security configurations or software deployment.
- C. Site Recovery and Backup are for disaster recovery and data protection, not for enforcing security configurations or software deployment on VMs.
Azure Policy & Automation for VM Security
Azure Policy helps define and enforce security configurations for VMs, ensuring compliance with organizational standards. Azure Automation extends this by providing capabilities for deploying software, managing patches, and applying desired state configurations (DSC) across VMs.
- Azure Policy enforces configuration baselines.
- Azure Automation automates deployment and patch management.
- Ensures consistent security posture for VMs.
- Monitors for configuration drift and remediates issues.
Memory trick: Policy Sets Rules, Automation Executes, VMs Stay Secure.