Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy

A global enterprise is designing a Zero Trust architecture for its cloud environment, which includes Azure and AWS. The security team needs to ensure that all cloud resources (VMs, storage accounts, databases, etc.) are continuously monitored for misconfigurations, vulnerabilities, and threats. Furthermore, they require automated responses to detected threats and compliance with industry standards. The solution must provide a unified view across both cloud providers.

  1. ADevelop custom scripts to periodically audit cloud configurations and generate reports.
  2. BImplement a Security Information and Event Management (SIEM) system to collect logs from both clouds.
  3. CDeploy individual security agents on each virtual machine within each cloud environment.
  4. DUtilize Microsoft Defender for Cloud for integrated Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across Azure and AWS.
Show answer & explanation

Correct answer: D. Utilize Microsoft Defender for Cloud for integrated Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across Azure and AWS.

Microsoft Defender for Cloud is specifically designed to provide unified security management across multi-cloud environments, including Azure and AWS. It offers integrated CSPM for posture management and CWP for threat protection for various resources, enabling continuous monitoring, vulnerability management, automated responses, and compliance assessments from a single platform.

Why the other options are wrong

  • A. Custom scripts are not scalable, prone to errors, and cannot provide continuous, real-time monitoring and automated responses across complex cloud environments.
  • B. A SIEM is for log aggregation and analysis, not for continuous security posture assessment, vulnerability management, or automated remediation services across cloud resources.
  • C. While security agents are part of CWP, they don't provide the comprehensive CSPM, compliance, and unified view across multiple clouds that is required.

Microsoft Defender for Cloud (CSPM & CWP)

A unified security solution that helps strengthen the security posture of cloud environments and protect workloads running in Azure, AWS, and GCP.

  • Combines Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP).
  • Provides continuous assessment of security configurations and compliance.
  • Detects threats and offers recommendations for remediation.
  • Supports multi-cloud and hybrid environments.

Memory trick: Defender for Cloud: Defends All Clouds, Posture and Workloads.

More Design a Zero Trust strategy and architecture questions