Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium
A security architect is designing a strategy for securing virtual machines (VMs) in Azure. The organization has a strict policy that all VMs must have a baseline security configuration applied automatically upon deployment and continuously monitored for drift. Additionally, any non-compliant configurations must be remediated without manual intervention. Which Azure service combination should be used to achieve this?
- AAzure Network Watcher and Azure Monitor.
- BAzure Policy and Azure Automation.
- CAzure Security Center (Defender for Cloud) and Azure Advisor.
- DAzure Sentinel and Azure Activity Log.
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Policy and Azure Automation.
Azure Policy allows defining and enforcing baseline security configurations for VMs, ensuring compliance at deployment and continuous monitoring for drift. Azure Automation can then be used to automatically remediate non-compliant resources identified by Azure Policy, achieving the desired automatic and continuous remediation.
Why the other options are wrong
- A. Azure Network Watcher monitors network performance and diagnostics. Azure Monitor collects and analyzes telemetry data. Neither directly enforces VM security baselines or provides automatic remediation.
- C. Azure Security Center (Defender for Cloud) provides recommendations and posture management but doesn't directly enforce baseline configurations or automatically remediate drift in the same way Azure Policy and Automation do. Azure Advisor provides recommendations for best practices, not enforcement or remediation.
- D. Azure Sentinel is a SIEM solution for security analytics and threat intelligence. Azure Activity Log records control-plane events. These are for monitoring and incident response, not for proactive configuration enforcement and remediation.
Azure Policy & Automation for VM Security
Azure Policy enforces organizational standards and assesses compliance at scale. Azure Automation helps manage and automate tasks, including the remediation of non-compliant resources identified by Azure Policy.
- Azure Policy defines and enforces resource configurations.
- Monitors for configuration drift.
- Azure Automation executes remediation actions.
- Ensures continuous compliance and security baselines.
Memory trick: Policy sets the rules, Automation fixes the flaws.