Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard

A security engineer is tasked with ensuring that all newly provisioned Azure Virtual Machines (VMs) in a specific subscription automatically have Microsoft Defender for Cloud enabled and configured for server protection. This must be enforced consistently across all new VM deployments without manual intervention. Which Azure service should the engineer use to implement this automated enforcement?

  1. AAzure CLI scripts
  2. BAzure Automation
  3. CAzure Policy
  4. DAzure Resource Manager (ARM) templates
Show answer & explanation

Correct answer: C. Azure Policy

Azure Policy is designed to enforce organizational standards and assess compliance at scale. It can be used to define policies that automatically enable Microsoft Defender for Cloud on new VMs or audit existing ones for compliance, ensuring consistent security configurations.

Why the other options are wrong

  • A. Azure CLI scripts are for manual or programmatic execution, not for automatic enforcement during resource provisioning.
  • B. Azure Automation can run scripts to configure resources, but it's not a native enforcement mechanism for resource creation.
  • D. ARM templates define infrastructure as code, but they don't enforce post-deployment configurations like enabling Defender for Cloud automatically without additional scripting or policy.

Azure Policy for Security

Azure Policy is a service in Azure that you use to create, assign, and manage policies that enforce rules and effects over your resources to stay compliant with your corporate standards and service level agreements (SLAs).

  • Enforces rules during resource creation and updates.
  • Can audit, deny, or modify resource configurations.
  • Supports built-in policies for common security scenarios.
  • Allows creation of custom policies for specific needs.

Memory trick: Azure Policy: The rulebook for your Azure resources.

More Implement platform protection questions