Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
A financial institution is migrating its on-premises virtual machines (VMs) to Azure. The security policy requires that all VMs must be protected against malicious software, unauthorized system changes, and unpatched vulnerabilities. Additionally, the institution needs to ensure that only approved software is allowed to run on these VMs. Which Azure security service should be configured on the VMs to address these requirements comprehensively?
- AAzure Security Center (now Defender for Cloud)
- BAzure Policy
- CAzure Network Watcher
- DAzure Active Directory
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Security Center (now Defender for Cloud)
Azure Security Center (now Microsoft Defender for Cloud) provides a comprehensive suite of security capabilities for VMs, including antimalware, file integrity monitoring, adaptive application controls (to allow only approved software), and vulnerability assessments, directly addressing all the stated requirements.
Why the other options are wrong
- B. Azure Policy enforces organizational standards and assesses compliance, but it doesn't directly provide antimalware or application control for running VMs.
- C. Azure Network Watcher focuses on network monitoring and diagnostics, not host-level security for VMs.
- D. Azure Active Directory is an identity and access management service, not a host protection service.
Microsoft Defender for Cloud (Server Protection)
A comprehensive cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that helps secure Azure, on-premises, and multi-cloud resources.
- Provides threat protection and vulnerability management.
- Includes antimalware, file integrity monitoring, and adaptive application controls.
- Offers recommendations to improve security posture across hybrid environments.
Memory trick: Defender for Cloud guards your VMs like a loyal knight.