Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A security engineer is tasked with ensuring that all newly provisioned Azure Virtual Machines adhere to a strict baseline configuration, including specific operating system settings, security extensions, and allowed software. If a VM deviates from this configuration, it should be flagged for remediation or prevented from deploying. Which Azure service is designed to enforce these organizational standards and assess compliance for VMs?

  1. AAzure Policy
  2. BAzure Advisor
  3. CAzure Monitor
  4. DAzure Sentinel
Show answer & explanation

Correct answer: A. Azure Policy

Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce rules and effects over your resources to ensure they stay compliant with your corporate standards and service level agreements. It can audit for non-compliance or deny resource creation that violates policies.

Why the other options are wrong

  • B. Azure Advisor provides personalized recommendations for best practices, but it doesn't enforce them.
  • C. Azure Monitor collects and analyzes telemetry data from Azure resources, but it doesn't enforce configurations.
  • D. Azure Sentinel is a cloud-native Security Information and Event Management (SIEM) solution, used for threat detection and response, not configuration enforcement.

Azure Policy

A service that helps to enforce organizational standards and to assess compliance at scale. It provides a way to define rules for your Azure resources.

  • Enforces standards and assesses compliance.
  • Can audit for non-compliance or deny resource creation.
  • Works with built-in or custom policy definitions.

Memory trick: Azure Policy is the rulebook for your Azure resources.

More Implement platform protection questions