Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
A company is migrating several legacy applications to Azure Virtual Machines (VMs). These applications run on Windows Server and require specific security configurations and monitoring for compliance. The security team wants to ensure that all VMs automatically receive endpoint protection, vulnerability assessments, and just-in-time (JIT) VM access. Which Azure service should be used to achieve this comprehensive host security for the VMs?
- AMicrosoft Defender for Servers
- BAzure Bastion
- CAzure Monitor
- DAzure Policy
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Defender for Servers
Microsoft Defender for Servers, a component of Microsoft Defender for Cloud, provides comprehensive host security features for VMs, including endpoint protection, vulnerability assessments, and JIT VM access. It's designed to protect servers and ensure compliance.
Why the other options are wrong
- B. Azure Bastion provides secure and seamless RDP/SSH connectivity to VMs over SSL, but it does not offer endpoint protection or vulnerability assessments.
- C. Azure Monitor collects and analyzes telemetry data but is not a security service for host protection.
- D. Azure Policy enforces organizational standards and assesses compliance but does not directly provide endpoint protection, vulnerability assessments, or JIT VM access.
Microsoft Defender for Servers
Microsoft Defender for Servers is a cloud-native solution providing comprehensive protection for your Windows and Linux machines across Azure, hybrid, and multi-cloud environments.
- Part of Microsoft Defender for Cloud.
- Includes endpoint detection and response (EDR) capabilities.
- Provides vulnerability assessment and recommendations.
- Enables Just-in-Time (JIT) VM access to reduce attack surface.
Memory trick: To defend my server, I need a 'Defender' to protect, scan, and guard access.