Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A financial institution is migrating its on-premises virtual machines (VMs) to Azure. They need to ensure that these VMs are continuously monitored for security vulnerabilities, misconfigurations, and threats, and receive recommendations for remediation. Which Azure service should be deployed to achieve this comprehensive security posture management for their Azure VMs?

  1. AAzure Network Watcher
  2. BAzure Sentinel
  3. CMicrosoft Defender for Cloud
  4. DAzure Monitor
Show answer & explanation

Correct answer: C. Microsoft Defender for Cloud

Microsoft Defender for Cloud provides comprehensive security posture management and threat protection for Azure resources, including VMs. It continuously assesses security, identifies vulnerabilities, and offers recommendations for remediation.

Why the other options are wrong

  • A. Azure Network Watcher provides network monitoring and diagnostics, not security posture management for VMs.
  • B. Azure Sentinel is a cloud-native SIEM for security information and event management, not direct VM security posture management.
  • D. Azure Monitor collects telemetry and metrics, but does not provide security posture management or threat protection specifically.

Microsoft Defender for Cloud

Microsoft Defender for Cloud is a unified infrastructure security management system that strengthens the security posture of your cloud workloads and provides advanced threat protection.

  • Continuously assesses security posture.
  • Provides security recommendations.
  • Detects threats and generates security alerts.
  • Supports hybrid cloud environments.

Memory trick: Defender for Cloud: Your VM's security guard, always watching.

More Implement platform protection questions