Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A security auditor needs to regularly assess the security posture of an Azure Storage account, including identifying misconfigurations, missing security updates, and potential vulnerabilities. The auditor requires a centralized solution that provides actionable recommendations. Which Azure security service should be configured for the storage account?
- AAzure Activity Log
- BAzure Policy
- CAzure Security Center (Defender for Cloud)
- DAzure Monitor
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Security Center (Defender for Cloud)
Azure Security Center, now part of Microsoft Defender for Cloud, provides unified security management and advanced threat protection capabilities across hybrid cloud workloads. It continuously assesses security posture, identifies vulnerabilities, and offers actionable recommendations for Azure resources, including storage accounts.
Why the other options are wrong
- A. Azure Activity Log records control plane events in Azure subscriptions but does not assess security posture or provide recommendations.
- B. Azure Policy enforces organizational standards and assesses compliance, but it doesn't actively scan for vulnerabilities or provide threat intelligence.
- D. Azure Monitor collects and analyzes telemetry from Azure resources but does not provide security posture assessment or recommendations directly.
Microsoft Defender for Cloud
A cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and advanced threat protection for hybrid cloud workloads.
- Continuously assesses security posture.
- Identifies vulnerabilities and provides actionable recommendations.
- Offers advanced threat protection for various Azure services, including storage.
Memory trick: Defender for Cloud defends by finding and fixing security weaknesses.