Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard
A software development company uses Azure DevOps for its continuous integration/continuous deployment (CI/CD) pipelines and deploys applications as containers to Azure Kubernetes Service (AKS). They need a solution to scan container images for vulnerabilities, monitor runtime threats in AKS, and enforce security best practices across their containerized workloads. Which Microsoft security solution should they leverage?
- AMicrosoft Defender for Endpoint
- BMicrosoft Defender for Identity
- CMicrosoft Defender for Containers
- DMicrosoft Defender for Cloud Apps
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Defender for Containers
Microsoft Defender for Containers provides cloud-native security capabilities for containerized environments, including vulnerability assessment of container images, runtime threat protection for AKS, and security recommendations for container hosts.
Why the other options are wrong
- A. Microsoft Defender for Endpoint protects traditional IT endpoints (VMs, servers, workstations), not specialized container workloads and orchestrated environments.
- B. Microsoft Defender for Identity protects Active Directory identities, not containerized workloads.
- D. Microsoft Defender for Cloud Apps focuses on protecting SaaS applications and cloud app data, not container security.
Microsoft Defender for Containers
A cloud-native solution that provides security for containerized environments, including vulnerability assessment for images, runtime threat protection for Kubernetes, and hardening recommendations.
- Scans container images for vulnerabilities
- Runtime threat protection for AKS/Kubernetes
- Security recommendations for container hosts
Memory trick: Defender for Containers secures your whole container pipeline.