Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudEasy

A security analyst is investigating a recommendation in Microsoft Defender for Cloud that states, 'Management ports should be closed on Virtual Machines.' They notice that this recommendation has a high Secure Score impact. Which specific security principle is this recommendation primarily aiming to enforce to reduce the attack surface?

  1. ALeast Privilege Access
  2. BMinimizing Attack Surface
  3. CDefense in Depth
  4. DZero Trust Network Access
Show answer & explanation

Correct answer: B. Minimizing Attack Surface

Closing management ports on Virtual Machines directly reduces the number of potential entry points for attackers, which is a core principle of minimizing the attack surface.

Why the other options are wrong

  • A. Least Privilege Access relates to user permissions, not network port exposure.
  • C. Defense in Depth is a strategy using multiple layers of security, but 'closing ports' specifically targets the attack surface.
  • D. Zero Trust Network Access is about verifying every access request, but the direct impact of closing ports is attack surface reduction.

Minimizing Attack Surface

A security principle focused on reducing the number of potential entry points or vulnerabilities that an attacker could exploit in a system, application, or network.

  • Involves removing unnecessary services, ports, and features.
  • Reduces the likelihood of successful exploitation.
  • A fundamental concept in secure design.
  • Example: closing unused network ports.

Memory trick: Closed ports reduce the attack, for security to come back.

More Mitigate threats using Microsoft Defender for Cloud questions