Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudEasy

A security analyst is investigating a recommendation in Microsoft Defender for Cloud that states, 'Enable threat protection for Azure DNS'. The analyst understands that Azure DNS is a critical component of their infrastructure and wants to ensure it is protected against DNS-based attacks. Which Microsoft Defender for Cloud plan needs to be enabled to address this specific recommendation?

  1. AMicrosoft Defender for Azure Cosmos DB
  2. BMicrosoft Defender for Resource Manager
  3. CMicrosoft Defender for App Service
  4. DMicrosoft Defender for DNS
Show answer & explanation

Correct answer: D. Microsoft Defender for DNS

Microsoft Defender for DNS provides threat protection for Azure DNS, detecting suspicious and malicious activities targeting DNS servers, such as data exfiltration or communication with C2 servers via DNS.

Why the other options are wrong

  • A. Defender for Azure Cosmos DB protects Cosmos DB accounts, not DNS.
  • B. Defender for Resource Manager protects management operations in Azure, not the DNS service itself.
  • C. Defender for App Service protects Azure App Service resources, not DNS.

Microsoft Defender for DNS

Microsoft Defender for DNS provides an additional layer of protection for resources that use Azure DNS, continuously monitoring DNS queries from your Azure resources to detect suspicious activities.

  • Detects malicious DNS queries and communications.
  • Identifies data exfiltration attempts via DNS.
  • Alerts on communication with known malicious domains.
  • Enhances security for Azure-hosted applications and services.

Memory trick: Defender's divisions: Each service, its own shield.

More Mitigate threats using Microsoft Defender for Cloud questions