Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is analyzing a recommendation in Microsoft Defender for Cloud that suggests enabling 'Adaptive Application Controls' for several virtual machines. What is the primary benefit of implementing Adaptive Application Controls?

  1. ATo detect and respond to advanced persistent threats (APTs).
  2. BTo encrypt data at rest on the virtual machines.
  3. CTo create a dynamic allowlist of applications that can run on the VMs.
  4. DTo limit network access to management ports using Just-in-Time access.
Show answer & explanation

Correct answer: C. To create a dynamic allowlist of applications that can run on the VMs.

Adaptive Application Controls in Microsoft Defender for Cloud help harden VMs by creating a dynamic allowlist of applications that are permitted to run, effectively preventing the execution of unauthorized or malicious software.

Why the other options are wrong

  • A. While it contributes to overall security, its primary mechanism is application control, not direct APT detection, which is typically handled by EDR solutions.
  • B. Encryption of data at rest is typically handled by Azure Disk Encryption or service-side encryption, not Adaptive Application Controls.
  • D. Limiting network access to management ports is achieved through Just-in-Time (JIT) VM access, a separate feature.

Adaptive Application Controls

A feature in Microsoft Defender for Cloud that helps to harden virtual machines by intelligently recommending, and optionally enforcing, an allowlist of applications that are permitted to run on the servers.

  • Reduces the risk of malware and unauthorized software execution.
  • Learns legitimate application behavior over time.
  • Generates rules to allow only known-good applications.
  • Requires the Defender for Servers Plan 2.

Memory trick: To control what apps can run free, Adaptive Controls are the key.

More Mitigate threats using Microsoft Defender for Cloud questions