Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard
A security engineer is analyzing a recommendation in Microsoft Defender for Cloud that suggests enabling 'Adaptive Application Controls' for several virtual machines. What is the primary benefit of implementing Adaptive Application Controls?
- ATo detect and respond to advanced persistent threats (APTs).
- BTo encrypt data at rest on the virtual machines.
- CTo create a dynamic allowlist of applications that can run on the VMs.
- DTo limit network access to management ports using Just-in-Time access.
Show answer & explanationAnswer & explanation
Correct answer: C. To create a dynamic allowlist of applications that can run on the VMs.
Adaptive Application Controls in Microsoft Defender for Cloud help harden VMs by creating a dynamic allowlist of applications that are permitted to run, effectively preventing the execution of unauthorized or malicious software.
Why the other options are wrong
- A. While it contributes to overall security, its primary mechanism is application control, not direct APT detection, which is typically handled by EDR solutions.
- B. Encryption of data at rest is typically handled by Azure Disk Encryption or service-side encryption, not Adaptive Application Controls.
- D. Limiting network access to management ports is achieved through Just-in-Time (JIT) VM access, a separate feature.
Adaptive Application Controls
A feature in Microsoft Defender for Cloud that helps to harden virtual machines by intelligently recommending, and optionally enforcing, an allowlist of applications that are permitted to run on the servers.
- Reduces the risk of malware and unauthorized software execution.
- Learns legitimate application behavior over time.
- Generates rules to allow only known-good applications.
- Requires the Defender for Servers Plan 2.
Memory trick: To control what apps can run free, Adaptive Controls are the key.