Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium

A security engineer needs to implement a solution to automatically protect newly provisioned Azure Kubernetes Service (AKS) clusters from common container-based threats, such as vulnerable container images, runtime attacks, and suspicious network activity within the cluster. The solution must integrate seamlessly with Microsoft Defender for Cloud. Which Defender for Cloud plan should the engineer enable for this purpose?

  1. AMicrosoft Defender for App Service
  2. BMicrosoft Defender for SQL
  3. CMicrosoft Defender for IoT
  4. DMicrosoft Defender for Containers
Show answer & explanation

Correct answer: D. Microsoft Defender for Containers

Microsoft Defender for Containers is specifically designed to protect Azure Kubernetes Service (AKS) clusters and other containerized environments. It provides capabilities for vulnerability assessment of container images, runtime threat protection for nodes and clusters, and monitoring of suspicious network activity within containers.

Why the other options are wrong

  • A. Defender for App Service protects web applications hosted on App Service, not AKS clusters.
  • B. Defender for SQL protects Azure SQL databases, not container environments.
  • C. Defender for IoT protects IoT devices and solutions, unrelated to AKS clusters.

Microsoft Defender for Containers

A Microsoft Defender for Cloud plan that provides security for containerized environments, including Azure Kubernetes Service (AKS) clusters, by offering vulnerability management, runtime threat protection, and environment hardening.

  • Scans container images for vulnerabilities.
  • Monitors runtime activity for threats.
  • Integrates with Azure Policy for enforcement.
  • Supports AKS and Azure Container Registry.

Memory trick: Each workload has its Defender shield.

More Mitigate threats using Microsoft Defender for Cloud questions