Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium
A security operations center (SOC) team is investigating a series of malicious file detections originating from a specific Azure Storage account within Microsoft Defender for Cloud. They need to automate the response to immediately quarantine any future detected malicious files in this storage account. Which feature in Defender for Cloud, integrated with other Azure services, should they configure?
- ACloud Security Explorer
- BWorkflow automation
- CSecurity Workbooks
- DAttack path analysis
Show answer & explanationAnswer & explanation
Correct answer: B. Workflow automation
Workflow automation in Microsoft Defender for Cloud allows you to trigger Azure Logic Apps or Azure Functions in response to security alerts, enabling automated remediation actions like quarantining files.
Why the other options are wrong
- A. Cloud Security Explorer is for discovering security risks and vulnerabilities, not for automating remediation.
- C. Security Workbooks are for data visualization and reporting, not for automated actions.
- D. Attack path analysis helps identify potential attack vectors, but doesn't automate responses.
Defender for Cloud Workflow Automation
A feature in Microsoft Defender for Cloud that enables automated responses to security alerts and recommendations by triggering Azure Logic Apps or Azure Functions, streamlining incident response.
- Automates repetitive security tasks.
- Integrates with Azure Logic Apps and Azure Functions.
- Can perform actions like quarantining, sending notifications, or opening tickets.
- Reduces manual effort and response time to security events.
Memory trick: For alerts to auto-act, workflow automation is the pact.