Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is configuring a new Azure subscription to meet strict compliance requirements. They need to ensure that all virtual machines provisioned in this subscription are automatically encrypted with Azure Disk Encryption (ADE) and that any VM deployed without ADE is flagged as non-compliant. Which combination of Microsoft Defender for Cloud and Azure Policy capabilities should the engineer use to enforce this requirement efficiently?

  1. AManually enable ADE for each VM and dismiss the 'Unencrypted disks' recommendation.
  2. BImplement Adaptive Application Controls and configure a workflow automation.
  3. CUse a built-in Azure Policy 'DeployIfNotExists' effect for ADE and enable a corresponding audit policy.
  4. DEnable Just-in-Time (JIT) VM access and configure a custom alert.
Show answer & explanation

Correct answer: C. Use a built-in Azure Policy 'DeployIfNotExists' effect for ADE and enable a corresponding audit policy.

To efficiently enforce Azure Disk Encryption, a built-in Azure Policy with the 'DeployIfNotExists' effect can automatically apply ADE to non-compliant VMs. Concurrently, an 'AuditIfNotExists' or 'Audit' policy can flag any VMs that are not encrypted, ensuring continuous compliance monitoring and enforcement.

Why the other options are wrong

  • A. Manually enabling ADE is not efficient or scalable for new VMs, and dismissing recommendations hides the compliance gap.
  • B. Adaptive Application Controls manage application execution, and workflow automation is for triggered actions, neither directly enforces disk encryption or reports non-compliance in this manner.
  • D. JIT VM access is for reducing inbound port exposure, not disk encryption or automatic enforcement.

Azure Policy for Automated Disk Encryption

Azure Policy, particularly with 'DeployIfNotExists' and 'AuditIfNotExists' effects, can automate the enforcement of Azure Disk Encryption (ADE) on virtual machines and continuously audit for non-compliant resources within Microsoft Defender for Cloud.

  • Automates deployment of ADE for new and existing VMs.
  • Flags VMs that are not encrypted as non-compliant.
  • Integrates seamlessly with Microsoft Defender for Cloud recommendations.
  • Ensures consistent security posture for disk encryption.

Memory trick: Policy's power: Deploy and Audit, always encrypted.

More Mitigate threats using Microsoft Defender for Cloud questions