Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium
A security analyst is investigating a high-severity alert in Microsoft Defender for Cloud indicating 'Suspicious activity detected in an Azure Storage account'. The alert details show numerous failed authentication attempts from various IP addresses, followed by a successful authentication from one of those IP addresses. The storage account is configured for public access. Which Defender for Cloud capability directly contributed to detecting this specific pattern of attack?
- AMicrosoft Defender for DNS
- BMicrosoft Defender for Key Vault
- CMicrosoft Defender for App Service
- DMicrosoft Defender for Storage
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Defender for Storage
The alert specifically mentions 'Suspicious activity detected in an Azure Storage account' and describes an attack pattern targeting storage. Microsoft Defender for Storage is designed to detect such threats, including suspicious access patterns, malware uploads, and data exfiltration from Azure Storage accounts.
Why the other options are wrong
- A. Defender for DNS detects suspicious DNS queries, which is unrelated to storage access attempts.
- B. Defender for Key Vault protects Azure Key Vaults, not storage accounts.
- C. Defender for App Service protects Azure App Service resources, not storage accounts.
Microsoft Defender for Storage
A Microsoft Defender for Cloud plan that provides an additional layer of security intelligence that detects unusual and potentially harmful attempts to access or exploit Azure Storage accounts.
- Monitors Azure Blob, File, and Data Lake Storage.
- Detects malware uploads, suspicious access, and data exfiltration.
- Integrates with Defender for Cloud alerts and recommendations.
Memory trick: Each Defender plan protects its own Azure domain.