Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard
A company is using Microsoft Defender for Cloud to manage the security posture of its Azure environment. They have a strict policy requiring all critical Azure SQL Databases to have Transparent Data Encryption (TDE) enabled. Defender for Cloud identifies several databases where TDE is disabled. The security team wants to automatically remediate this finding without manual intervention. Which remediation type should they look for in Defender for Cloud for this specific recommendation?
- AManual remediation
- BQuick fix (deploy if not exists)
- CQuick fix (Logic App)
- DQuick fix (deny)
Show answer & explanationAnswer & explanation
Correct answer: B. Quick fix (deploy if not exists)
A 'Quick fix (deploy if not exists)' remediation action in Defender for Cloud, powered by Azure Policy, can automatically deploy or enable configurations like TDE on non-compliant resources, ensuring compliance without manual intervention. This is distinct from a Logic App which might be used for more complex, event-driven automations.
Why the other options are wrong
- A. Manual remediation requires human intervention, which contradicts the 'automatically remediate' requirement.
- C. A Quick fix (Logic App) would trigger a Logic App, which is for more complex, event-driven workflows. While it could achieve remediation, 'deploy if not exists' is a more direct and often simpler policy-driven approach for configuration enforcement.
- D. A Quick fix (deny) would prevent the deployment of non-compliant resources, but it wouldn't remediate existing ones by enabling TDE.
Defender for Cloud Quick Fix (Deploy If Not Exists)
A type of automated remediation action in Microsoft Defender for Cloud, powered by Azure Policy's 'deployIfNotExists' effect, that automatically deploys or configures resources to meet security recommendations when they are found to be non-compliant.
- Automatically enforces security configurations.
- Leverages Azure Policy definitions.
- Ideal for 'enable a setting' or 'deploy a resource' type recommendations.
- Reduces manual effort for common security baselines.
Memory trick: To automatically deploy a missing setting, 'deploy if not exists' is the best betting.