Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium

A security architect is designing a strategy to monitor and protect Azure Key Vaults across multiple subscriptions within their organization. They need to ensure that any suspicious activities, such as unusual access patterns or excessive secret retrieval attempts, are detected and alerted upon. Which Microsoft Defender for Cloud plan should be enabled to provide this specific protection for Azure Key Vaults?

  1. AMicrosoft Defender for Storage
  2. BMicrosoft Defender for Key Vault
  3. CMicrosoft Defender for SQL
  4. DMicrosoft Defender for Servers
Show answer & explanation

Correct answer: B. Microsoft Defender for Key Vault

Microsoft Defender for Key Vault is specifically designed to detect and alert on suspicious activities related to Azure Key Vaults, such as unusual access patterns or potential data exfiltration attempts.

Why the other options are wrong

  • A. Defender for Storage protects Azure storage accounts, not Key Vaults.
  • C. Defender for SQL protects Azure SQL databases and SQL Servers, not Key Vaults.
  • D. Defender for Servers protects virtual machines and physical servers, not Key Vaults.

Microsoft Defender for Key Vault

Microsoft Defender for Key Vault provides an additional layer of intelligence that detects unusual and potentially harmful attempts to access or exploit Key Vault accounts. It monitors for suspicious activities like unusual access patterns, excessive secret retrieval, or potential brute-force attacks.

  • Protects Azure Key Vaults.
  • Detects suspicious access patterns and key vault operations.
  • Generates security alerts for immediate investigation.

Memory trick: For the secrets in the vault, Defender for Key Vault calls a halt.

More Mitigate threats using Microsoft Defender for Cloud questions