A security engineer is investigating a series of alerts in Microsoft Defender for Cloud related to suspicious network activity originating from several Azure virtual machines. The alerts indicate potential command and control (C2) communication. The engineer needs to quickly determine which outbound network connections are allowed from these VMs and identify any unexpected open ports that could be facilitating this communication. Which Microsoft Defender for Cloud capability, leveraging machine learning, provides recommendations to restrict unnecessary network access based on actual traffic patterns?
- ANetwork Security Group (NSG) flow logs
- BJust-in-Time (JIT) VM Access
- CAzure Firewall Manager
- DAdaptive Network Hardening
Show answer & explanationAnswer & explanation
Correct answer: D. Adaptive Network Hardening
Adaptive Network Hardening uses machine learning to analyze actual network traffic flows and existing NSG rules. It then provides recommendations to further restrict inbound and outbound network access, ensuring only necessary ports and protocols are open, which is ideal for identifying and closing unexpected open ports facilitating C2 communication.
Why the other options are wrong
- A. NSG flow logs provide raw traffic data but don't automatically generate recommendations for hardening based on machine learning.
- B. JIT VM Access is for controlling inbound management port access on demand, not for analyzing general network traffic patterns for hardening.
- C. Azure Firewall Manager centrally manages Azure Firewalls but doesn't provide machine learning-driven recommendations for individual VM NSGs based on traffic patterns like Adaptive Network Hardening.
Adaptive Network Hardening
Adaptive Network Hardening in Microsoft Defender for Cloud uses machine learning to analyze network traffic patterns and existing NSG rules to provide recommendations for more restrictive NSG rules, reducing the network attack surface by ensuring only necessary ports and protocols are open.
- Uses machine learning to analyze actual traffic.
- Recommends granular NSG rules (inbound/outbound).
- Reduces network attack surface and helps identify suspicious open ports.
Memory trick: Adaptive hardening, smart rules it weaves, based on the traffic, what it perceives.