Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is investigating a series of alerts in Microsoft Defender for Cloud related to suspicious network activity originating from several Azure virtual machines. The alerts indicate attempts to communicate with known malicious IP addresses. The engineer needs to quickly block outbound communication from these compromised VMs to the identified malicious IPs without manual intervention for each new alert. Which Defender for Cloud capability, integrated with Azure networking, should be configured?

  1. ANetwork access hardening (Adaptive Network Hardening)
  2. BSecurity alerts and incidents
  3. CJust-in-Time (JIT) VM access
  4. DAdaptive application controls
Show answer & explanation

Correct answer: A. Network access hardening (Adaptive Network Hardening)

Adaptive Network Hardening (part of Network access hardening) in Microsoft Defender for Cloud uses machine learning to analyze network traffic patterns and provide recommendations for tightening Network Security Group (NSG) rules. It can also automatically apply recommended rules or integrate with workflow automation to block suspicious outbound traffic identified by Defender for Cloud alerts.

Why the other options are wrong

  • B. Security alerts and incidents provide notifications but do not, by themselves, automatically block network traffic without further automation or configuration.
  • C. JIT VM access focuses on inbound port access reduction, not outbound threat blocking.
  • D. Adaptive application controls manage application execution on VMs, not network traffic.

Adaptive Network Hardening

Adaptive Network Hardening in Microsoft Defender for Cloud provides recommendations and automated enforcement for Network Security Group (NSG) rules based on actual network traffic patterns, helping to restrict network access to only necessary ports and protocols.

  • Uses machine learning to analyze traffic patterns.
  • Recommends NSG rules to tighten network security.
  • Can automatically apply recommended rules (requires auto-remediation).
  • Helps reduce the network attack surface and prevent lateral movement.

Memory trick: Harden's hand: Learns traffic, limits threats, locks down ports.

More Mitigate threats using Microsoft Defender for Cloud questions