Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is configuring Microsoft Defender for Cloud for an Azure subscription that hosts critical web applications. The engineer needs to ensure that all network traffic to and from the web application servers is continuously analyzed for malicious activity, including port scanning, brute-force attacks, and network-level exploits. This analysis must also extend to the DNS layer to detect suspicious domain requests. Which two Defender for Cloud plans should the engineer enable to meet these requirements?

  1. AMicrosoft Defender for SQL and Microsoft Defender for IoT
  2. BMicrosoft Defender for Servers and Microsoft Defender for Containers
  3. CMicrosoft Defender for Key Vault and Microsoft Defender for Storage
  4. DMicrosoft Defender for App Service and Microsoft Defender for DNS
Show answer & explanation

Correct answer: D. Microsoft Defender for App Service and Microsoft Defender for DNS

The scenario describes web application servers ('critical web applications') and the need for network traffic analysis for malicious activity, including brute-force attacks and network-level exploits, which are covered by Microsoft Defender for App Service. Additionally, the requirement for analysis 'to the DNS layer to detect suspicious domain requests' directly points to Microsoft Defender for DNS. Therefore, both plans are necessary.

Why the other options are wrong

  • A. Defender for SQL protects databases, and Defender for IoT protects IoT devices; neither is relevant to web app network traffic or DNS.
  • B. Defender for Servers protects VMs, and Defender for Containers protects containerized workloads; while web apps might run on these, the specific focus on 'web application servers' and 'DNS layer' makes App Service and DNS more targeted.
  • C. Key Vault protects secrets, and Storage protects storage accounts; neither directly addresses web app network traffic or DNS.

Defender for App Service & DNS

Microsoft Defender for App Service protects web applications from attacks targeting the web layer, while Microsoft Defender for DNS detects suspicious DNS queries and communications, together providing comprehensive network-level threat protection for web applications.

  • App Service protects against web-specific attacks (e.g., SQL injection, XSS).
  • DNS protects against domain-related threats (e.g., C2 callbacks, phishing).
  • Both contribute to network-level security visibility.

Memory trick: Web apps need App Service shield, and DNS needs its own guard.

More Mitigate threats using Microsoft Defender for Cloud questions