Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudEasy
A security engineer is configuring threat protection for an Azure subscription in Microsoft Defender for Cloud. The organization has multiple Azure Storage accounts, including Blob storage for backups, File shares for internal documents, and Queue storage for application messaging. The engineer wants to ensure that all these storage types are protected from malware uploads, suspicious access patterns, and data exfiltration attempts. Which Defender for Cloud plan should be enabled at the subscription level to cover all these storage services comprehensively?
- AMicrosoft Defender for Servers
- BMicrosoft Defender for Key Vault
- CMicrosoft Defender for Storage
- DMicrosoft Defender for SQL
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Defender for Storage
Microsoft Defender for Storage provides comprehensive protection for all types of Azure Storage accounts (Blob, File, Queue, Table) against malware, suspicious access, and data exfiltration by analyzing data plane and control plane operations.
Why the other options are wrong
- A. Defender for Servers protects virtual machines and physical servers, not storage accounts.
- B. Defender for Key Vault protects Azure Key Vaults, not storage accounts.
- D. Defender for SQL protects Azure SQL Databases and SQL Servers, not general storage accounts.
Microsoft Defender for Storage
Microsoft Defender for Storage provides advanced threat protection for Azure Storage accounts, detecting malware uploads, suspicious access activities, and data exfiltration attempts across Blob, File, Queue, and Table storage.
- Covers all major Azure Storage services automatically.
- Analyzes data and control plane operations.
- Detects malware using hash reputation and deep learning.
- Helps prevent data exfiltration and unauthorized access.
Memory trick: Storage's Shield: All data types, always guarded.