Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is integrating an on-premises Linux server into Microsoft Defender for Cloud for security monitoring. The server needs to be assessed for security vulnerabilities, receive threat protection, and have its security posture continuously monitored. The organization uses Azure Arc for hybrid cloud management. Which agent should the engineer deploy on the Linux server to enable these Defender for Cloud capabilities?

  1. AAzure Security Agent
  2. BLog Analytics agent (MMA) only
  3. CAzure Connected Machine agent (Azure Arc agent) and Azure Monitor Agent (AMA)
  4. DAzure Connected Machine agent (Azure Arc agent) only
Show answer & explanation

Correct answer: C. Azure Connected Machine agent (Azure Arc agent) and Azure Monitor Agent (AMA)

To integrate an on-premises Linux server into Defender for Cloud via Azure Arc and enable comprehensive security capabilities (vulnerability assessment, threat protection, posture monitoring), both the Azure Connected Machine agent (for Arc connectivity) and the Azure Monitor Agent (AMA) are required. The Arc agent registers the server with Azure, and AMA collects security logs and data for Defender for Cloud.

Why the other options are wrong

  • A. There is no standalone 'Azure Security Agent' for this purpose; Defender for Cloud leverages existing Azure agents like AMA.
  • B. The Log Analytics agent (MMA) is being deprecated in favor of AMA. While MMA could collect some data, AMA is the recommended modern solution for Defender for Cloud.
  • D. The Azure Connected Machine agent connects the server to Azure Arc, but it doesn't collect the detailed security logs needed by Defender for Cloud for posture management and threat detection.

Azure Arc & Azure Monitor Agent for Hybrid Security

For on-premises servers to be fully integrated with Microsoft Defender for Cloud for security posture, vulnerability management, and threat protection, they require both the Azure Connected Machine agent (for Azure Arc onboarding) and the Azure Monitor Agent (AMA) for data collection.

  • Azure Arc agent connects non-Azure machines to Azure.
  • AMA collects logs and metrics, including security events.
  • Defender for Cloud uses AMA data for security insights and alerts.
  • MMA is being replaced by AMA.

Memory trick: Arc connects the house, AMA collects the security clues.

More Mitigate threats using Microsoft Defender for Cloud questions