Implement Defender for Storage threat protection configurations (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for storage accounts
      --> Implement Defender for Storage threat protection configurations


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Microsoft Defender for Storage is a Microsoft Defender for Cloud workload protection service that helps detect and respond to threats targeting Azure Storage. It provides security coverage for supported Azure Blob Storage, Azure Data Lake Storage Gen2, and Azure Files workloads.

The current Defender for Storage plan provides three primary protection capabilities:

  1. Activity monitoring
  2. On-upload malware scanning
  3. Sensitive data threat detection

These capabilities complement, but do not replace:

  • Azure Storage firewall rules
  • Private endpoints
  • Microsoft Entra authentication
  • Azure RBAC
  • Encryption
  • Logging
  • Microsoft Purview
  • Azure Policy
  • Incident response processes

Defender for Storage is primarily a threat detection and data-protection service. It does not automatically make a storage account private, replace access controls, or guarantee that every malicious object will be detected.


What Defender for Storage Protects

Defender for Storage is designed to help protect data stored in supported storage services, including:

  • Azure Blob Storage
  • Azure Data Lake Storage Gen2
  • Azure Files
  • Supported storage account configurations and resource types

The exact capabilities available can vary by storage service, account type, region, subscription configuration, and enabled Defender plan.

For the SC-500 exam, focus on understanding what each protection capability does and when to enable or configure it.


The Three Main Protection Capabilities

1. Activity monitoring

Activity monitoring analyzes storage activity and helps identify suspicious behavior.

Examples of suspicious activity may include:

  • Unusual access patterns
  • Access from known malicious IP addresses
  • Access associated with Tor exit nodes
  • Suspicious authentication activity
  • Anomalous data access
  • Potential data exfiltration behavior
  • Unusual operations against storage resources

Activity monitoring is the foundational capability of Defender for Storage. It provides threat intelligence and behavioral analysis without requiring you to install an agent on the storage account.

What activity monitoring does not do

Activity monitoring does not:

  • Replace Azure RBAC
  • Block every unauthorized request
  • Encrypt data
  • Configure firewall rules
  • Scan every uploaded file for malware
  • Automatically delete suspicious data

It generates security information and alerts that security teams can investigate and respond to.


2. On-upload malware scanning

On-upload malware scanning automatically scans supported blobs when they are uploaded or modified.

This capability is especially useful when a storage account receives untrusted content from:

  • Customers
  • Vendors
  • External users
  • Public-facing applications
  • File-sharing applications
  • Collaboration platforms
  • Data ingestion pipelines

The objective is to identify malicious content before it is consumed by downstream applications.

For example, a web application may allow users to upload documents to Blob Storage. A malicious user could upload a file containing malware. On-upload malware scanning can inspect the uploaded blob and generate a scan result that the application or security team can use to determine whether the object should be made available.

On-upload malware scanning is an agentless service. You do not install or maintain an antivirus agent inside the storage account.


3. Sensitive data threat detection

Sensitive data threat detection uses sensitive data discovery to identify storage resources that contain sensitive information and provide additional context for security alerts.

This helps security teams prioritize an alert involving sensitive information over an otherwise similar alert involving non-sensitive data.

Examples of sensitive data may include:

  • Personally identifiable information
  • Financial information
  • Government identification numbers
  • Health-related information
  • Sensitive business records
  • Data associated with Microsoft Purview sensitivity labels
  • Files containing supported sensitive information types

Sensitive data threat detection is not the same as malware scanning.

CapabilityPrimary purpose
Activity monitoringDetect suspicious storage activity
Malware scanningIdentify malicious uploaded content
Sensitive data threat detectionIdentify whether data involved in an alert is sensitive

Sensitive data discovery uses an agentless scanning engine and can integrate with Microsoft Purview sensitivity settings, including supported sensitive information types and classification labels.


Understanding the New Defender for Storage Plan

The current Defender for Storage plan provides configurable protection capabilities beyond basic activity monitoring.

The full plan can include:

  • Activity monitoring
  • On-upload malware scanning
  • Sensitive data threat detection

A basic Defender for Storage policy may enable only activity monitoring. To enable the full set of capabilities, use the policy or configuration that enables Defender for Storage with malware scanning and sensitive data threat detection.

This distinction is important in exam questions. If a scenario requires malware scanning or sensitive data discovery, enabling only the basic activity-monitoring configuration is insufficient.


Enabling Defender for Storage

Defender for Storage can be enabled at different scopes.

Subscription-level enablement

Subscription-level enablement applies Defender for Storage to storage accounts within the subscription according to the plan configuration.

This is useful when:

  • Most or all storage accounts require protection
  • Security requirements apply consistently across the subscription
  • The organization wants centralized management
  • New storage accounts should receive protection automatically
  • The organization wants to use Azure Policy for deployment at scale

Subscription-level enablement is generally preferred for standardized enterprise security.

Storage-account-level enablement

You can also enable Defender for Storage for an individual storage account.

This is useful when:

  • Testing the service
  • Protecting a particularly sensitive storage account
  • Applying different settings to a specific workload
  • Overriding subscription-level configuration
  • Enabling protection during a phased rollout

Portal configuration

A typical portal workflow is:

  1. Open the Azure portal.
  2. Navigate to Microsoft Defender for Cloud.
  3. Open Environment settings.
  4. Select the subscription.
  5. Open Defender plans.
  6. Locate Storage.
  7. Enable the Defender for Storage plan.
  8. Save the configuration.

To configure an individual storage account:

  1. Open the storage account.
  2. Select Microsoft Defender for Cloud under the security settings.
  3. Enable Defender for Storage on the account.
  4. Review the malware scanning and sensitive data threat detection settings.
  5. Configure any required advanced settings.
  6. Save the changes.

The portal provides options to enable or disable on-upload malware scanning and sensitive data threat detection, configure malware scanning limits, configure scan-result storage, and configure notification destinations.


Configuring On-Upload Malware Scanning

Why malware scanning is important

Storage accounts frequently receive files from sources that cannot be fully trusted.

Examples include:

  • Customer-uploaded documents
  • Images uploaded by users
  • Attachments submitted through a web application
  • Files received from external partners
  • Documents imported from another environment
  • Data uploaded by automated processes

A malicious file can create risk when it is:

  • Downloaded by another user
  • Processed by an application
  • Extracted by a data pipeline
  • Indexed by a search service
  • Passed to an AI model
  • Copied to another storage account
  • Executed by a downstream system

On-upload scanning provides an additional security inspection point before the content is used by other systems.


Scan results

Malware scanning can provide scan results through several mechanisms.

Blob index tags

Scan results can be stored as blob index tags.

These tags allow applications to inspect the scanning status or result associated with a blob.

For example, an application could use a scanning result to determine whether a file should be:

  • Published
  • Quarantined
  • Moved to another container
  • Rejected
  • Submitted for investigation

Blob index tags are useful when the application needs to query or inspect scan results directly.

Event Grid

Malware scanning results can be sent to an Azure Event Grid custom topic.

Event Grid is useful for near-real-time response automation.

A possible workflow is:

  1. A user uploads a blob.
  2. Defender for Storage scans the blob.
  3. A scan result is generated.
  4. The result is published to Event Grid.
  5. An event-driven process evaluates the result.
  6. A Logic App, Function, or other automation process quarantines or moves the file.
  7. The security team is notified if the file is malicious.

Event Grid is generally the best choice when the requirement emphasizes:

  • Near-real-time processing
  • Event-driven automation
  • Automatic quarantine
  • Automatic remediation
  • Immediate downstream action

Log Analytics

Malware scanning results can also be sent to a Log Analytics workspace.

Log Analytics is useful when the requirement emphasizes:

  • Centralized logging
  • Compliance
  • Auditing
  • Historical investigation
  • Cross-resource queries
  • Security analytics
  • Correlation with Microsoft Sentinel

Log Analytics is not necessarily the best mechanism for immediate per-file remediation, although automation can be built around logged results.

Event Grid versus Log Analytics

RequirementPreferred destination
Trigger immediate automated responseEvent Grid
Store every scan result centrallyLog Analytics
Investigate historical scan resultsLog Analytics
Integrate scan results with event-driven workflowsEvent Grid
Support compliance and audit reportingLog Analytics

Defender for Storage supports sending malware scan results to Event Grid for near-real-time response and Log Analytics for centralized storage, compliance, and audit purposes.


Malware Scanning Cost Controls

Malware scanning is priced according to the amount of data scanned. Therefore, organizations should configure cost controls.

A key setting is the monthly GB scanning cap per storage account.

This setting limits the amount of data that can be scanned for malware during a month for each storage account.

Why a cap matters

Without a suitable cap, a storage account that receives a large volume of uploaded data could generate unexpected scanning costs.

A cap can help the organization:

  • Control costs
  • Prevent unexpected consumption
  • Establish a predictable security budget
  • Identify unusually high upload activity
  • Apply different scanning limits to different workloads

Important distinction

A scanning cap is a cost-control setting, not a security allowlist.

It does not specify which files are trusted. It limits the amount of data that can be scanned.

The default cap and the supported value for unlimited scanning can change as the service evolves. Current configuration documentation identifies -1 as the value for unlimited scanning in supported configuration interfaces, while the default limit may vary by configuration and documentation version. Always verify the current service behavior before implementing production settings.


Malware Scanning Filters

Advanced malware scanning settings can be used to reduce unnecessary scanning or tailor scanning to the workload.

Depending on the supported configuration, filters can be used to control scanning based on characteristics such as:

  • Container
  • Blob type
  • Object size
  • Other supported object-selection criteria

Filters can help organizations focus scanning on the content that creates the greatest risk or business value.

For example:

  • Scan all customer-upload containers.
  • Exclude a trusted internal backup container.
  • Scan only supported blob types.
  • Avoid scanning objects that exceed the configured size limit.
  • Apply different settings to different storage accounts.

Exam consideration

Filtering should be used carefully. Excluding content from scanning creates a protection gap. The decision should be based on a documented risk assessment rather than convenience alone.


Soft Deletion of Malicious Blobs

Defender for Storage can support soft deletion of malicious blobs when configured.

Soft deletion can help preserve a malicious object for investigation while preventing it from being immediately available in its original location.

This can be useful for:

  • Incident investigation
  • Evidence preservation
  • Malware analysis
  • Recovery
  • Auditing
  • Preventing immediate consumption of malicious content

Soft deletion should not be confused with permanent deletion. A soft-deleted blob may remain recoverable according to the applicable retention configuration.

Important distinction

Soft deletion is a response and recovery feature. It is not a substitute for:

  • Malware scanning
  • Access control
  • Network security
  • Secure application processing
  • Data classification

Sensitive Data Threat Detection Configuration

How sensitive data discovery works

Sensitive data threat detection uses an agentless sensitive data discovery engine.

The engine uses smart sampling to identify resources that contain sensitive data. It can integrate with Microsoft Purview sensitivity settings, including supported:

  • Sensitive information types
  • Sensitivity labels
  • Organizational classification settings

When a security alert involves a resource containing sensitive data, the alert can include additional context to help security teams prioritize the incident.

Examples of alert context may include:

  • The most sensitive label found in a container
  • Sensitive information types detected
  • Sensitive file types
  • The time of the latest sensitivity scan
  • Whether custom rules were involved

Sensitive data threat detection is intended to improve alert prioritization and investigation. It is not a replacement for Microsoft Purview data governance or data loss prevention policies.


Supported storage scenarios

Sensitive data threat detection is available for supported storage configurations, including:

  • Standard general-purpose v1 storage accounts
  • Standard general-purpose v2 storage accounts
  • Azure Data Lake Storage Gen2
  • Premium block blob accounts

Support for Azure Files and other configurations may depend on additional requirements, such as Defender CSPM availability and the supported service configuration.

For exam purposes, do not assume that every storage type has identical feature support. Verify the storage service and plan requirements when a question includes a specific account type.


Scan timing

Sensitive data discovery is not necessarily instantaneous.

After enablement:

  • Initial results may take time to become available.
  • Newly created protected storage accounts may be scanned on a different schedule.
  • Recurring scans may occur periodically.

Current service documentation indicates that initial results are typically generated within approximately 24 hours, newly created protected accounts may be scanned within approximately six hours, and recurring scans may occur weekly. These timeframes are service behaviors rather than guarantees for an immediate response.

Exam trap

If a question asks for immediate malware detection on upload, choose on-upload malware scanning, not sensitive data threat detection.

Sensitive data discovery is intended to classify and provide sensitivity context. It is not an immediate antivirus inspection mechanism.


Microsoft Purview Integration

Defender for Storage sensitive data threat detection can use supported Microsoft Purview sensitivity information.

This helps align storage threat detection with organizational data classification.

For example, an organization may use Microsoft Purview to classify data as:

  • Public
  • General
  • Confidential
  • Highly Confidential

When an alert involves a container containing highly sensitive data, Defender for Storage can provide that context to security personnel.

Benefits

Purview integration can help organizations:

  • Prioritize incidents involving sensitive data
  • Align security alerts with data classification
  • Identify the potential business impact of an incident
  • Improve incident triage
  • Support compliance investigations

Important distinction

Microsoft Purview classifies and governs data. Defender for Storage detects threats and adds sensitivity context to security alerts.

They serve related but different purposes.


Configuring Defender for Storage at Scale with Azure Policy

Azure Policy can be used to deploy and enforce Defender for Storage configuration across a subscription or management group.

A built-in policy can enable Defender for Storage automatically for applicable storage accounts.

This is useful for:

  • Enterprise-wide security baselines
  • Regulatory requirements
  • Standardized deployments
  • Preventing newly created storage accounts from remaining unprotected
  • Infrastructure governance
  • Continuous compliance

Policy-driven deployment

A typical approach is:

  1. Open Azure Policy.
  2. Search for the Defender for Storage enablement policy.
  3. Select the policy definition.
  4. Assign it to the appropriate subscription or management group.
  5. Configure the assignment parameters.
  6. Review the managed identity permissions.
  7. Create the assignment.
  8. Monitor compliance results.
  9. Remediate noncompliant resources.

The built-in policy named Configure Microsoft Defender for Storage to be enabled enables the full Defender for Storage capabilities, including activity monitoring, malware scanning, and sensitive data threat detection.

A separate basic policy enables activity monitoring only.

Why Azure Policy is valuable

Without policy enforcement, an administrator may enable Defender for Storage on existing accounts but forget to protect new accounts.

A policy-based deployment can help ensure that protection is applied consistently as resources are created.


Subscription Settings and Account Overrides

Subscription-level settings provide centralized configuration. However, a storage account may require different settings from the subscription default.

For example:

  • Most storage accounts use a 10,000 GB monthly scan cap.
  • One high-volume ingestion account requires a different cap.
  • A development account does not need sensitive data discovery.
  • A high-risk customer-upload account requires more restrictive scanning settings.

To configure account-specific settings, use the storage account’s Defender for Storage settings and enable the option to override subscription-level settings where supported.

Important exam distinction

If a question asks you to configure one storage account differently from the subscription default, look for an account-level override rather than changing the entire subscription configuration.


Defender for Storage Alerts

Defender for Storage can generate security alerts when it identifies suspicious activity or malicious content.

Examples include:

  • Malicious file uploaded to a storage account
  • Suspicious access patterns
  • Access from known malicious sources
  • Potential data exfiltration
  • Unusual authentication behavior
  • Activity involving sensitive data

Alerts can be investigated in Microsoft Defender for Cloud and may be integrated with Microsoft Sentinel or other security operations workflows.

Alert routing

A complete alerting design should consider:

  • Who receives the alert
  • How alerts are prioritized
  • Whether sensitive data is involved
  • Whether automated remediation is appropriate
  • Where logs are retained
  • How incidents are tracked
  • Whether alerts are forwarded to a SIEM

Defender for Storage detection is most effective when connected to a broader incident-response process.


Testing Defender for Storage

A security team should validate that Defender for Storage is configured correctly.

Testing can include:

  1. Enable Defender for Storage on a test storage account.
  2. Enable the required capabilities.
  3. Upload a controlled test file for malware-scanning validation.
  4. Review the generated scan result or alert.
  5. Confirm that the result is available through the configured destination.
  6. Verify that sensitive data discovery produces expected sensitivity context.
  7. Confirm that activity monitoring detects test activity where applicable.
  8. Validate Event Grid or Log Analytics integration.
  9. Confirm that security personnel can investigate the resulting alert.

Testing should be performed in a controlled environment and should not involve uploading real malicious software into a production account.


Defender for Storage and AI Workloads

Storage accounts often support AI workloads by holding:

  • Training data
  • Documents for retrieval-augmented generation
  • User-uploaded files
  • Prompt attachments
  • Vectorization input
  • Model evaluation data
  • Generated content
  • Logs and audit records

Defender for Storage is particularly relevant when AI applications accept files from users or external sources.

A secure AI ingestion workflow may include:

  1. User uploads a document to a quarantine container.
  2. Defender for Storage scans the uploaded blob.
  3. The scan result is delivered through Event Grid or stored as a blob index tag.
  4. An application checks the scan result.
  5. Malicious or suspicious content is quarantined or deleted.
  6. Only approved content is copied to the AI processing container.
  7. Microsoft Purview or sensitive data discovery provides classification context.
  8. Managed identities and RBAC control which services can read the data.

Important limitation

Malware scanning does not guarantee that a document is safe for an AI model.

A file may be free of traditional malware but still contain:

  • Prompt injection instructions
  • Sensitive information
  • Malicious URLs
  • Data poisoning content
  • Inappropriate content
  • Confidential information that should not be indexed

AI-specific guardrails, content filtering, data governance, and application-level validation are still required.


Defender for Storage versus Other Controls

ControlMain purpose
Storage firewallRestrict network sources
Private endpointProvide private network connectivity
Azure RBACAuthorize identities to access data or resources
EncryptionProtect data confidentiality at rest or in transit
Defender for StorageDetect storage threats and scan supported content
Microsoft PurviewClassify, govern, and protect data
Azure PolicyEnforce configuration standards
Microsoft SentinelCentralize and correlate security events
Event GridDeliver events for automated response
Log AnalyticsStore and query logs and scan results

A common exam scenario requires several controls together. For example:

  • Private endpoint for network isolation
  • Managed identity for authentication
  • Azure RBAC for data authorization
  • Defender for Storage for threat detection
  • Event Grid for automated response
  • Microsoft Sentinel for investigation

Common Exam Traps

Trap 1: Confusing activity monitoring with malware scanning

Activity monitoring detects suspicious access and behavior. It does not automatically scan every uploaded file.

Correct choice: Enable on-upload malware scanning when the requirement is to inspect uploaded content.

Trap 2: Assuming Defender for Storage blocks all threats automatically

Defender for Storage detects threats and produces alerts or scan results. Automated blocking or quarantine requires appropriate configuration and application logic.

Correct choice: Configure scan-result handling, Event Grid, or remediation workflows when automatic action is required.

Trap 3: Choosing Log Analytics for immediate event-driven response

Log Analytics is useful for centralized storage, querying, auditing, and investigation.

Correct choice: Use Event Grid when the requirement emphasizes near-real-time automated response to each scan result.

Trap 4: Choosing Event Grid for long-term audit storage

Event Grid is designed for event delivery, not long-term centralized log retention.

Correct choice: Use Log Analytics for centralized scan-result storage and investigation.

Trap 5: Confusing sensitive data discovery with malware scanning

Sensitive data discovery identifies sensitive information and adds context to alerts. It is not an antivirus service.

Correct choice: Use on-upload malware scanning for malicious-file detection.

Trap 6: Assuming sensitive data results are immediate

Sensitive data discovery may take hours and recurring scans may be periodic.

Correct choice: Do not use sensitive data discovery when the requirement is immediate inspection during upload.

Trap 7: Enabling only the basic Defender for Storage policy

The basic policy may enable activity monitoring only.

Correct choice: Use the full Defender for Storage policy when malware scanning and sensitive data threat detection are required.

Trap 8: Ignoring scanning costs

Malware scanning consumes billable scanning capacity.

Correct choice: Configure a monthly GB scanning cap and monitor usage.

Trap 9: Assuming a scan result grants or denies access

A scan result is information that an application or workflow must use.

Correct choice: Implement application logic or automation to quarantine, reject, or move malicious content.

Trap 10: Assuming Defender for Storage replaces access controls

Defender for Storage does not replace:

  • Firewalls
  • Private endpoints
  • RBAC
  • Encryption
  • Secure application design

Correct choice: Use Defender for Storage as one layer in a defense-in-depth design.


Recommended Configuration Pattern

For a storage account receiving untrusted documents, consider the following design:

  1. Use a private endpoint when practical.
  2. Disable public network access if all clients can use private connectivity.
  3. Use managed identities and Microsoft Entra ID.
  4. Assign least-privilege Storage data roles.
  5. Enable Defender for Storage.
  6. Enable on-upload malware scanning.
  7. Configure a monthly scanning cap.
  8. Store scan results as blob index tags when the application needs to inspect them.
  9. Send scan results to Event Grid for near-real-time automated response.
  10. Send scan results to Log Analytics for centralized investigation and audit.
  11. Configure soft deletion or quarantine handling for malicious blobs.
  12. Enable sensitive data threat detection for sensitive workloads.
  13. Integrate supported classification information from Microsoft Purview.
  14. Use Azure Policy to enforce Defender for Storage across subscriptions.
  15. Connect relevant alerts to Microsoft Sentinel.
  16. Test the complete detection and response workflow.

Exam Summary

Remember these key points:

  • Defender for Storage provides activity monitoring, malware scanning, and sensitive data threat detection.
  • Activity monitoring detects suspicious storage activity.
  • On-upload malware scanning inspects supported blobs when uploaded or modified.
  • Sensitive data threat detection adds sensitivity context to security alerts.
  • Malware scanning is useful for untrusted uploaded content.
  • Event Grid is appropriate for near-real-time automated response.
  • Log Analytics is appropriate for centralized scan-result storage, auditing, and investigation.
  • Malware scanning has configurable cost controls, including a monthly GB cap.
  • Scan results can be stored as blob index tags.
  • Sensitive data discovery integrates with supported Microsoft Purview classification settings.
  • Sensitive data discovery is not an antivirus replacement and is not necessarily immediate.
  • Azure Policy can enable Defender for Storage at scale.
  • The full Defender for Storage policy enables more capabilities than the basic activity-monitoring policy.
  • Account-level overrides can apply different settings to an individual storage account.
  • Defender for Storage does not replace firewall rules, private endpoints, RBAC, encryption, or application security.
  • A scan result does not automatically grant or deny data access; remediation must be configured.

Practice Exam Questions

Question 1

A company operates a public web application that allows customers to upload documents to Azure Blob Storage. The security team wants every uploaded blob inspected for malware before downstream applications process it.

Which Defender for Storage capability should be enabled?

A. Sensitive data threat detection
B. Activity monitoring
C. On-upload malware scanning
D. Azure Policy compliance evaluation

Correct Answer: C

Explanation

On-upload malware scanning is designed to inspect supported blobs when they are uploaded or modified.

Activity monitoring analyzes suspicious activity but is not an antivirus scan. Sensitive data threat detection identifies sensitive information and adds context to alerts. Azure Policy enforces configuration and does not scan files.


Question 2

A security team wants every malware scan result stored centrally so analysts can query historical results and correlate them with other security events.

Which destination should be configured?

A. Log Analytics workspace
B. Azure Event Grid custom topic
C. Blob index tags only
D. Azure Storage firewall rules

Correct Answer: A

Explanation

Log Analytics is appropriate for centralized storage, querying, auditing, and historical investigation of scan results.

Event Grid is better suited to near-real-time event-driven response. Blob index tags can help an application inspect an individual blob’s result but are not a centralized security analytics repository.


Question 3

An organization wants a malicious blob to trigger an automated workflow that moves the blob to a quarantine container immediately after the scan result is generated.

What should the organization configure?

A. Microsoft Purview sensitivity labels only
B. Azure Event Grid integration with an automated response workflow
C. A storage account resource lock
D. A private endpoint for the storage account

Correct Answer: B

Explanation

Event Grid can deliver malware scan results to an event-driven workflow. The workflow can then move, quarantine, delete, or otherwise process the malicious blob.

Purview provides classification context, a resource lock protects resource management operations, and a private endpoint controls network connectivity. None of these directly provides event-driven malware remediation.


Question 4

A storage account contains confidential employee records. The security team wants storage alerts to indicate whether the affected container contains sensitive information so analysts can prioritize the incident.

Which capability should be enabled?

A. On-upload malware scanning
B. Activity monitoring only
C. Sensitive data threat detection
D. Storage firewall IP rules

Correct Answer: C

Explanation

Sensitive data threat detection uses sensitive data discovery to identify sensitive information and provide additional context in security alerts.

Malware scanning detects malicious content. Activity monitoring detects suspicious activity but does not provide the same sensitivity classification context. Firewall rules restrict network access.


Question 5

An organization assigns the basic Defender for Storage policy to a subscription. Later, the security team discovers that uploaded blobs are not being scanned for malware.

What is the most likely explanation?

A. The storage account must use a private endpoint before malware scanning works
B. The basic policy enables activity monitoring only
C. Malware scanning is provided only by Microsoft Purview
D. Azure Storage firewall rules must be disabled

Correct Answer: B

Explanation

The basic Defender for Storage policy enables activity monitoring only. Malware scanning and sensitive data threat detection require the full Defender for Storage configuration.

The network configuration does not determine whether the Defender malware-scanning feature is enabled.


Question 6

A company wants to prevent unexpected malware-scanning costs on a high-volume storage account.

Which setting should be configured?

A. Monthly GB scanning cap per storage account
B. Storage account deletion lock
C. Public network access setting
D. Microsoft Entra Conditional Access policy

Correct Answer: A

Explanation

The monthly GB scanning cap limits the amount of data scanned for malware per storage account during a month.

A deletion lock protects resource management operations. Public network access controls connectivity. Conditional Access controls identity access and does not control malware-scanning consumption.


Question 7

A security engineer needs to configure a storage account differently from the subscription-level Defender for Storage settings. The account requires a different malware-scanning cap.

What should the engineer use?

A. A storage account-level configuration override
B. A network security group rule
C. A Microsoft Purview retention label
D. A storage account access key

Correct Answer: A

Explanation

An account-level override allows a specific storage account to use settings different from the subscription-level defaults, where supported.

A network security group does not configure Defender for Storage. Purview retention labels manage data governance, and an access key is an authentication credential.


Question 8

A security team wants to use Microsoft Purview classification information to improve the prioritization of Defender for Storage alerts.

Which capability supports this requirement?

A. Activity monitoring
B. Sensitive data threat detection
C. On-upload malware scanning
D. Azure Storage firewall rules

Correct Answer: B

Explanation

Sensitive data threat detection can use supported Microsoft Purview sensitivity information, including sensitive information types and classification labels, to provide sensitivity context in alerts.

The other options address suspicious activity, malicious content, or network access rather than data classification.


Question 9

A security analyst wants to determine whether a malicious file was uploaded to a storage account and investigate the event in Microsoft Defender for Cloud.

Which Defender for Storage capability is most directly relevant?

A. On-upload malware scanning
B. Azure Policy
C. Private Link
D. Storage encryption

Correct Answer: A

Explanation

On-upload malware scanning is designed to detect malicious content in supported uploaded blobs and generate scan results or alerts.

Azure Policy enforces configuration. Private Link provides private connectivity. Encryption protects data confidentiality but does not detect malware.


Question 10

A company enables Defender for Storage but wants to ensure that malicious files are not automatically made available to an AI document-processing pipeline.

Which additional design is most appropriate?

A. Rely only on activity-monitoring alerts
B. Use Event Grid or scan-result tags to implement quarantine and approval logic
C. Disable all storage firewall rules
D. Grant the AI application Storage Blob Data Owner permissions

Correct Answer: B

Explanation

Defender for Storage provides scan results, but the application or an automated workflow must use those results to quarantine, reject, or move malicious content.

Event Grid supports near-real-time automation, while blob index tags can allow an application to inspect scan results. Granting excessive permissions would increase risk, and disabling firewall rules would weaken security.


Final Review Checklist

Before considering Defender for Storage properly configured, verify:

  • Is Defender for Storage enabled at the appropriate scope?
  • Is the full plan enabled if malware scanning and sensitive data threat detection are required?
  • Is on-upload malware scanning enabled for untrusted content?
  • Is a monthly scanning cap configured?
  • Are scan-result filters appropriate for the workload?
  • Are scan results stored as blob index tags when needed?
  • Are Event Grid notifications configured for automated response?
  • Are Log Analytics destinations configured for audit and investigation?
  • Is malicious-content quarantine or soft deletion configured where appropriate?
  • Is sensitive data threat detection enabled for sensitive workloads?
  • Are supported Microsoft Purview classification settings integrated?
  • Are subscription-level and account-level settings understood?
  • Is Azure Policy used to enforce protection at scale?
  • Are Defender alerts connected to the organization’s incident-response process?
  • Has the complete detection and remediation workflow been tested?

Go to the SC-500 Exam Prep Hub main page

Leave a Reply