Monitor AI security by using the Data and AI security dashboard in Defender for Cloud (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for AI
      --> Monitor AI security by using the Data and AI security dashboard in Defender for Cloud


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Artificial intelligence workloads introduce security risks that are different from those associated with traditional applications. AI systems may process sensitive data, use external tools, connect to storage and search services, expose model endpoints, and depend on containers, libraries, identities, and infrastructure-as-code configurations.

Microsoft Defender for Cloud provides capabilities for discovering AI workloads, assessing their security posture, detecting threats, and investigating security issues. The Data and AI security dashboard provides a centralized view of data and AI resources, their protection coverage, security recommendations, alerts, attack paths, and internet exposure.

For the SC-500 exam, the key concept is that the dashboard helps security teams answer three questions:

  1. What data and AI resources exist in the environment?
  2. What security risks or protection gaps affect those resources?
  3. What actions should be taken to reduce the risks?

The dashboard combines information from Defender for Cloud capabilities such as Cloud Security Posture Management, sensitive data discovery, Defender for Storage, Defender for Databases, and AI threat protection.


What Is the Data and AI Security Dashboard?

The Data and AI security dashboard is a centralized monitoring experience in Microsoft Defender for Cloud. It provides visibility into an organization’s data and AI estate and helps security teams identify resources that require attention.

The dashboard can display information about:

  • Storage resources
  • Managed databases
  • Hosted databases, including databases hosted on infrastructure
  • AI services and AI workloads
  • Sensitive data
  • Security recommendations
  • Security alerts
  • Attack paths
  • Internet-exposed resources
  • Protection coverage
  • AI threat detection activity

The dashboard is intended to support both proactive and reactive security activities:

  • Proactive security: Identify misconfigurations, exposed resources, missing protection, and potential attack paths.
  • Reactive security: Investigate alerts, identify affected resources, and respond to detected threats.

It is important to understand that the dashboard is not itself a replacement for all security controls. Instead, it provides a consolidated view of information collected by Defender for Cloud and related security services.


Relationship to AI Security Posture Management

Microsoft Defender for Cloud includes AI security posture management, which helps organizations discover AI workloads and identify security risks throughout the AI lifecycle.

AI security posture management can help identify:

  • AI applications and services
  • AI models and model deployments
  • Vulnerable AI-related libraries
  • Infrastructure-as-code misconfigurations
  • Internet-exposed AI endpoints
  • Weak or excessive identity permissions
  • Risks involving data used for grounding or fine-tuning
  • Potential attack paths involving AI resources

Defender for Cloud can discover AI workloads across supported environments and services, including Azure AI services, Azure AI Foundry, Azure Machine Learning, Amazon Bedrock, and Google Vertex AI.

The dashboard provides a practical way to review these findings without having to examine every AI resource independently.

AI security posture management versus AI threat protection

These capabilities address different security questions.

CapabilityPrimary purpose
AI security posture managementIdentify configuration weaknesses, vulnerabilities, exposure, and security gaps
AI threat protectionDetect suspicious or malicious activity targeting AI workloads
Data and AI security dashboardPresent data and AI inventory, posture findings, protection coverage, and threat information in one view

For example:

  • A publicly accessible AI endpoint is primarily a posture concern.
  • A suspicious sequence of prompts targeting an AI service may be a runtime threat concern.
  • The dashboard can help security personnel see both types of information together.

Prerequisites for the Dashboard

The exact information displayed depends on the Defender for Cloud plans and capabilities enabled in the subscription.

For full access to the dashboard’s data and AI capabilities, Microsoft documentation identifies the following requirements:

  • Defender CSPM
  • The Defender CSPM sensitive data discovery extension
  • Defender for Storage
  • Defender for Databases
  • AI workload threat protection
  • Registration of each relevant Azure subscription with the Microsoft.Security resource provider

Access also requires appropriate permissions to read assessments, subassessments, and alerts. The documented minimum privileged role for the dashboard is the Security reader role.

Why plan enablement matters

If a protection plan is not enabled, the dashboard may show incomplete protection coverage or may not provide certain findings.

For example:

  • Without sensitive data discovery, sensitive information findings may be unavailable.
  • Without Defender for Storage, storage threat protection information may be incomplete.
  • Without Defender for Databases, database-related protection information may be unavailable.
  • Without AI threat protection, AI prompt scanning and AI threat alerts may not be displayed.

The dashboard should therefore be interpreted in the context of the plans enabled for the subscription.


Data and AI Security Overview

The Data and AI security overview section provides a high-level view of the organization’s data and AI resources.

Resources may be categorized into areas such as:

  • Storage assets
  • Managed databases
  • Hosted databases
  • AI services

The overview can help identify whether resources are:

  • Fully protected
  • Partially protected
  • Not protected

Protection status depends on the relevant Defender for Cloud plans and extensions that apply to the resource.

The overview may also highlight resources associated with:

  • High-severity recommendations
  • Critical-severity recommendations
  • High-severity alerts
  • Critical-severity alerts
  • High- or critical-severity attack paths

This allows security teams to prioritize the most important issues instead of treating every resource equally.


The Top Issues Section

The Top issues section focuses attention on the resources and findings that require the most immediate action.

It can include:

High- and critical-severity alerts

Alerts indicate that Defender for Cloud or an integrated protection service has detected potentially malicious or suspicious activity.

Examples may include:

  • Suspicious activity involving data resources
  • Threats against AI workloads
  • Malicious or abnormal access patterns
  • Other detected security events

Alerts should be investigated to determine:

  • Which resource is affected
  • What activity was detected
  • When the activity occurred
  • Whether the activity is ongoing
  • What identities or services were involved
  • Whether containment or remediation is required

High- and critical-severity recommendations

Recommendations identify security improvements that should be made to reduce risk.

Examples include recommendations related to:

  • Internet exposure
  • Authentication
  • Identity permissions
  • Data protection
  • Missing security configurations
  • Vulnerable components
  • Protection plan coverage

A recommendation is generally a posture finding, whereas an alert is generally associated with detected activity or a security event.

High- and critical-severity attack paths

Attack path analysis helps identify combinations of weaknesses that could allow an attacker to reach a valuable resource.

An attack path may involve:

  1. An internet-exposed endpoint
  2. A weak identity or excessive permission
  3. A vulnerable workload
  4. Access to sensitive data
  5. A high-value AI or data resource

Attack paths are important because an individual issue may appear moderate when viewed in isolation but become critical when combined with other weaknesses.


The Data Closer Look Section

The Data closer look section provides more detailed information about data resources and their associated risks.

It can include the following areas.

Sensitive data discovery

Sensitive data discovery helps identify data resources that contain sensitive information.

Examples of sensitive information may include:

  • Personal information
  • Financial information
  • Credentials or secrets
  • Regulated information
  • Other information types identified by the organization

The dashboard can provide an overview of:

  • Sensitive information types
  • Sensitivity labels
  • Resources containing sensitive data
  • Resources where sensitive data may be exposed

Security teams can use this information to determine whether sensitive data is:

  • Publicly exposed
  • Accessible by inappropriate identities
  • Used by an AI workload without sufficient controls
  • Stored in a resource lacking appropriate protection

Sensitivity settings can be managed to control which information types and sensitivity labels are relevant to the organization.

Data threat protection

This area provides information about security alerts associated with data resources, including:

  • Storage resources
  • Managed databases

The purpose is to help security teams investigate threats affecting data and determine whether the associated resource requires remediation.

Data queries in Security Explorer

The dashboard can provide investigation queries for data-related risks.

Examples of investigation scenarios include:

  • Data resources containing plaintext secrets
  • Databases accessible by external users
  • Public storage containing sensitive data
  • Resources with potentially unsafe configurations

Security Explorer can be used to investigate relationships between resources, identities, configurations, and risks.

Internet-exposed data resources

The dashboard can identify data resources exposed to the internet.

These may include:

  • Public storage resources
  • Internet-accessible managed databases
  • Hosted databases with external exposure

Internet exposure does not automatically mean that a resource has been compromised. However, it increases the potential attack surface and should be evaluated alongside authentication, authorization, network controls, and data sensitivity.


The AI Closer Look Section

The AI closer look section focuses specifically on AI workloads and their security risks.

It includes several important areas.

AI discovery

AI discovery provides an inventory of AI resources found in the environment.

This visibility helps organizations identify:

  • Which AI services are deployed
  • Where AI workloads are running
  • Which teams or applications use AI
  • Which AI resources require security assessment
  • Whether unauthorized or unexpected AI resources exist

AI discovery is particularly important because organizations may have AI resources deployed by multiple teams across different subscriptions, projects, or cloud providers.

AI threat protection

AI threat protection provides information about detected threats involving AI workloads.

The dashboard can display:

  • The number of prompts scanned
  • Detected alerts
  • Alert severity
  • AI workloads associated with the alerts

Prompt scanning and AI threat detection help identify suspicious activity targeting AI services. However, the number of prompts scanned is a monitoring metric, not a security score by itself.

A high number of scanned prompts may simply indicate that an AI service is heavily used. Security teams should focus on the associated alerts, severity, affected resources, and investigation details.

AI queries in Security Explorer

The dashboard can provide queries for investigating AI-related risks.

Examples include:

  • Sensitive data resources used for grounding
  • Vulnerable containers used by AI workloads
  • AI resources with risky configurations
  • Relationships between AI endpoints and data resources
  • AI workloads with excessive exposure or permissions

These queries help security teams understand how AI resources interact with the rest of the environment.

Internet-exposed resources used for grounding

Grounding allows an AI workload to use external data to improve the relevance or accuracy of its responses.

The dashboard can identify internet-exposed storage and search resources used for grounding.

This is important because an AI application may be secure at the model endpoint while the data used to ground the model is exposed or inadequately protected.

Security teams should evaluate:

  • Whether the grounding data is sensitive
  • Whether the storage or search resource is publicly accessible
  • Whether the AI workload has excessive access
  • Whether authentication and authorization are properly configured
  • Whether the data source is trustworthy
  • Whether the resource is protected by appropriate Defender plans

Monitoring AI Protection Coverage

Protection coverage indicates whether resources are protected by the applicable security plans.

A resource may be:

Fully protected

The relevant posture and threat protection capabilities are enabled and providing coverage.

Partially protected

Some relevant capabilities are enabled, but one or more protections are missing.

Not protected

The applicable protection capabilities are not enabled or do not cover the resource.

Protection coverage should be reviewed regularly because AI environments change quickly. New AI services, model deployments, storage resources, and containers may be introduced without being included in the organization’s original security design.


How to Access and Use the Dashboard

A typical workflow is:

  1. Sign in to the Azure portal.
  2. Open Microsoft Defender for Cloud.
  3. Select Data and AI security dashboard.
  4. Review the Data and AI security overview.
  5. Review the Top issues section.
  6. Examine AI discovery and AI threat protection information.
  7. Investigate relevant recommendations, alerts, or attack paths.
  8. Use Security Explorer queries for deeper analysis.
  9. Remediate configuration issues.
  10. Reassess the dashboard to confirm that risk and protection coverage have improved.

For data-specific investigations, the dashboard can also be used to view resources containing sensitive information and then open the resource’s recommendations and alerts.


Recommended Monitoring Process

A repeatable monitoring process can be organized into five stages.

1. Establish an inventory

Identify all AI services, applications, models, endpoints, data sources, containers, and supporting infrastructure.

2. Review protection coverage

Determine whether each resource is covered by the appropriate Defender for Cloud plans.

3. Prioritize critical findings

Start with:

  • Critical alerts
  • Critical recommendations
  • Critical attack paths
  • Internet-exposed AI endpoints
  • Sensitive data used by AI workloads
  • AI resources with excessive permissions

4. Investigate relationships

Use Security Explorer and attack path analysis to understand how an issue could affect other resources.

5. Remediate and verify

Apply the recommended changes, then return to the dashboard to confirm that the issue has been resolved or that the risk has been reduced.


Common Security Actions After Reviewing the Dashboard

Depending on the findings, remediation may include:

  • Enabling the appropriate Defender for Cloud plan
  • Removing unnecessary public network access
  • Configuring private endpoints
  • Strengthening authentication
  • Applying least-privilege permissions
  • Using managed identities
  • Protecting storage and databases
  • Removing plaintext secrets
  • Updating vulnerable libraries or container images
  • Restricting access to grounding data
  • Investigating suspicious AI prompts or alerts
  • Reviewing attack paths
  • Applying security recommendations through infrastructure as code
  • Monitoring the environment continuously

The dashboard helps identify what should be addressed, but remediation usually occurs in the underlying Azure service, identity platform, network configuration, data platform, or application.


Important Exam Distinctions

Dashboard versus Security Explorer

  • The Data and AI security dashboard provides a summarized monitoring view.
  • Security Explorer provides deeper investigation and relationship analysis.

Recommendation versus alert

  • A recommendation identifies a security improvement or configuration gap.
  • An alert indicates detected suspicious or malicious activity.

Posture management versus threat protection

  • Posture management focuses on reducing weaknesses before they are exploited.
  • Threat protection focuses on detecting threats and suspicious activity.

AI discovery versus AI threat protection

  • AI discovery identifies AI resources and workloads.
  • AI threat protection detects threats targeting those workloads.

Sensitive data discovery versus data threat protection

  • Sensitive data discovery identifies resources containing sensitive information.
  • Data threat protection identifies security threats involving data resources.

Internet exposure versus compromise

An internet-exposed resource is not necessarily compromised. It is a resource with increased attack surface and potentially greater risk. An alert or investigation is needed to determine whether malicious activity occurred.


Key Takeaways

For the SC-500 exam, remember these points:

  • The Data and AI security dashboard provides a centralized view of data and AI security.
  • The dashboard combines inventory, protection coverage, recommendations, alerts, and attack paths.
  • Full functionality depends on the relevant Defender for Cloud plans and extensions.
  • AI discovery helps identify AI resources across the environment.
  • AI threat protection provides visibility into scanned prompts and detected alerts.
  • Sensitive data discovery helps identify resources containing sensitive information.
  • Security Explorer supports deeper investigation of data and AI risks.
  • Attack path analysis helps identify chains of weaknesses that could lead to high-impact compromise.
  • Internet-exposed AI and data resources should be prioritized for review.
  • The dashboard supports monitoring and prioritization; remediation is performed in the underlying services and security controls.

Practice Exam Questions

Question 1

A security team wants a centralized view of its AI resources, protection coverage, recommendations, alerts, and attack paths. Which Microsoft Defender for Cloud capability should the team use?

A. Microsoft Defender Vulnerability Management
B. Azure Resource Graph
C. Data and AI security dashboard
D. Microsoft Sentinel workbook

Correct answer: C

Explanation: The Data and AI security dashboard provides a centralized view of data and AI resources, protection status, recommendations, alerts, and attack paths. Azure Resource Graph can query resources, but it does not provide the same integrated security dashboard experience.


Question 2

An organization wants to identify storage and database resources that contain sensitive information. Which capability should be enabled?

A. Azure Bastion
B. Defender for Servers
C. Sensitive data discovery
D. Microsoft Entra Privileged Identity Management

Correct answer: C

Explanation: Sensitive data discovery identifies resources containing sensitive information types and sensitivity labels. The results can be reviewed through the Data and AI security dashboard.


Question 3

What is the primary purpose of AI security posture management in Defender for Cloud?

A. To identify AI workload risks, vulnerabilities, misconfigurations, and exposure
B. To replace Microsoft Entra authentication for AI applications
C. To train foundation models
D. To provide end-user prompt authoring assistance

Correct answer: A

Explanation: AI security posture management focuses on discovering AI workloads and identifying security weaknesses such as vulnerable components, excessive permissions, misconfigurations, and internet exposure.


Question 4

The AI closer look section reports the number of prompts scanned and displays alerts by severity. What capability is providing this information?

A. Sensitive data discovery
B. AI threat protection
C. Azure Policy
D. Defender for Containers

Correct answer: B

Explanation: AI threat protection provides information about AI-related threat detection, including prompt scanning activity and detected alerts.


Question 5

A security analyst sees a critical recommendation for an AI endpoint that is accessible from the internet. What does this finding primarily represent?

A. Proof that the endpoint has been compromised
B. A completed incident investigation
C. A posture or configuration risk requiring remediation
D. A successful model deployment

Correct answer: C

Explanation: An internet-exposed endpoint is a security posture concern. It increases the attack surface but does not, by itself, prove that a compromise has occurred.


Question 6

Which dashboard section is most directly associated with identifying sensitive information types and sensitivity labels in cloud data resources?

A. Data closer look
B. Top issues
C. AI discovery
D. AI threat protection

Correct answer: A

Explanation: The Data closer look section includes sensitive data discovery information, including sensitive information types and sensitivity labels.


Question 7

A security team wants to investigate whether sensitive data resources are being used for AI grounding. Which capability should the team use?

A. Azure Backup
B. Security Explorer queries
C. Azure Bastion
D. Microsoft Entra authentication methods

Correct answer: B

Explanation: Security Explorer provides queries for investigating relationships and risks involving AI resources, including sensitive data resources used for grounding.


Question 8

Which statement best describes an attack path in Defender for Cloud?

A. A list of all prompts sent to an AI model
B. A backup copy of an affected resource
C. A sequence of weaknesses that could allow an attacker to reach a valuable resource
D. A list of approved Azure Policy definitions

Correct answer: C

Explanation: Attack path analysis identifies connected weaknesses, such as internet exposure, excessive permissions, and vulnerable resources, that could lead to a high-impact compromise.


Question 9

A subscription has Defender CSPM enabled, but sensitive data discovery and Defender for Storage are not enabled. What is the most likely result?

A. The dashboard will automatically protect all storage resources
B. The dashboard may provide incomplete data protection and sensitive data information
C. All storage resources will be removed from the inventory
D. AI threat protection will be disabled automatically

Correct answer: B

Explanation: Dashboard information depends on the relevant plans and extensions. Without sensitive data discovery and Defender for Storage, data-related visibility and protection coverage may be incomplete.


Question 10

Which action is the best first step after identifying a critical AI security alert in the Data and AI security dashboard?

A. Delete every AI resource in the subscription
B. Ignore the alert until the next monthly review
C. Disable all network connectivity
D. Investigate the alert, affected resource, activity, and related recommendations

Correct answer: D

Explanation: A critical alert should be investigated to understand the detected activity, affected resources, identities, timing, and recommended response. Remediation should be based on the investigation rather than automatically deleting or disabling unrelated resources.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply