Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management (EASM) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management (EASM)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Modern organizations rarely have a completely static IT environment.

Applications are deployed across Azure and other clouds. Developers create new internet-facing services. Acquisitions introduce unfamiliar domains and infrastructure. Third-party providers host applications and content. Old systems remain online after their owners have forgotten about them. Certificates, DNS records, IP addresses, and web applications continually change.

This creates a security problem:

How can an organization secure assets that it doesn’t even know it owns or exposes to the internet?

Microsoft Defender External Attack Surface Management (Defender EASM) addresses this problem by providing an outside-in view of an organization’s internet-exposed infrastructure.

Rather than starting with an Azure subscription or a known cloud resource, Defender EASM starts with known organizational assets—called discovery seeds—and recursively discovers related infrastructure. The resulting information is organized into an inventory that can expose unknown assets, third-party dependencies, vulnerabilities, and other security risks.

An important exam distinction is that Defender EASM uses an outside-in view of the internet to discover assets that may be unknown or unmanaged, complementing the resource-centric view provided by other Defender capabilities. The current Defender for Cloud integration also provides external attack-surface-management capabilities through Defender CSPM without requiring a separate Defender EASM license or special configuration.

For the SC-500 exam, this topic is particularly important because you need to understand:

  • What Defender EASM is
  • What an external attack surface is
  • How EASM differs from traditional vulnerability scanning
  • How discovery seeds work
  • How recursive discovery finds unknown assets
  • What types of assets EASM discovers
  • How assets are classified
  • The difference between approved, candidate, dependency, monitor-only, and investigation-required assets
  • How EASM identifies vulnerabilities and security-hygiene issues
  • How dashboards and inventory are used to prioritize risk
  • How EASM complements Defender for Cloud and Defender CSPM
  • How EASM can contribute to attack-path analysis
  • How organizations can manage discovered assets
  • How to distinguish EASM from Defender for Cloud’s cloud inventory and Defender Vulnerability Management

1. What Is Microsoft Defender External Attack Surface Management?

Microsoft Defender External Attack Surface Management (EASM) continuously discovers and maps an organization’s digital attack surface from an external perspective.

The key phrase to remember is:

Outside-in

EASM looks at the organization’s infrastructure from the perspective of what can be discovered from the internet.

This allows security teams to identify:

  • Unknown internet-facing infrastructure
  • Previously unmonitored assets
  • Web applications
  • Domains
  • Hosts
  • IP addresses
  • IP address blocks
  • SSL certificates
  • Third-party dependencies
  • Potential vulnerabilities
  • Security-hygiene problems
  • Suspicious or potentially malicious infrastructure relationships

Microsoft describes Defender EASM as providing visibility that helps organizations identify unknowns, prioritize risk, eliminate threats, and extend vulnerability and exposure management beyond the firewall.

The fundamental problem EASM solves

Traditional security programs often begin with assets that the organization already knows about.

For example:

“Show me all the virtual machines in this Azure subscription.”

That is useful, but it doesn’t answer:

“What internet-facing infrastructure associated with our organization exists that we don’t know about?”

EASM is designed to help answer the second question.


2. What Is an External Attack Surface?

An organization’s external attack surface consists broadly of infrastructure and services that are exposed or discoverable from the public internet.

Examples include:

  • Public websites
  • Internet-facing applications
  • Public IP addresses
  • DNS domains
  • Hosts
  • Web pages
  • SSL certificates
  • Publicly exposed services
  • Third-party infrastructure supporting organizational applications

The external attack surface changes constantly.

For example:

New application deployed
↓
New DNS record
↓
New public hostname
↓
New SSL certificate
↓
New internet-facing service
↓
New potential attack surface

A security team that relies entirely on manually maintained asset inventories may not discover every change.

Defender EASM continuously monitors and updates its understanding of the organization’s externally exposed infrastructure.


3. Why External Attack Surface Management Matters

Security controls are only effective when organizations know what they need to protect.

Consider an organization that believes it has:

  • 50 public-facing websites
  • 100 public IP addresses
  • 20 internet-facing applications

EASM might discover additional infrastructure associated with those known assets.

For example:

Known corporate domain
|
+--- Web host
| |
| +--- Web application
| +--- SSL certificate
|
+--- Related IP block
| |
| +--- Additional host
|
+--- WHOIS contact
|
+--- Additional organization asset

The newly discovered infrastructure may represent:

  • Legitimate infrastructure
  • A third-party dependency
  • A forgotten asset
  • A development environment
  • Shadow IT
  • An incorrectly categorized asset
  • An asset requiring further investigation

This is one of the major security benefits of EASM.


4. How Defender EASM Discovery Works

The core concept behind EASM discovery is recursive discovery.

The process begins with assets that are known to belong to the organization.

These are called:

Discovery seeds

Defender EASM analyzes the known assets and observes relationships between them and other internet infrastructure.

It then follows those relationships to discover additional assets.

The process can be represented as:

Known Asset
↓
Discovery Seed
↓
Observe relationships
↓
Discover connected infrastructure
↓
Analyze newly discovered assets
↓
Follow additional relationships
↓
Build attack-surface inventory

Microsoft’s proprietary discovery technology recursively searches through observed connections to known legitimate assets and uses those connections to infer relationships between infrastructure.


5. What Is a Discovery Seed?

A discovery seed is a known asset that Defender EASM uses as a starting point for discovering additional infrastructure.

Examples include:

  • Domain names
  • Hosts
  • IP addresses or IP ranges
  • Autonomous System Numbers (ASNs)
  • Email addresses
  • WHOIS organization information

For example, suppose a company owns:

contoso.com

The organization can use that known domain as a discovery seed.

Defender EASM can then investigate relationships involving that domain and potentially identify:

contoso.com
↓
www.contoso.com
↓
public IP address
↓
IP block
↓
additional host
↓
related certificate

The objective is not simply to scan the original domain.

The objective is to understand the broader infrastructure connected to it.


6. Automated Discovery vs. Custom Discovery

Defender EASM supports automated attack-surface discovery as well as customized discovery.

Automated discovery

Microsoft has preconfigured attack surfaces for many organizations.

When starting with Defender EASM, Microsoft recommends searching for the organization’s existing attack surface before immediately creating a custom attack surface.

This allows an organization to take advantage of infrastructure that has already been identified and then allow Defender EASM to continue refreshing and expanding the inventory.

Custom discovery

Custom discovery is useful when an organization wants to investigate infrastructure that may not be sufficiently connected to its primary known assets.

For example:

  • A recently acquired company
  • A newly established business unit
  • A subsidiary
  • A newly purchased domain
  • A known IP range
  • An infrastructure relationship not discovered through the primary attack surface

Custom discoveries use selected seeds as starting points.


7. Discovery Seeds Cannot Be Private IP Addresses

An important exam detail is that Defender EASM is designed to provide an external perspective.

Therefore, private IP addresses cannot be used as discovery seeds.

The discovery process focuses on infrastructure that can be observed from the internet rather than internal-only addressing.

Exam scenario

If a question asks:

An administrator wants to create an EASM discovery group using an internal private IP address as the seed. What should the administrator do?

The correct concept is:

Use an externally discoverable asset instead.


8. Types of Assets Defender EASM Can Discover

Defender EASM’s inventory can contain several asset types.

Important asset types include:

Asset typeExample
Domainscontoso.com
Hostswww.contoso.com
PagesWeb pages associated with hosts
IP addressesPublic IP addresses
IP blocksPublic address ranges
ASNsAutonomous System Numbers
SSL certificatesCertificates associated with internet-facing services
WHOIS contactsRegistration/contact information

Microsoft’s current EASM documentation identifies domains, IP address blocks, hosts, email contacts, ASNs, and WHOIS organizations as core discovery asset types; the inventory also includes pages, IP addresses, and SSL certificates.

Exam tip

If a question asks which technology can help discover an organization’s:

“unknown internet-facing domains, hosts, IP addresses, and related infrastructure”

think:

Defender EASM


9. The Defender EASM Inventory

Discovered assets are indexed into the Defender EASM inventory.

The inventory acts as a dynamic record of the organization’s externally visible infrastructure.

This is important because the attack surface is not static.

An asset might:

  • Appear
  • Disappear
  • Change ownership
  • Change infrastructure
  • Become inactive
  • Become associated with a new application
  • Develop a new vulnerability

Defender EASM tracks these changes as part of its continuously updated attack-surface view.


10. Asset States

One of the most important SC-500 exam concepts is that not every discovered asset is automatically treated as an organizational asset.

Defender EASM uses different asset states to help organizations categorize discovered infrastructure.

Current asset states include:

  • Approved Inventory
  • Dependency
  • Monitor Only
  • Candidate
  • Requires Investigation

Understanding these states is important for exam questions involving asset ownership and classification.


11. Approved Inventory

Approved Inventory represents an asset that has been determined to belong to the organization’s attack surface and for which the organization is directly responsible.

For example:

Company-owned website
↓
Approved Inventory

This means the organization should normally consider the asset part of its managed security scope.


12. Dependency

A Dependency is infrastructure owned by another party but used to support the organization’s attack surface.

For example, a company may have a website hosted by a third-party provider.

The company owns the website and domain, but the underlying hosting infrastructure may belong to the provider.

The external infrastructure may therefore be classified as a dependency.

This distinction is important because:

The asset can be relevant to your attack surface even though you don’t directly own or control it.

Microsoft gives third-party hosting as an example of infrastructure that can be classified as a dependency.


13. Monitor Only

Monitor Only is useful when an asset is relevant to the organization’s attack surface but isn’t directly controlled by the organization and isn’t a technical dependency.

For example:

  • An independently operated franchise
  • A related organization
  • An asset belonging to a related company

The organization may want visibility into the asset without treating it as directly owned infrastructure.


14. Candidate

A Candidate asset has a relationship to known organizational assets but does not have a strong enough relationship for Defender EASM to automatically classify it as approved inventory.

A security administrator should review the asset and determine its appropriate classification.

For example:

Known company domain
↓
Related host discovered
↓
Relationship uncertain
↓
Candidate
↓
Manual review

This is an important distinction.

A discovered asset does not necessarily mean:

“This definitely belongs to our organization.”

Instead, Defender EASM provides evidence and relationship information so security teams can make the determination.


15. Requires Investigation

Requires Investigation is another state that identifies assets requiring additional human analysis.

Defender EASM uses internally generated confidence information to determine whether relationships between assets are sufficiently strong.

A Requires Investigation designation means:

The relationship needs further validation.

It does not necessarily mean the asset is malicious.

It means the organization should investigate its relationship to the known attack surface.


16. Understanding the Discovery Chain

The discovery chain helps security professionals understand why Defender EASM believes an asset is related to the organization.

For example:

Known domain
↓
WHOIS contact
↓
IP block
↓
IP address
↓
Host

The discovery chain provides evidence about the relationships connecting a discovered asset to a known seed.

This is extremely useful when investigating potentially unknown infrastructure.

Rather than simply saying:

“We found this IP address.”

Defender EASM can help answer:

“Why does Defender EASM believe this IP address is related to our organization?”


17. Asset Approval

Some discovered assets can be automatically approved when Defender EASM determines that the relationship to the known seed is sufficiently strong.

Other assets require manual review.

The current discovery information distinguishes between:

Approved inventory

and

Candidate

based on the strength of the relationship and approval process.

Exam scenario

If an asset is discovered but there isn’t enough evidence to automatically establish ownership, don’t assume it is automatically approved.

Think:

Candidate → investigate/approve appropriately.


18. Vulnerability Discovery

Defender EASM isn’t only an asset-discovery tool.

It also provides information that can help security teams identify vulnerabilities and other risks associated with externally exposed infrastructure.

For example, EASM can surface:

  • Vulnerabilities
  • CVEs
  • Weak security configurations
  • SSL/TLS issues
  • Exposed services
  • Security-hygiene problems
  • Potentially risky infrastructure

These insights help organizations prioritize which parts of their external attack surface require attention.


19. EASM and CVEs

Defender EASM can associate known vulnerabilities with externally discovered assets.

For example:

Internet-facing host
↓
Detected software
↓
Known vulnerability
↓
CVE
↓
Risk prioritization
↓
Remediation

This provides a useful external perspective on vulnerability exposure.

However, remember that EASM is fundamentally concerned with the external attack surface.

It is not simply another name for Defender Vulnerability Management.


20. Defender EASM vs. Defender Vulnerability Management

This distinction is highly relevant to SC-500.

CapabilityDefender EASMDefender Vulnerability Management
Primary focusExternal attack surfaceVulnerability/exposure management
PerspectiveOutside-inPrimarily workload/endpoint-oriented
Unknown internet-facing assetsStrong capabilityNot its primary purpose
Discover domains and hostsYesNot its primary purpose
Discover public IP infrastructureYesNot its primary purpose
Identify software vulnerabilitiesYes, as part of external attack-surface insightsCore capability
Endpoint software inventoryNot primaryStrong capability
Defender for Endpoint integrationNot its primary purposeYes
Azure VM vulnerability assessmentNot its primary purposeYes

A useful mental model is:

EASM asks, “What can the internet see that belongs to us?”

while:

Defender Vulnerability Management asks, “What vulnerabilities exist on the systems we’re managing?”

These capabilities complement one another.


21. Defender EASM vs. Defender for Cloud Inventory

Another important distinction is between EASM and the Defender for Cloud cloud inventory.

Defender for Cloud’s inventory provides a resource-centric view of connected cloud resources, including Azure, AWS, and GCP resources.

For example:

Azure subscription
↓
VM
Storage account
SQL database
Container
AI service

EASM takes a different approach:

Internet
↓
Known public asset
↓
Related infrastructure
↓
Unknown external assets
↓
External attack surface

Defender for Cloud inventory is therefore useful for understanding the security state of known connected cloud resources, while EASM helps uncover internet-facing infrastructure that may not be represented in the organization’s cloud-resource inventory.


22. EASM and Defender CSPM

Defender EASM is particularly important in conjunction with Defender Cloud Security Posture Management (Defender CSPM).

Current Defender for Cloud functionality integrates external attack-surface-management capabilities through Defender EASM.

This integration allows organizations to improve their security posture by incorporating an external view of attack-surface exposure.

Importantly, Microsoft currently states that the external attack-surface-management capability integrated into Defender CSPM is included with the Defender CSPM plan and doesn’t require a separate Defender EASM license or special configuration.

Exam tip

Don’t automatically assume:

“Defender EASM always requires a separate EASM license.”

The current Defender CSPM integration changes this distinction.


23. EASM and Attack Path Analysis

EASM findings can also complement attack path analysis.

The SC-500 training specifically calls out the integration of EASM findings with Defender CSPM for attack-path analysis.

The significance is that an organization can move beyond simply asking:

“What assets are exposed?”

and begin asking:

“Which exposed assets create meaningful attack paths into important resources?”

For example:

Internet-facing asset
↓
Vulnerability
↓
Compromised workload
↓
Lateral movement
↓
Sensitive resource

Attack-path analysis helps security teams focus on exposures that could contribute to meaningful attack scenarios.


24. EASM Dashboards

Defender EASM provides dashboards designed to help organizations understand their attack surface.

Dashboard insights can focus on areas such as:

  • Vulnerabilities
  • Security hygiene
  • Compliance
  • Infrastructure
  • Asset exposure

These dashboards help security teams prioritize the areas presenting the greatest risk rather than reviewing every discovered asset individually.


25. Security Hygiene

Not every security problem is necessarily a traditional software vulnerability.

For example, an organization might have:

  • An expired or weak SSL certificate
  • Unexpected exposed ports
  • Unnecessary internet-facing infrastructure
  • An outdated service
  • An unexpected host
  • An unmanaged domain

These conditions can contribute to an organization’s overall security hygiene.

EASM dashboards and inventory capabilities help surface these conditions so organizations can investigate and remediate them.


26. IP Reputation

Defender EASM also provides IP reputation information.

The IP reputation information can identify potential threats associated with an IP address, including evidence that the address has appeared on threat lists.

For example, an IP address could have been associated with suspicious activity or a known malicious host.

This information provides additional context when evaluating an externally exposed asset.

Important distinction

An IP appearing in threat intelligence does not automatically prove that the organization’s current system is compromised.

It is an indicator that warrants investigation.


27. Connected Assets

The Defender EASM asset details experience provides a Connected assets view.

This allows security professionals to understand other assets connected to a particular asset.

For example:

Domain
|
+-- Host
|
+-- IP address
|
+-- SSL certificate
|
+-- Web page

Understanding connected assets is valuable because a security issue involving one component may reveal additional infrastructure that needs investigation.


28. JavaScript and Web Resources

Defender EASM can also provide visibility into resources associated with web assets.

For example, it can identify JavaScript resources associated with pages or hosts.

Information can include:

  • Resource URL
  • Resource host
  • MD5 hash
  • First-seen date
  • Last-seen date

This provides another layer of visibility into the technologies and resources used by externally exposed web applications.


29. SSL Certificate Visibility

SSL certificates are another important component of the external attack surface.

Certificates can provide relationships between:

  • Domains
  • Hosts
  • Infrastructure
  • Organizations

An unexpected certificate can sometimes reveal infrastructure that wasn’t present in a manually maintained inventory.

For this reason, certificate information can be valuable during external attack-surface discovery.


30. Managing EASM Inventory Assets

Defender EASM doesn’t just discover assets.

Security teams can also manage the inventory.

Current capabilities include:

  • Changing asset states
  • Adding labels
  • Assigning external IDs
  • Removing labels
  • Marking observations as not applicable
  • Removing assets from inventory
  • Managing assets discovered through specific seeds
  • Tracking changes through Task Manager

For example, an organization can label an asset according to an internal classification such as:

Production
Development
Acquisition
Third-party
Critical
Requires Review

Labels provide additional organizational context.


31. Marking an Observation as Not Applicable

An important management capability is the ability to mark certain observations as not applicable.

For example, a security team may investigate a vulnerability or other observation and determine that it does not apply to the organization’s specific situation.

Rather than ignoring the issue informally, the organization can manage the observation within the EASM inventory.

This helps maintain more accurate reporting.


32. Removing Assets

Defender EASM also provides mechanisms for removing assets from inventory.

For example, when removing a discovery seed, an administrator can choose to remove assets that were discovered through a connection to that seed.

This is useful when an organization determines that:

  • A seed no longer belongs to it
  • An acquisition has been divested
  • An infrastructure relationship is no longer relevant
  • The inventory needs to be corrected


33. EASM and Shadow IT

One of the strongest practical use cases for EASM is discovering shadow IT and previously unknown external infrastructure.

Consider this scenario:

A development team launches:

test-new-app.company-example.com

The security team isn’t informed.

The application becomes publicly accessible.

Traditional security inventory:

Unknown

EASM:

Internet discovery
↓
Related domain discovered
↓
Host discovered
↓
Application identified
↓
Potential vulnerability detected

This provides security teams with visibility into infrastructure that may have bypassed normal inventory and security-review processes.


34. EASM for Mergers and Acquisitions

EASM can also be valuable during mergers and acquisitions.

Suppose Company A acquires Company B.

Company A may receive:

  • New domains
  • Public IP ranges
  • Websites
  • Web applications
  • Certificates
  • Hosts
  • Third-party dependencies

The acquiring organization’s existing asset inventory may not immediately contain all of this infrastructure.

EASM can help establish an external view of the acquired organization’s attack surface.


35. EASM and Third-Party Dependencies

An organization may depend on infrastructure it doesn’t directly own.

For example:

Company website
↓
Third-party hosting provider
↓
External infrastructure

That external infrastructure may be classified as a Dependency.

This is important because:

Security responsibility may differ from ownership.

An organization can have a security exposure resulting from a third party even when the organization doesn’t directly manage the underlying infrastructure.


36. A Typical EASM Investigation

Consider an organization that believes all of its public infrastructure is known.

Step 1 — Start with known assets

Provide known:

  • Domains
  • Hosts
  • IP blocks
  • Other supported identifiers

Step 2 — Run discovery

Defender EASM recursively examines relationships among internet-facing infrastructure.

Step 3 — Review the inventory

The security team examines discovered assets.

Step 4 — Classify assets

Assets may be:

  • Approved Inventory
  • Dependency
  • Monitor Only
  • Candidate
  • Requires Investigation

Step 5 — Investigate unknown assets

The security team examines:

  • Discovery chains
  • Connected assets
  • IP reputation
  • Vulnerabilities
  • Web resources
  • Certificates

Step 6 — Prioritize risk

Security teams use dashboards and vulnerability information to identify the most important exposures.

Step 7 — Remediate

Examples include:

  • Remove unnecessary public exposure
  • Patch vulnerable software
  • Replace certificates
  • Secure misconfigured services
  • Remove abandoned infrastructure
  • Transfer remediation to the appropriate third-party owner

Step 8 — Continue monitoring

The organization continues monitoring its changing external attack surface.


37. EASM Outside-In vs. Traditional Inside-Out Security

This is perhaps the most important conceptual distinction for the exam.

Traditional cloud security

Starts with:

Known Azure resource
↓
Configuration
↓
Security posture
↓
Recommendations

Defender EASM

Starts with:

Internet
↓
Known organizational asset
↓
Related infrastructure
↓
Unknown assets
↓
External vulnerabilities
↓
Attack-surface risk

Neither approach replaces the other.

They answer different questions.


38. EASM Does Not Replace Defender for Cloud

It is important not to interpret EASM as a replacement for Defender for Cloud.

Instead, think of the technologies as complementary.

Security questionAppropriate capability
What Azure resources do we have?Defender for Cloud inventory
What security recommendations affect our Azure resources?Defender for Cloud
What vulnerabilities exist on protected VMs?Defender Vulnerability Management
What internet-facing infrastructure belongs to us?Defender EASM
What unknown domains/hosts/IP infrastructure exists?Defender EASM
What externally exposed vulnerabilities exist?Defender EASM
What attack paths involve external exposure?Defender CSPM + EASM integration

39. Permissions

Defender EASM uses Azure RBAC.

Current documentation identifies the following general roles:

Owner

An Owner can:

  • Create EASM resources
  • Delete resources
  • Edit resources
  • Manage inventory assets
  • Use EASM capabilities

Contributor

A Contributor can also create, delete, and edit EASM resources and inventory assets.

Reader

A Reader can:

  • View Defender EASM data

but cannot create, delete, or edit resources or inventory assets.

Exam tip

If the question says:

“The user only needs to view EASM data.”

Think:

Reader

If the user needs to modify inventory or resources:

Contributor or Owner, depending on the required scope and operation.


40. Current Defender CSPM Integration

A particularly important current-platform consideration is the integration between Defender EASM and Defender CSPM.

Microsoft currently describes external attack-surface-management functionality in Defender for Cloud as being provided through integration with Defender EASM.

The capability is included with the Defender CSPM plan by default and does not require a separate Defender EASM license or special configuration for that integrated capability.

This makes external attack-surface visibility part of a broader cloud-security-posture strategy.


41. Security Copilot Integration

Current Defender EASM also supports integration with Microsoft Security Copilot.

Security Copilot can be used to interact with Defender EASM data using natural-language prompts.

For example, security teams can ask questions about:

  • External attack surface
  • Critical risks
  • CVEs
  • SSL certificates
  • Exposed ports
  • Specific assets

It can also help with attack-surface curation, including working with labels, external IDs, and asset states.

For SC-500, however, the foundational concept remains:

EASM provides external attack-surface discovery and visibility.


42. Common EASM Misconceptions

Misconception 1: EASM is just another vulnerability scanner

Not exactly.

Vulnerability discovery is an important capability, but the primary purpose is to understand the external attack surface.


Misconception 2: EASM only scans Azure

Incorrect.

EASM is concerned with internet-facing infrastructure and can discover assets across an organization’s external digital environment rather than limiting itself to Azure resource types.


Misconception 3: Every discovered asset belongs to the organization

Incorrect.

Assets can be classified as:

  • Approved Inventory
  • Dependency
  • Monitor Only
  • Candidate
  • Requires Investigation

Misconception 4: Candidate means malicious

Incorrect.

Candidate means the relationship to the organization requires review.


Misconception 5: Dependency means the organization owns the infrastructure

Incorrect.

A dependency can be infrastructure owned by another organization but supporting the organization’s attack surface.


Misconception 6: EASM replaces Defender Vulnerability Management

Incorrect.

EASM and Defender Vulnerability Management provide complementary capabilities.


Misconception 7: EASM only looks at internal Azure inventory

Incorrect.

Its defining characteristic is the external, outside-in perspective.


Misconception 8: Private IP addresses can be used as discovery seeds

Incorrect.

Private IP addresses cannot be used as Defender EASM discovery seeds.


43. SC-500 Exam-Focused Comparison

ScenarioThink
Discover unknown public domainsDefender EASM
Discover unknown internet-facing hostsDefender EASM
Discover external IP infrastructureDefender EASM
Map relationships between known and unknown public assetsEASM discovery
Start discovery from a known domainDiscovery seed
Determine why an asset was associated with the organizationDiscovery chain
Asset ownership uncertainCandidate / Requires Investigation
Third-party infrastructure supporting an applicationDependency
Related but independently controlled organization infrastructureMonitor Only
Asset directly owned and managed by organizationApproved Inventory
Find vulnerabilities associated with externally exposed assetsDefender EASM
Scan Azure VM software for vulnerabilitiesDefender Vulnerability Management
Get cloud-resource inventoryDefender for Cloud Inventory
Use external attack-surface information for attack-path analysisDefender CSPM + EASM
View EASM information without modifying itReader
Modify EASM inventoryContributor/Owner
Use a private IP as a discovery seedNot supported

44. Key Takeaways

For the SC-500 exam, remember the following:

  1. Defender EASM provides an outside-in view of an organization’s internet-exposed attack surface.
  2. EASM uses discovery seeds as starting points.
  3. Discovery is recursive—Defender EASM follows observed relationships to discover additional infrastructure.
  4. Discovery seeds can include known domains, hosts, IP ranges, ASNs, email information, and WHOIS-related identifiers.
  5. Private IP addresses cannot be used as discovery seeds.
  6. EASM can discover assets such as domains, hosts, pages, IP addresses, IP blocks, ASNs, SSL certificates, and WHOIS-related information.
  7. Discovered assets are maintained in the Defender EASM inventory.
  8. Important asset states include:
    • Approved Inventory
    • Dependency
    • Monitor Only
    • Candidate
    • Requires Investigation
  9. A Candidate asset requires additional review before being treated as approved organizational infrastructure.
  10. A Dependency can be owned by a third party but still be relevant to the organization’s attack surface.
  11. The discovery chain helps explain why Defender EASM believes an asset is connected to the organization.
  12. EASM can surface vulnerabilities, CVEs, IP reputation information, SSL-related issues, and other security-hygiene concerns.
  13. EASM is not simply another name for Defender Vulnerability Management.
  14. Defender Vulnerability Management focuses primarily on vulnerability management for managed workloads/endpoints, whereas EASM emphasizes the organization’s externally observable attack surface.
  15. Defender EASM complements Defender for Cloud rather than replacing it.
  16. Current Defender CSPM functionality integrates external attack-surface management through Defender EASM without requiring a separate EASM license for that integrated capability.
  17. EASM findings can complement Defender CSPM attack-path analysis.
  18. The fundamental EASM question is:

“What can the internet see that belongs to our organization?”

  1. The fundamental vulnerability-management question is:

“What vulnerabilities exist on the systems we’re managing?”

  1. For the exam, remember:

Known asset → Discovery seed → Recursive discovery → External attack-surface inventory → Classify assets → Identify vulnerabilities/exposures → Prioritize risk → Remediate.


Practice Exam Questions

Question 1

A security team is concerned that developers may have deployed internet-facing applications that are not included in the organization’s official asset inventory. The team wants to discover unknown public-facing domains, hosts, and related infrastructure associated with the organization.

Which Microsoft solution is most appropriate?

A. Azure Policy

B. Microsoft Defender for Endpoint

C. Microsoft Defender External Attack Surface Management

D. Microsoft Sentinel

Answer: C

Explanation

A is correct. Defender EASM is specifically designed to provide an external, outside-in view of an organization’s internet-facing attack surface. Its recursive discovery capabilities can uncover previously unknown and unmonitored infrastructure connected to known organizational assets.

B is incorrect because Defender for Endpoint primarily provides endpoint protection, detection, and response capabilities.

C is incorrect because Azure Policy governs Azure resources and configurations rather than discovering an organization’s unknown public internet infrastructure.

D is incorrect because Sentinel is a SIEM/SOAR platform rather than an external attack-surface discovery service.


Question 2

An administrator wants to create a custom Defender EASM discovery group. The administrator has identified a known company-owned domain that should be used as the starting point for discovery.

What should the administrator configure?

A. A private IP address

B. A security recommendation

C. The company-owned domain as a discovery seed

D. An Azure Resource Graph query

Answer: C

Explanation

C is correct. A discovery seed is a known organizational asset that Defender EASM uses as a starting point for recursive discovery. Domains, hosts, IP ranges, and other supported identifiers can be used as seeds.

A is incorrect because private IP addresses cannot be used as Defender EASM discovery seeds.

B is incorrect because a security recommendation isn’t a discovery seed.

D is incorrect because Azure Resource Graph is used to query Azure resource information and isn’t the mechanism for defining EASM discovery seeds.


Question 3

Defender EASM discovers an IP address associated with a known corporate domain. The security team wants to understand why EASM determined that the IP address is related to the organization.

Which capability should the team examine?

A. Security baseline assessment

B. Discovery chain

C. Azure Policy compliance

D. CVSS score

Answer: B

Explanation

B is correct. The discovery chain provides information about the observed relationships between a discovery seed and a discovered asset. It helps security professionals understand why Defender EASM associated an asset with their organization.

A is incorrect because security baseline assessment evaluates machine configuration rather than EASM asset relationships.

C is incorrect because Azure Policy compliance doesn’t explain EASM discovery relationships.

D is incorrect because CVSS relates to vulnerability severity rather than asset discovery relationships.


Question 4

A Defender EASM discovery operation identifies an external host that appears to be related to the organization. However, the relationship isn’t strong enough for the asset to be automatically classified as part of the organization’s approved inventory.

What asset state should the security team expect?

A. Approved Inventory

B. Dependency

C. Monitor Only

D. Candidate

Answer: D

Explanation

D is correct. A Candidate asset has a relationship to known organizational assets but doesn’t have sufficient evidence to be automatically treated as approved inventory. It requires manual review to determine the appropriate classification.

A is incorrect because Approved Inventory indicates that the asset has been established as part of the organization’s owned attack surface.

B is incorrect because Dependency is used when infrastructure owned by another party supports the organization’s attack surface.

C is incorrect because Monitor Only is intended for relevant assets that aren’t directly controlled and aren’t necessarily technical dependencies.


Question 5

A company hosts its public web application with a third-party provider. Defender EASM identifies the third-party infrastructure as being directly associated with the company’s externally exposed application, but the company does not own the underlying hosting infrastructure.

How should this infrastructure generally be classified?

A. Candidate

B. Dependency

C. Approved Inventory

D. Requires Investigation

Answer: B

Explanation

B is correct. A Dependency represents infrastructure owned by a third party that directly supports the organization’s attack surface. Third-party hosting is a typical example.

A is incorrect because Candidate is primarily used when the relationship to the organization requires additional ownership validation.

C is incorrect because the scenario explicitly states that the organization does not own the infrastructure.

D is incorrect because the scenario provides sufficient information to establish that the infrastructure supports the organization’s attack surface as a third-party dependency.


Question 6

A security architect needs a tool that can provide an external view of the organization’s public-facing infrastructure and discover previously unknown hosts, domains, and IP addresses.

Which characteristic most directly distinguishes Defender EASM from a traditional cloud-resource inventory?

A. EASM begins with an outside-in perspective of internet-exposed infrastructure

B. EASM only inventories Azure virtual machines

C. EASM requires every discovered asset to be an Azure resource

D. EASM can only discover resources that are manually entered by administrators

Answer: A

Explanation

A is correct. The defining characteristic of EASM is its outside-in perspective. It starts with known external assets and recursively discovers related internet-facing infrastructure.

B is incorrect because EASM isn’t limited to Azure VMs.

C is incorrect because EASM discovers externally exposed infrastructure that does not necessarily correspond to Azure resource objects.

D is incorrect because the purpose of recursive discovery is precisely to identify infrastructure that administrators may not have manually entered.


Question 7

A security analyst wants to investigate whether a public IP address associated with an organization’s attack surface has previously been associated with suspicious or malicious activity.

Which Defender EASM capability should the analyst examine?

A. Discovery seed configuration

B. Asset state

C. Azure RBAC

D. IP reputation

Answer: D

Explanation

D is correct. Defender EASM provides an IP reputation view that can identify potential threats and suspicious activity associated with an IP address, including appearances on threat lists.

A is incorrect because discovery seeds determine where discovery starts.

B is incorrect because asset state describes how the organization categorizes an asset.

C is incorrect because Azure RBAC controls access to resources and data; it doesn’t provide IP reputation information.


Question 8

A security team wants to understand the difference between Defender EASM and Microsoft Defender Vulnerability Management.

Which statement is most accurate?

A. EASM is primarily an endpoint detection and response system, while Defender Vulnerability Management is primarily a SIEM.

B. EASM and Defender Vulnerability Management are identical capabilities with different names.

C. EASM focuses on discovering and understanding internet-facing attack-surface exposure, while Defender Vulnerability Management focuses on vulnerability management for managed workloads and endpoints.

D. Defender Vulnerability Management discovers unknown public domains, while EASM scans operating-system vulnerabilities on Azure VMs.

Answer: C

Explanation

C is correct. EASM’s primary purpose is to discover and understand an organization’s external attack surface, including unknown internet-facing infrastructure. Defender Vulnerability Management focuses on identifying, assessing, and prioritizing vulnerabilities on managed systems and endpoints.

A is incorrect because neither description is accurate.

B is incorrect because the two technologies serve complementary but distinct purposes.

D is incorrect because it reverses the primary responsibilities of the two technologies.


Question 9

An organization uses Defender CSPM and wants external attack-surface information to contribute to its overall cloud security posture and attack-path analysis.

Which integration should the organization use?

A. Defender EASM integration with Defender CSPM

B. Azure Bastion integration with Microsoft Sentinel

C. Azure Key Vault integration with Defender for Endpoint

D. Azure Policy integration with Defender Vulnerability Management

Answer: A

Explanation

A is correct. Defender EASM integrates with Defender CSPM to provide external attack-surface information that can contribute to security-posture analysis and attack-path analysis. The current Defender for Cloud implementation provides this external attack-surface capability through the Defender EASM integration.

B, C, and D are incorrect because those combinations do not provide the EASM external attack-surface integration described in the scenario.


Question 10

A security analyst has been given access to a Defender EASM resource. The analyst only needs to view the organization’s attack-surface information and must not be able to modify resources or inventory assets.

Which Azure RBAC role is most appropriate?

A. Owner

B. Contributor

C. Reader

D. Global Administrator

Answer: C

Explanation

C is correct. The Defender EASM documentation identifies the Reader role as providing the ability to view Defender EASM data without allowing the user to create, delete, or edit resources or inventory assets.

A is incorrect because Owner provides extensive management permissions beyond the analyst’s requirement.

B is incorrect because Contributor can create, delete, and edit EASM resources and inventory assets.

D is incorrect because Global Administrator is a Microsoft Entra directory role and is not the appropriate least-privilege choice for simply viewing Defender EASM data.


Final Word

For this exam objective, place some emphasis on discovery seeds → recursive discovery → inventory → asset states → vulnerabilities/exposure → risk prioritization. Those concepts are more important for the SC-500 exam than memorizing portal navigation. The distinction between Candidate, Dependency, Monitor Only, and Approved Inventory is especially worth studying because it lends itself naturally to scenario-based exam questions.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply