This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
--> Manage security posture by using Defender for Cloud
--> Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management (EASM)
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
Modern organizations rarely have a completely static IT environment.
Applications are deployed across Azure and other clouds. Developers create new internet-facing services. Acquisitions introduce unfamiliar domains and infrastructure. Third-party providers host applications and content. Old systems remain online after their owners have forgotten about them. Certificates, DNS records, IP addresses, and web applications continually change.
This creates a security problem:
How can an organization secure assets that it doesn’t even know it owns or exposes to the internet?
Microsoft Defender External Attack Surface Management (Defender EASM) addresses this problem by providing an outside-in view of an organization’s internet-exposed infrastructure.
Rather than starting with an Azure subscription or a known cloud resource, Defender EASM starts with known organizational assets—called discovery seeds—and recursively discovers related infrastructure. The resulting information is organized into an inventory that can expose unknown assets, third-party dependencies, vulnerabilities, and other security risks.
An important exam distinction is that Defender EASM uses an outside-in view of the internet to discover assets that may be unknown or unmanaged, complementing the resource-centric view provided by other Defender capabilities. The current Defender for Cloud integration also provides external attack-surface-management capabilities through Defender CSPM without requiring a separate Defender EASM license or special configuration.
For the SC-500 exam, this topic is particularly important because you need to understand:
- What Defender EASM is
- What an external attack surface is
- How EASM differs from traditional vulnerability scanning
- How discovery seeds work
- How recursive discovery finds unknown assets
- What types of assets EASM discovers
- How assets are classified
- The difference between approved, candidate, dependency, monitor-only, and investigation-required assets
- How EASM identifies vulnerabilities and security-hygiene issues
- How dashboards and inventory are used to prioritize risk
- How EASM complements Defender for Cloud and Defender CSPM
- How EASM can contribute to attack-path analysis
- How organizations can manage discovered assets
- How to distinguish EASM from Defender for Cloud’s cloud inventory and Defender Vulnerability Management
1. What Is Microsoft Defender External Attack Surface Management?
Microsoft Defender External Attack Surface Management (EASM) continuously discovers and maps an organization’s digital attack surface from an external perspective.
The key phrase to remember is:
Outside-in
EASM looks at the organization’s infrastructure from the perspective of what can be discovered from the internet.
This allows security teams to identify:
- Unknown internet-facing infrastructure
- Previously unmonitored assets
- Web applications
- Domains
- Hosts
- IP addresses
- IP address blocks
- SSL certificates
- Third-party dependencies
- Potential vulnerabilities
- Security-hygiene problems
- Suspicious or potentially malicious infrastructure relationships
Microsoft describes Defender EASM as providing visibility that helps organizations identify unknowns, prioritize risk, eliminate threats, and extend vulnerability and exposure management beyond the firewall.
The fundamental problem EASM solves
Traditional security programs often begin with assets that the organization already knows about.
For example:
“Show me all the virtual machines in this Azure subscription.”
That is useful, but it doesn’t answer:
“What internet-facing infrastructure associated with our organization exists that we don’t know about?”
EASM is designed to help answer the second question.
2. What Is an External Attack Surface?
An organization’s external attack surface consists broadly of infrastructure and services that are exposed or discoverable from the public internet.
Examples include:
- Public websites
- Internet-facing applications
- Public IP addresses
- DNS domains
- Hosts
- Web pages
- SSL certificates
- Publicly exposed services
- Third-party infrastructure supporting organizational applications
The external attack surface changes constantly.
For example:
New application deployed ↓New DNS record ↓New public hostname ↓New SSL certificate ↓New internet-facing service ↓New potential attack surface
A security team that relies entirely on manually maintained asset inventories may not discover every change.
Defender EASM continuously monitors and updates its understanding of the organization’s externally exposed infrastructure.
3. Why External Attack Surface Management Matters
Security controls are only effective when organizations know what they need to protect.
Consider an organization that believes it has:
- 50 public-facing websites
- 100 public IP addresses
- 20 internet-facing applications
EASM might discover additional infrastructure associated with those known assets.
For example:
Known corporate domain | +--- Web host | | | +--- Web application | +--- SSL certificate | +--- Related IP block | | | +--- Additional host | +--- WHOIS contact | +--- Additional organization asset
The newly discovered infrastructure may represent:
- Legitimate infrastructure
- A third-party dependency
- A forgotten asset
- A development environment
- Shadow IT
- An incorrectly categorized asset
- An asset requiring further investigation
This is one of the major security benefits of EASM.
4. How Defender EASM Discovery Works
The core concept behind EASM discovery is recursive discovery.
The process begins with assets that are known to belong to the organization.
These are called:
Discovery seeds
Defender EASM analyzes the known assets and observes relationships between them and other internet infrastructure.
It then follows those relationships to discover additional assets.
The process can be represented as:
Known Asset ↓Discovery Seed ↓Observe relationships ↓Discover connected infrastructure ↓Analyze newly discovered assets ↓Follow additional relationships ↓Build attack-surface inventory
Microsoft’s proprietary discovery technology recursively searches through observed connections to known legitimate assets and uses those connections to infer relationships between infrastructure.
5. What Is a Discovery Seed?
A discovery seed is a known asset that Defender EASM uses as a starting point for discovering additional infrastructure.
Examples include:
- Domain names
- Hosts
- IP addresses or IP ranges
- Autonomous System Numbers (ASNs)
- Email addresses
- WHOIS organization information
For example, suppose a company owns:
contoso.com
The organization can use that known domain as a discovery seed.
Defender EASM can then investigate relationships involving that domain and potentially identify:
contoso.com ↓www.contoso.com ↓public IP address ↓IP block ↓additional host ↓related certificate
The objective is not simply to scan the original domain.
The objective is to understand the broader infrastructure connected to it.
6. Automated Discovery vs. Custom Discovery
Defender EASM supports automated attack-surface discovery as well as customized discovery.
Automated discovery
Microsoft has preconfigured attack surfaces for many organizations.
When starting with Defender EASM, Microsoft recommends searching for the organization’s existing attack surface before immediately creating a custom attack surface.
This allows an organization to take advantage of infrastructure that has already been identified and then allow Defender EASM to continue refreshing and expanding the inventory.
Custom discovery
Custom discovery is useful when an organization wants to investigate infrastructure that may not be sufficiently connected to its primary known assets.
For example:
- A recently acquired company
- A newly established business unit
- A subsidiary
- A newly purchased domain
- A known IP range
- An infrastructure relationship not discovered through the primary attack surface
Custom discoveries use selected seeds as starting points.
7. Discovery Seeds Cannot Be Private IP Addresses
An important exam detail is that Defender EASM is designed to provide an external perspective.
Therefore, private IP addresses cannot be used as discovery seeds.
The discovery process focuses on infrastructure that can be observed from the internet rather than internal-only addressing.
Exam scenario
If a question asks:
An administrator wants to create an EASM discovery group using an internal private IP address as the seed. What should the administrator do?
The correct concept is:
Use an externally discoverable asset instead.
8. Types of Assets Defender EASM Can Discover
Defender EASM’s inventory can contain several asset types.
Important asset types include:
| Asset type | Example |
|---|---|
| Domains | contoso.com |
| Hosts | www.contoso.com |
| Pages | Web pages associated with hosts |
| IP addresses | Public IP addresses |
| IP blocks | Public address ranges |
| ASNs | Autonomous System Numbers |
| SSL certificates | Certificates associated with internet-facing services |
| WHOIS contacts | Registration/contact information |
Microsoft’s current EASM documentation identifies domains, IP address blocks, hosts, email contacts, ASNs, and WHOIS organizations as core discovery asset types; the inventory also includes pages, IP addresses, and SSL certificates.
Exam tip
If a question asks which technology can help discover an organization’s:
“unknown internet-facing domains, hosts, IP addresses, and related infrastructure”
think:
Defender EASM
9. The Defender EASM Inventory
Discovered assets are indexed into the Defender EASM inventory.
The inventory acts as a dynamic record of the organization’s externally visible infrastructure.
This is important because the attack surface is not static.
An asset might:
- Appear
- Disappear
- Change ownership
- Change infrastructure
- Become inactive
- Become associated with a new application
- Develop a new vulnerability
Defender EASM tracks these changes as part of its continuously updated attack-surface view.
10. Asset States
One of the most important SC-500 exam concepts is that not every discovered asset is automatically treated as an organizational asset.
Defender EASM uses different asset states to help organizations categorize discovered infrastructure.
Current asset states include:
- Approved Inventory
- Dependency
- Monitor Only
- Candidate
- Requires Investigation
Understanding these states is important for exam questions involving asset ownership and classification.
11. Approved Inventory
Approved Inventory represents an asset that has been determined to belong to the organization’s attack surface and for which the organization is directly responsible.
For example:
Company-owned website ↓Approved Inventory
This means the organization should normally consider the asset part of its managed security scope.
12. Dependency
A Dependency is infrastructure owned by another party but used to support the organization’s attack surface.
For example, a company may have a website hosted by a third-party provider.
The company owns the website and domain, but the underlying hosting infrastructure may belong to the provider.
The external infrastructure may therefore be classified as a dependency.
This distinction is important because:
The asset can be relevant to your attack surface even though you don’t directly own or control it.
Microsoft gives third-party hosting as an example of infrastructure that can be classified as a dependency.
13. Monitor Only
Monitor Only is useful when an asset is relevant to the organization’s attack surface but isn’t directly controlled by the organization and isn’t a technical dependency.
For example:
- An independently operated franchise
- A related organization
- An asset belonging to a related company
The organization may want visibility into the asset without treating it as directly owned infrastructure.
14. Candidate
A Candidate asset has a relationship to known organizational assets but does not have a strong enough relationship for Defender EASM to automatically classify it as approved inventory.
A security administrator should review the asset and determine its appropriate classification.
For example:
Known company domain ↓Related host discovered ↓Relationship uncertain ↓Candidate ↓Manual review
This is an important distinction.
A discovered asset does not necessarily mean:
“This definitely belongs to our organization.”
Instead, Defender EASM provides evidence and relationship information so security teams can make the determination.
15. Requires Investigation
Requires Investigation is another state that identifies assets requiring additional human analysis.
Defender EASM uses internally generated confidence information to determine whether relationships between assets are sufficiently strong.
A Requires Investigation designation means:
The relationship needs further validation.
It does not necessarily mean the asset is malicious.
It means the organization should investigate its relationship to the known attack surface.
16. Understanding the Discovery Chain
The discovery chain helps security professionals understand why Defender EASM believes an asset is related to the organization.
For example:
Known domain ↓WHOIS contact ↓IP block ↓IP address ↓Host
The discovery chain provides evidence about the relationships connecting a discovered asset to a known seed.
This is extremely useful when investigating potentially unknown infrastructure.
Rather than simply saying:
“We found this IP address.”
Defender EASM can help answer:
“Why does Defender EASM believe this IP address is related to our organization?”
17. Asset Approval
Some discovered assets can be automatically approved when Defender EASM determines that the relationship to the known seed is sufficiently strong.
Other assets require manual review.
The current discovery information distinguishes between:
Approved inventory
and
Candidate
based on the strength of the relationship and approval process.
Exam scenario
If an asset is discovered but there isn’t enough evidence to automatically establish ownership, don’t assume it is automatically approved.
Think:
Candidate → investigate/approve appropriately.
18. Vulnerability Discovery
Defender EASM isn’t only an asset-discovery tool.
It also provides information that can help security teams identify vulnerabilities and other risks associated with externally exposed infrastructure.
For example, EASM can surface:
- Vulnerabilities
- CVEs
- Weak security configurations
- SSL/TLS issues
- Exposed services
- Security-hygiene problems
- Potentially risky infrastructure
These insights help organizations prioritize which parts of their external attack surface require attention.
19. EASM and CVEs
Defender EASM can associate known vulnerabilities with externally discovered assets.
For example:
Internet-facing host ↓Detected software ↓Known vulnerability ↓CVE ↓Risk prioritization ↓Remediation
This provides a useful external perspective on vulnerability exposure.
However, remember that EASM is fundamentally concerned with the external attack surface.
It is not simply another name for Defender Vulnerability Management.
20. Defender EASM vs. Defender Vulnerability Management
This distinction is highly relevant to SC-500.
| Capability | Defender EASM | Defender Vulnerability Management |
|---|---|---|
| Primary focus | External attack surface | Vulnerability/exposure management |
| Perspective | Outside-in | Primarily workload/endpoint-oriented |
| Unknown internet-facing assets | Strong capability | Not its primary purpose |
| Discover domains and hosts | Yes | Not its primary purpose |
| Discover public IP infrastructure | Yes | Not its primary purpose |
| Identify software vulnerabilities | Yes, as part of external attack-surface insights | Core capability |
| Endpoint software inventory | Not primary | Strong capability |
| Defender for Endpoint integration | Not its primary purpose | Yes |
| Azure VM vulnerability assessment | Not its primary purpose | Yes |
A useful mental model is:
EASM asks, “What can the internet see that belongs to us?”
while:
Defender Vulnerability Management asks, “What vulnerabilities exist on the systems we’re managing?”
These capabilities complement one another.
21. Defender EASM vs. Defender for Cloud Inventory
Another important distinction is between EASM and the Defender for Cloud cloud inventory.
Defender for Cloud’s inventory provides a resource-centric view of connected cloud resources, including Azure, AWS, and GCP resources.
For example:
Azure subscription ↓VMStorage accountSQL databaseContainerAI service
EASM takes a different approach:
Internet ↓Known public asset ↓Related infrastructure ↓Unknown external assets ↓External attack surface
Defender for Cloud inventory is therefore useful for understanding the security state of known connected cloud resources, while EASM helps uncover internet-facing infrastructure that may not be represented in the organization’s cloud-resource inventory.
22. EASM and Defender CSPM
Defender EASM is particularly important in conjunction with Defender Cloud Security Posture Management (Defender CSPM).
Current Defender for Cloud functionality integrates external attack-surface-management capabilities through Defender EASM.
This integration allows organizations to improve their security posture by incorporating an external view of attack-surface exposure.
Importantly, Microsoft currently states that the external attack-surface-management capability integrated into Defender CSPM is included with the Defender CSPM plan and doesn’t require a separate Defender EASM license or special configuration.
Exam tip
Don’t automatically assume:
“Defender EASM always requires a separate EASM license.”
The current Defender CSPM integration changes this distinction.
23. EASM and Attack Path Analysis
EASM findings can also complement attack path analysis.
The SC-500 training specifically calls out the integration of EASM findings with Defender CSPM for attack-path analysis.
The significance is that an organization can move beyond simply asking:
“What assets are exposed?”
and begin asking:
“Which exposed assets create meaningful attack paths into important resources?”
For example:
Internet-facing asset ↓Vulnerability ↓Compromised workload ↓Lateral movement ↓Sensitive resource
Attack-path analysis helps security teams focus on exposures that could contribute to meaningful attack scenarios.
24. EASM Dashboards
Defender EASM provides dashboards designed to help organizations understand their attack surface.
Dashboard insights can focus on areas such as:
- Vulnerabilities
- Security hygiene
- Compliance
- Infrastructure
- Asset exposure
These dashboards help security teams prioritize the areas presenting the greatest risk rather than reviewing every discovered asset individually.
25. Security Hygiene
Not every security problem is necessarily a traditional software vulnerability.
For example, an organization might have:
- An expired or weak SSL certificate
- Unexpected exposed ports
- Unnecessary internet-facing infrastructure
- An outdated service
- An unexpected host
- An unmanaged domain
These conditions can contribute to an organization’s overall security hygiene.
EASM dashboards and inventory capabilities help surface these conditions so organizations can investigate and remediate them.
26. IP Reputation
Defender EASM also provides IP reputation information.
The IP reputation information can identify potential threats associated with an IP address, including evidence that the address has appeared on threat lists.
For example, an IP address could have been associated with suspicious activity or a known malicious host.
This information provides additional context when evaluating an externally exposed asset.
Important distinction
An IP appearing in threat intelligence does not automatically prove that the organization’s current system is compromised.
It is an indicator that warrants investigation.
27. Connected Assets
The Defender EASM asset details experience provides a Connected assets view.
This allows security professionals to understand other assets connected to a particular asset.
For example:
Domain | +-- Host | +-- IP address | +-- SSL certificate | +-- Web page
Understanding connected assets is valuable because a security issue involving one component may reveal additional infrastructure that needs investigation.
28. JavaScript and Web Resources
Defender EASM can also provide visibility into resources associated with web assets.
For example, it can identify JavaScript resources associated with pages or hosts.
Information can include:
- Resource URL
- Resource host
- MD5 hash
- First-seen date
- Last-seen date
This provides another layer of visibility into the technologies and resources used by externally exposed web applications.
29. SSL Certificate Visibility
SSL certificates are another important component of the external attack surface.
Certificates can provide relationships between:
- Domains
- Hosts
- Infrastructure
- Organizations
An unexpected certificate can sometimes reveal infrastructure that wasn’t present in a manually maintained inventory.
For this reason, certificate information can be valuable during external attack-surface discovery.
30. Managing EASM Inventory Assets
Defender EASM doesn’t just discover assets.
Security teams can also manage the inventory.
Current capabilities include:
- Changing asset states
- Adding labels
- Assigning external IDs
- Removing labels
- Marking observations as not applicable
- Removing assets from inventory
- Managing assets discovered through specific seeds
- Tracking changes through Task Manager
For example, an organization can label an asset according to an internal classification such as:
ProductionDevelopmentAcquisitionThird-partyCriticalRequires Review
Labels provide additional organizational context.
31. Marking an Observation as Not Applicable
An important management capability is the ability to mark certain observations as not applicable.
For example, a security team may investigate a vulnerability or other observation and determine that it does not apply to the organization’s specific situation.
Rather than ignoring the issue informally, the organization can manage the observation within the EASM inventory.
This helps maintain more accurate reporting.
32. Removing Assets
Defender EASM also provides mechanisms for removing assets from inventory.
For example, when removing a discovery seed, an administrator can choose to remove assets that were discovered through a connection to that seed.
This is useful when an organization determines that:
- A seed no longer belongs to it
- An acquisition has been divested
- An infrastructure relationship is no longer relevant
- The inventory needs to be corrected
33. EASM and Shadow IT
One of the strongest practical use cases for EASM is discovering shadow IT and previously unknown external infrastructure.
Consider this scenario:
A development team launches:
test-new-app.company-example.com
The security team isn’t informed.
The application becomes publicly accessible.
Traditional security inventory:
Unknown
EASM:
Internet discovery ↓Related domain discovered ↓Host discovered ↓Application identified ↓Potential vulnerability detected
This provides security teams with visibility into infrastructure that may have bypassed normal inventory and security-review processes.
34. EASM for Mergers and Acquisitions
EASM can also be valuable during mergers and acquisitions.
Suppose Company A acquires Company B.
Company A may receive:
- New domains
- Public IP ranges
- Websites
- Web applications
- Certificates
- Hosts
- Third-party dependencies
The acquiring organization’s existing asset inventory may not immediately contain all of this infrastructure.
EASM can help establish an external view of the acquired organization’s attack surface.
35. EASM and Third-Party Dependencies
An organization may depend on infrastructure it doesn’t directly own.
For example:
Company website ↓Third-party hosting provider ↓External infrastructure
That external infrastructure may be classified as a Dependency.
This is important because:
Security responsibility may differ from ownership.
An organization can have a security exposure resulting from a third party even when the organization doesn’t directly manage the underlying infrastructure.
36. A Typical EASM Investigation
Consider an organization that believes all of its public infrastructure is known.
Step 1 — Start with known assets
Provide known:
- Domains
- Hosts
- IP blocks
- Other supported identifiers
Step 2 — Run discovery
Defender EASM recursively examines relationships among internet-facing infrastructure.
Step 3 — Review the inventory
The security team examines discovered assets.
Step 4 — Classify assets
Assets may be:
- Approved Inventory
- Dependency
- Monitor Only
- Candidate
- Requires Investigation
Step 5 — Investigate unknown assets
The security team examines:
- Discovery chains
- Connected assets
- IP reputation
- Vulnerabilities
- Web resources
- Certificates
Step 6 — Prioritize risk
Security teams use dashboards and vulnerability information to identify the most important exposures.
Step 7 — Remediate
Examples include:
- Remove unnecessary public exposure
- Patch vulnerable software
- Replace certificates
- Secure misconfigured services
- Remove abandoned infrastructure
- Transfer remediation to the appropriate third-party owner
Step 8 — Continue monitoring
The organization continues monitoring its changing external attack surface.
37. EASM Outside-In vs. Traditional Inside-Out Security
This is perhaps the most important conceptual distinction for the exam.
Traditional cloud security
Starts with:
Known Azure resource ↓Configuration ↓Security posture ↓Recommendations
Defender EASM
Starts with:
Internet ↓Known organizational asset ↓Related infrastructure ↓Unknown assets ↓External vulnerabilities ↓Attack-surface risk
Neither approach replaces the other.
They answer different questions.
38. EASM Does Not Replace Defender for Cloud
It is important not to interpret EASM as a replacement for Defender for Cloud.
Instead, think of the technologies as complementary.
| Security question | Appropriate capability |
|---|---|
| What Azure resources do we have? | Defender for Cloud inventory |
| What security recommendations affect our Azure resources? | Defender for Cloud |
| What vulnerabilities exist on protected VMs? | Defender Vulnerability Management |
| What internet-facing infrastructure belongs to us? | Defender EASM |
| What unknown domains/hosts/IP infrastructure exists? | Defender EASM |
| What externally exposed vulnerabilities exist? | Defender EASM |
| What attack paths involve external exposure? | Defender CSPM + EASM integration |
39. Permissions
Defender EASM uses Azure RBAC.
Current documentation identifies the following general roles:
Owner
An Owner can:
- Create EASM resources
- Delete resources
- Edit resources
- Manage inventory assets
- Use EASM capabilities
Contributor
A Contributor can also create, delete, and edit EASM resources and inventory assets.
Reader
A Reader can:
- View Defender EASM data
but cannot create, delete, or edit resources or inventory assets.
Exam tip
If the question says:
“The user only needs to view EASM data.”
Think:
Reader
If the user needs to modify inventory or resources:
Contributor or Owner, depending on the required scope and operation.
40. Current Defender CSPM Integration
A particularly important current-platform consideration is the integration between Defender EASM and Defender CSPM.
Microsoft currently describes external attack-surface-management functionality in Defender for Cloud as being provided through integration with Defender EASM.
The capability is included with the Defender CSPM plan by default and does not require a separate Defender EASM license or special configuration for that integrated capability.
This makes external attack-surface visibility part of a broader cloud-security-posture strategy.
41. Security Copilot Integration
Current Defender EASM also supports integration with Microsoft Security Copilot.
Security Copilot can be used to interact with Defender EASM data using natural-language prompts.
For example, security teams can ask questions about:
- External attack surface
- Critical risks
- CVEs
- SSL certificates
- Exposed ports
- Specific assets
It can also help with attack-surface curation, including working with labels, external IDs, and asset states.
For SC-500, however, the foundational concept remains:
EASM provides external attack-surface discovery and visibility.
42. Common EASM Misconceptions
Misconception 1: EASM is just another vulnerability scanner
Not exactly.
Vulnerability discovery is an important capability, but the primary purpose is to understand the external attack surface.
Misconception 2: EASM only scans Azure
Incorrect.
EASM is concerned with internet-facing infrastructure and can discover assets across an organization’s external digital environment rather than limiting itself to Azure resource types.
Misconception 3: Every discovered asset belongs to the organization
Incorrect.
Assets can be classified as:
- Approved Inventory
- Dependency
- Monitor Only
- Candidate
- Requires Investigation
Misconception 4: Candidate means malicious
Incorrect.
Candidate means the relationship to the organization requires review.
Misconception 5: Dependency means the organization owns the infrastructure
Incorrect.
A dependency can be infrastructure owned by another organization but supporting the organization’s attack surface.
Misconception 6: EASM replaces Defender Vulnerability Management
Incorrect.
EASM and Defender Vulnerability Management provide complementary capabilities.
Misconception 7: EASM only looks at internal Azure inventory
Incorrect.
Its defining characteristic is the external, outside-in perspective.
Misconception 8: Private IP addresses can be used as discovery seeds
Incorrect.
Private IP addresses cannot be used as Defender EASM discovery seeds.
43. SC-500 Exam-Focused Comparison
| Scenario | Think |
|---|---|
| Discover unknown public domains | Defender EASM |
| Discover unknown internet-facing hosts | Defender EASM |
| Discover external IP infrastructure | Defender EASM |
| Map relationships between known and unknown public assets | EASM discovery |
| Start discovery from a known domain | Discovery seed |
| Determine why an asset was associated with the organization | Discovery chain |
| Asset ownership uncertain | Candidate / Requires Investigation |
| Third-party infrastructure supporting an application | Dependency |
| Related but independently controlled organization infrastructure | Monitor Only |
| Asset directly owned and managed by organization | Approved Inventory |
| Find vulnerabilities associated with externally exposed assets | Defender EASM |
| Scan Azure VM software for vulnerabilities | Defender Vulnerability Management |
| Get cloud-resource inventory | Defender for Cloud Inventory |
| Use external attack-surface information for attack-path analysis | Defender CSPM + EASM |
| View EASM information without modifying it | Reader |
| Modify EASM inventory | Contributor/Owner |
| Use a private IP as a discovery seed | Not supported |
44. Key Takeaways
For the SC-500 exam, remember the following:
- Defender EASM provides an outside-in view of an organization’s internet-exposed attack surface.
- EASM uses discovery seeds as starting points.
- Discovery is recursive—Defender EASM follows observed relationships to discover additional infrastructure.
- Discovery seeds can include known domains, hosts, IP ranges, ASNs, email information, and WHOIS-related identifiers.
- Private IP addresses cannot be used as discovery seeds.
- EASM can discover assets such as domains, hosts, pages, IP addresses, IP blocks, ASNs, SSL certificates, and WHOIS-related information.
- Discovered assets are maintained in the Defender EASM inventory.
- Important asset states include:
- Approved Inventory
- Dependency
- Monitor Only
- Candidate
- Requires Investigation
- A Candidate asset requires additional review before being treated as approved organizational infrastructure.
- A Dependency can be owned by a third party but still be relevant to the organization’s attack surface.
- The discovery chain helps explain why Defender EASM believes an asset is connected to the organization.
- EASM can surface vulnerabilities, CVEs, IP reputation information, SSL-related issues, and other security-hygiene concerns.
- EASM is not simply another name for Defender Vulnerability Management.
- Defender Vulnerability Management focuses primarily on vulnerability management for managed workloads/endpoints, whereas EASM emphasizes the organization’s externally observable attack surface.
- Defender EASM complements Defender for Cloud rather than replacing it.
- Current Defender CSPM functionality integrates external attack-surface management through Defender EASM without requiring a separate EASM license for that integrated capability.
- EASM findings can complement Defender CSPM attack-path analysis.
- The fundamental EASM question is:
“What can the internet see that belongs to our organization?”
- The fundamental vulnerability-management question is:
“What vulnerabilities exist on the systems we’re managing?”
- For the exam, remember:
Known asset → Discovery seed → Recursive discovery → External attack-surface inventory → Classify assets → Identify vulnerabilities/exposures → Prioritize risk → Remediate.
Practice Exam Questions
Question 1
A security team is concerned that developers may have deployed internet-facing applications that are not included in the organization’s official asset inventory. The team wants to discover unknown public-facing domains, hosts, and related infrastructure associated with the organization.
Which Microsoft solution is most appropriate?
A. Azure Policy
B. Microsoft Defender for Endpoint
C. Microsoft Defender External Attack Surface Management
D. Microsoft Sentinel
Answer: C
Explanation
A is correct. Defender EASM is specifically designed to provide an external, outside-in view of an organization’s internet-facing attack surface. Its recursive discovery capabilities can uncover previously unknown and unmonitored infrastructure connected to known organizational assets.
B is incorrect because Defender for Endpoint primarily provides endpoint protection, detection, and response capabilities.
C is incorrect because Azure Policy governs Azure resources and configurations rather than discovering an organization’s unknown public internet infrastructure.
D is incorrect because Sentinel is a SIEM/SOAR platform rather than an external attack-surface discovery service.
Question 2
An administrator wants to create a custom Defender EASM discovery group. The administrator has identified a known company-owned domain that should be used as the starting point for discovery.
What should the administrator configure?
A. A private IP address
B. A security recommendation
C. The company-owned domain as a discovery seed
D. An Azure Resource Graph query
Answer: C
Explanation
C is correct. A discovery seed is a known organizational asset that Defender EASM uses as a starting point for recursive discovery. Domains, hosts, IP ranges, and other supported identifiers can be used as seeds.
A is incorrect because private IP addresses cannot be used as Defender EASM discovery seeds.
B is incorrect because a security recommendation isn’t a discovery seed.
D is incorrect because Azure Resource Graph is used to query Azure resource information and isn’t the mechanism for defining EASM discovery seeds.
Question 3
Defender EASM discovers an IP address associated with a known corporate domain. The security team wants to understand why EASM determined that the IP address is related to the organization.
Which capability should the team examine?
A. Security baseline assessment
B. Discovery chain
C. Azure Policy compliance
D. CVSS score
Answer: B
Explanation
B is correct. The discovery chain provides information about the observed relationships between a discovery seed and a discovered asset. It helps security professionals understand why Defender EASM associated an asset with their organization.
A is incorrect because security baseline assessment evaluates machine configuration rather than EASM asset relationships.
C is incorrect because Azure Policy compliance doesn’t explain EASM discovery relationships.
D is incorrect because CVSS relates to vulnerability severity rather than asset discovery relationships.
Question 4
A Defender EASM discovery operation identifies an external host that appears to be related to the organization. However, the relationship isn’t strong enough for the asset to be automatically classified as part of the organization’s approved inventory.
What asset state should the security team expect?
A. Approved Inventory
B. Dependency
C. Monitor Only
D. Candidate
Answer: D
Explanation
D is correct. A Candidate asset has a relationship to known organizational assets but doesn’t have sufficient evidence to be automatically treated as approved inventory. It requires manual review to determine the appropriate classification.
A is incorrect because Approved Inventory indicates that the asset has been established as part of the organization’s owned attack surface.
B is incorrect because Dependency is used when infrastructure owned by another party supports the organization’s attack surface.
C is incorrect because Monitor Only is intended for relevant assets that aren’t directly controlled and aren’t necessarily technical dependencies.
Question 5
A company hosts its public web application with a third-party provider. Defender EASM identifies the third-party infrastructure as being directly associated with the company’s externally exposed application, but the company does not own the underlying hosting infrastructure.
How should this infrastructure generally be classified?
A. Candidate
B. Dependency
C. Approved Inventory
D. Requires Investigation
Answer: B
Explanation
B is correct. A Dependency represents infrastructure owned by a third party that directly supports the organization’s attack surface. Third-party hosting is a typical example.
A is incorrect because Candidate is primarily used when the relationship to the organization requires additional ownership validation.
C is incorrect because the scenario explicitly states that the organization does not own the infrastructure.
D is incorrect because the scenario provides sufficient information to establish that the infrastructure supports the organization’s attack surface as a third-party dependency.
Question 6
A security architect needs a tool that can provide an external view of the organization’s public-facing infrastructure and discover previously unknown hosts, domains, and IP addresses.
Which characteristic most directly distinguishes Defender EASM from a traditional cloud-resource inventory?
A. EASM begins with an outside-in perspective of internet-exposed infrastructure
B. EASM only inventories Azure virtual machines
C. EASM requires every discovered asset to be an Azure resource
D. EASM can only discover resources that are manually entered by administrators
Answer: A
Explanation
A is correct. The defining characteristic of EASM is its outside-in perspective. It starts with known external assets and recursively discovers related internet-facing infrastructure.
B is incorrect because EASM isn’t limited to Azure VMs.
C is incorrect because EASM discovers externally exposed infrastructure that does not necessarily correspond to Azure resource objects.
D is incorrect because the purpose of recursive discovery is precisely to identify infrastructure that administrators may not have manually entered.
Question 7
A security analyst wants to investigate whether a public IP address associated with an organization’s attack surface has previously been associated with suspicious or malicious activity.
Which Defender EASM capability should the analyst examine?
A. Discovery seed configuration
B. Asset state
C. Azure RBAC
D. IP reputation
Answer: D
Explanation
D is correct. Defender EASM provides an IP reputation view that can identify potential threats and suspicious activity associated with an IP address, including appearances on threat lists.
A is incorrect because discovery seeds determine where discovery starts.
B is incorrect because asset state describes how the organization categorizes an asset.
C is incorrect because Azure RBAC controls access to resources and data; it doesn’t provide IP reputation information.
Question 8
A security team wants to understand the difference between Defender EASM and Microsoft Defender Vulnerability Management.
Which statement is most accurate?
A. EASM is primarily an endpoint detection and response system, while Defender Vulnerability Management is primarily a SIEM.
B. EASM and Defender Vulnerability Management are identical capabilities with different names.
C. EASM focuses on discovering and understanding internet-facing attack-surface exposure, while Defender Vulnerability Management focuses on vulnerability management for managed workloads and endpoints.
D. Defender Vulnerability Management discovers unknown public domains, while EASM scans operating-system vulnerabilities on Azure VMs.
Answer: C
Explanation
C is correct. EASM’s primary purpose is to discover and understand an organization’s external attack surface, including unknown internet-facing infrastructure. Defender Vulnerability Management focuses on identifying, assessing, and prioritizing vulnerabilities on managed systems and endpoints.
A is incorrect because neither description is accurate.
B is incorrect because the two technologies serve complementary but distinct purposes.
D is incorrect because it reverses the primary responsibilities of the two technologies.
Question 9
An organization uses Defender CSPM and wants external attack-surface information to contribute to its overall cloud security posture and attack-path analysis.
Which integration should the organization use?
A. Defender EASM integration with Defender CSPM
B. Azure Bastion integration with Microsoft Sentinel
C. Azure Key Vault integration with Defender for Endpoint
D. Azure Policy integration with Defender Vulnerability Management
Answer: A
Explanation
A is correct. Defender EASM integrates with Defender CSPM to provide external attack-surface information that can contribute to security-posture analysis and attack-path analysis. The current Defender for Cloud implementation provides this external attack-surface capability through the Defender EASM integration.
B, C, and D are incorrect because those combinations do not provide the EASM external attack-surface integration described in the scenario.
Question 10
A security analyst has been given access to a Defender EASM resource. The analyst only needs to view the organization’s attack-surface information and must not be able to modify resources or inventory assets.
Which Azure RBAC role is most appropriate?
A. Owner
B. Contributor
C. Reader
D. Global Administrator
Answer: C
Explanation
C is correct. The Defender EASM documentation identifies the Reader role as providing the ability to view Defender EASM data without allowing the user to create, delete, or edit resources or inventory assets.
A is incorrect because Owner provides extensive management permissions beyond the analyst’s requirement.
B is incorrect because Contributor can create, delete, and edit EASM resources and inventory assets.
D is incorrect because Global Administrator is a Microsoft Entra directory role and is not the appropriate least-privilege choice for simply viewing Defender EASM data.
Final Word
For this exam objective, place some emphasis on discovery seeds → recursive discovery → inventory → asset states → vulnerabilities/exposure → risk prioritization. Those concepts are more important for the SC-500 exam than memorizing portal navigation. The distinction between Candidate, Dependency, Monitor Only, and Approved Inventory is especially worth studying because it lends itself naturally to scenario-based exam questions.
Go to the SC-500 Exam Prep Hub main page
