Tag: Defender for Cloud

Implement and configure security controls in Defender for Cloud, including security standards and recommendations (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
   --> Implement governance to enforce security and regulatory compliance
      --> Implement and configure security controls in Defender for Cloud, including security standards and recommendations


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

One of the responsibilities of a cloud and AI security engineer is to establish security controls that continuously evaluate cloud resources, identify security weaknesses, prioritize risks, and provide actionable remediation guidance.

Microsoft Defender for Cloud provides this capability through security policies, security standards, security controls, assessments, recommendations, and security posture management.

For the SC-500 exam, it is important to understand not only what Defender for Cloud can detect, but also how security standards and policies drive assessments and how those assessments produce recommendations that can be remediated.


1. What Is Microsoft Defender for Cloud?

Microsoft Defender for Cloud is a cloud security platform that provides capabilities for:

  • Cloud Security Posture Management (CSPM)
  • Cloud workload protection
  • Security recommendations
  • Security standards and compliance assessment
  • Vulnerability management
  • Security alerts
  • Multicloud security
  • Security posture monitoring
  • Risk prioritization

Defender for Cloud can assess resources across Azure, AWS, and Google Cloud Platform (GCP).

For this SC-500 topic, the most important concept is that Defender for Cloud continuously evaluates resources against defined security requirements and identifies resources that don’t meet those requirements.

The basic flow is:

Security Standard → Security Controls → Assessments → Findings/Recommendations → Remediation

This relationship is fundamental to understanding Defender for Cloud.


2. Understanding Security Policies

A security policy in Defender for Cloud defines how resources are evaluated for security.

Security policies incorporate:

  • Security standards
  • Security controls
  • Assessment logic
  • Conditions used to evaluate resources

Defender for Cloud continuously evaluates resources against the applicable security policies.

For example, an organization might establish a security requirement that storage accounts must restrict network access.

Defender for Cloud can evaluate storage accounts against that requirement.

If a storage account doesn’t satisfy the control, Defender for Cloud identifies the resource as noncompliant and can generate a recommendation explaining how to remediate the problem.

Important distinction

A security policy establishes the evaluation framework.

A security standard groups related security requirements.

A security control represents a specific security requirement or logical group of requirements.

An assessment determines whether a resource satisfies the applicable requirement.

A recommendation provides actionable guidance when a security issue is identified.

These terms are closely related, but they are not interchangeable.


3. Security Standards

Security standards provide a structured collection of security requirements against which Defender for Cloud evaluates resources.

Defender for Cloud supports several categories of security standards.

Security benchmarks

Benchmarks provide foundational security guidance.

The most important built-in benchmark to know for the SC-500 exam is the:

Microsoft Cloud Security Benchmark (MCSB)

MCSB provides Microsoft-recommended security best practices for cloud environments.

When Defender for Cloud is enabled for Azure, MCSB is enabled by default.

Defender for Cloud can also work with cloud-provider benchmarks for multicloud environments.


Regulatory compliance standards

Defender for Cloud also supports security standards associated with regulatory and industry frameworks.

Examples include standards associated with:

  • ISO 27001
  • NIST
  • PCI DSS
  • CIS
  • HIPAA
  • FedRAMP
  • SOC
  • CMMC
  • GDPR
  • DORA
  • Other supported industry and regulatory frameworks

The exact standards available depend on the cloud environment and Defender for Cloud capabilities.

These standards help organizations evaluate their cloud configuration against requirements associated with particular frameworks.

Important: Defender for Cloud helps identify technical security gaps related to a framework. It does not, by itself, certify an organization as compliant.


Custom security standards

Organizations can also define custom standards to represent their own security requirements.

For example, an organization could establish internal requirements such as:

  • Every production resource must have an owner tag.
  • Storage must use HTTPS.
  • Databases must not have unrestricted public access.
  • Certain resource types must use approved network configurations.

Custom recommendations can be incorporated into custom standards.

Current Defender for Cloud functionality allows custom recommendations to use Kusto Query Language (KQL) for assessment logic when the required Defender CSPM capability is enabled.


4. The Microsoft Cloud Security Benchmark

The Microsoft Cloud Security Benchmark (MCSB) is particularly important for the SC-500 exam.

MCSB provides a baseline of cloud security recommendations based on established security principles and best practices.

When Defender for Cloud is enabled for Azure, MCSB is the default security standard.

Defender for Cloud evaluates Azure resources against applicable MCSB controls and generates recommendations when resources don’t satisfy those controls.

Example

Suppose an organization has an Azure Storage account that permits unrestricted network access.

An applicable MCSB control requires network access to be appropriately restricted.

Defender for Cloud evaluates the storage account.

If the configuration doesn’t satisfy the control:

  1. The resource fails the applicable assessment.
  2. Defender for Cloud identifies the security issue.
  3. A recommendation is generated.
  4. The recommendation describes the problem.
  5. Remediation guidance is provided.
  6. The organization can correct the configuration.

This is the basic Defender for Cloud posture-management cycle.


5. Security Controls

A security control represents a particular security requirement that Defender for Cloud can evaluate.

Controls organize related security requirements into logical areas.

Examples of security concerns represented by controls can include:

  • Identity and access management
  • Network security
  • Data protection
  • Encryption
  • Logging and monitoring
  • Vulnerability management
  • Secure configuration
  • Resource hardening

A standard contains multiple controls, and controls are evaluated against applicable resources.

For example:

MCSB

→ Network Security control

→ Storage network-access requirement

→ Storage resources assessed

→ Noncompliant resources identified

→ Recommendation generated

The exact controls and mappings depend on the selected standard.


6. Assessments

An assessment is the evaluation performed against a resource to determine whether it satisfies a security requirement.

Think of an assessment as the question:

“Does this resource meet this security requirement?”

For example:

Does this storage account restrict network access appropriately?

The assessment produces a result indicating whether the applicable resource satisfies the requirement.

This is different from a recommendation.

Assessment vs. recommendation

ConceptPurpose
Security standardDefines the broader security framework
Security controlDefines a specific security requirement or logical group
AssessmentDetermines whether a resource satisfies the requirement
RecommendationExplains a security issue and how to remediate it

This distinction is highly relevant to scenario-based exam questions.


7. Security Recommendations

Security recommendations are actionable findings generated from security assessments.

A recommendation typically provides information such as:

  • Description of the security issue
  • Affected resources
  • Remediation instructions
  • Severity
  • Risk factors
  • Potential attack-path context, when available

A recommendation answers a practical question:

“What security problem should I fix, and how should I fix it?”

For example:

Problem: A storage account allows overly broad network access.

Recommendation: Restrict network access using appropriate network rules.

The recommendation gives the security team something actionable to address.


8. Security Recommendations and Secure Score

Defender for Cloud provides a Secure Score that helps organizations understand and improve their security posture.

Recommendations can contribute to Secure Score when they are associated with score-bearing security controls.

However, it is important not to confuse:

Secure Score

with

Regulatory Compliance

or

Security Recommendations.

They serve different purposes.

Secure Score

Focuses on improving overall security posture and prioritizing security improvements.

Regulatory Compliance

Focuses on assessing resources against selected compliance standards and their controls.

Security Recommendations

Identify specific security problems and provide remediation guidance.

A recommendation may therefore be relevant to both general security posture improvement and a compliance requirement, but these concepts are not identical.


9. Prioritizing Recommendations

Large cloud environments can generate many recommendations.

Defender for Cloud therefore provides information that helps security teams determine which recommendations should be addressed first.

Factors used in risk prioritization can include:

  • Exposure
  • Data sensitivity
  • Potential lateral movement
  • Exploitability
  • Other contextual risk information
  • Attack-path context, where available

Why prioritization matters

Consider an organization with 500 security recommendations.

It may not be practical to address all 500 immediately.

Instead, the security team might prioritize:

  1. Internet-exposed resources
  2. Resources containing sensitive data
  3. Vulnerable resources with known attack paths
  4. High-severity configuration weaknesses
  5. Lower-risk configuration improvements

This allows security teams to concentrate on the issues that present the greatest risk.


10. Security Recommendations vs. Security Alerts

This is another important distinction.

Security recommendation

Usually identifies a security posture or configuration weakness.

Examples:

  • Storage account should restrict network access.
  • MFA should be enabled.
  • A resource should use encryption.
  • A VM should have a recommended security configuration.

Security alert

Generally indicates a detected security threat or suspicious activity.

Examples:

  • Malware detected.
  • Suspicious activity detected.
  • A resource is involved in potentially malicious activity.

A useful way to remember the distinction is:

Recommendations help you harden your environment.

Alerts help you respond to detected threats.


11. Configuring Security Policies

Security policies determine which security requirements apply to an environment.

In Defender for Cloud, security policy configuration can be used to manage the standards applied to cloud environments.

For Azure environments, security standards are closely integrated with Azure Policy.

Defender for Cloud uses policy-based evaluation to assess resources against defined security requirements.

This is especially important when security requirements need to be applied consistently across large environments.


12. Azure Policy and Defender for Cloud

Azure Policy and Defender for Cloud are related but have different primary purposes.

Azure Policy

Azure Policy evaluates Azure resources against organizational rules.

It can be used to:

  • Audit configurations
  • Deny noncompliant deployments
  • Modify resource configurations
  • Deploy required configurations
  • Enforce organizational standards

Defender for Cloud

Defender for Cloud focuses on:

  • Security posture
  • Security assessments
  • Security recommendations
  • Security standards
  • Vulnerability and workload protection
  • Risk prioritization
  • Regulatory compliance

Defender for Cloud uses policy-based controls as part of its security evaluation capabilities.

For Azure, standards can be represented through Azure Policy initiatives, which group related policy definitions.

Exam takeaway

Don’t assume that Azure Policy and Defender for Cloud are competing products.

Instead:

Azure Policy provides policy-based governance and enforcement capabilities, while Defender for Cloud uses policy-based assessment as part of its broader cloud security posture-management capabilities.


13. Audit vs. Enforce

One of the most important governance concepts is the difference between detecting a problem and preventing the problem.

A security control might identify that resources are configured incorrectly.

That is different from preventing the deployment of an incorrectly configured resource.

Audit

An audit-oriented approach identifies noncompliant resources.

For example:

“Identify storage accounts that don’t meet the required security configuration.”

The resource can still exist, but the security issue is reported.

Deny

A deny-oriented policy can prevent a resource deployment or modification that violates the policy.

For example:

“Prevent creation of a storage account that violates the organization’s required security configuration.”

Important exam distinction

If the question asks:

“Which approach identifies existing noncompliant resources?”

Think audit/evaluation.

If it asks:

“Which approach prevents deployment of a noncompliant resource?”

Think deny/enforcement.


14. Security Recommendations Can Be Remediated

Identifying a problem is only the first step.

Defender for Cloud recommendations generally include remediation guidance.

A security administrator can investigate a recommendation and determine:

  • Which resources are affected
  • Why they are considered vulnerable or noncompliant
  • What configuration needs to change
  • Whether remediation can be performed automatically
  • Whether the issue should instead be handled through governance or deployment processes

This creates a continuous improvement cycle:

Assess → Identify → Prioritize → Remediate → Reassess


15. Remediating Recommendations at Scale

Manually fixing hundreds of resources isn’t an effective long-term security strategy.

For large environments, security controls should ideally be incorporated into:

  • Azure Policy
  • Infrastructure as code
  • Standardized deployments
  • Governance processes
  • Automation
  • CI/CD pipelines

For example, if every production storage account must use a specific network configuration, the organization should ideally enforce that requirement during deployment rather than relying solely on someone to fix the configuration afterward.

This is one reason security governance and Defender for Cloud work well together.


16. Custom Recommendations

Defender for Cloud supports custom security recommendations for organization-specific requirements.

A custom recommendation can define:

  • The security issue
  • Scope
  • Severity
  • Description
  • Remediation
  • Assessment logic
  • Applicable standards

Current Defender for Cloud supports creating custom recommendations using KQL when the Defender CSPM plan is enabled. Custom recommendations can then be associated with custom security standards.

Example

An organization requires every production resource to have an Owner tag.

A custom recommendation could evaluate resources and identify those missing the required tag.

The recommendation could then provide remediation guidance such as:

“Add the Owner tag to the resource.”

This allows Defender for Cloud to evaluate organization-specific requirements in addition to Microsoft’s built-in standards.


17. Custom Standards

A custom standard allows an organization to group security recommendations into its own security framework.

For example, an organization might create a standard called:

Corporate Cloud Security Standard

It could contain recommendations requiring:

  • Mandatory resource tags
  • Approved regions
  • HTTPS
  • Restricted network access
  • Encryption
  • Logging
  • Approved identity configurations

Custom recommendations can be assigned to custom standards.

This is useful when an organization’s security requirements go beyond the built-in Microsoft and regulatory standards.


18. Multicloud Security

Defender for Cloud isn’t limited to Azure.

It can provide security posture capabilities across:

  • Azure
  • AWS
  • GCP

This allows organizations with multicloud environments to use a centralized security experience.

The specific standards and capabilities available can vary depending on the cloud environment and enabled Defender capabilities.

For the SC-500 exam, remember that Defender for Cloud is designed for multicloud security posture management, not exclusively Azure security.


19. Security Standards Are Not the Same as Certification

This is an important exam concept.

Suppose an organization selects an industry standard such as ISO 27001.

Defender for Cloud can evaluate applicable cloud resources against mapped controls.

It can identify:

  • Passing assessments
  • Failing assessments
  • Affected resources
  • Recommendations
  • Remediation opportunities

However, Defender for Cloud does not mean:

“Your company is now officially ISO 27001 certified.”

Instead, it helps the organization understand and improve its technical security posture relative to the standard.

Formal certification may require additional organizational processes, documentation, evidence, policies, procedures, and independent assessment.


20. Security Standards and Compliance Controls

A useful mental model for the SC-500 exam is:

Security Policy
↓
Security Standard
↓
Security Controls
↓
Assessments
↓
Security Findings
↓
Recommendations
↓
Remediation

For example:

Microsoft Cloud Security Benchmark
↓
Network Security
↓
Storage Assessment
↓
Noncompliant Resource
↓
Security Recommendation
↓
Restrict Network Access

Understanding this hierarchy makes many scenario-based questions easier.


21. The Defender for Cloud Security Workflow

A typical security workflow looks like this:

Step 1: Enable Defender for Cloud

Connect the required subscriptions or cloud environments.

Step 2: Configure security policies

Determine which security requirements should apply.

Step 3: Enable or assign applicable standards

Use MCSB and any additional supported regulatory, industry, or custom standards that apply.

Step 4: Assess resources

Defender for Cloud evaluates applicable resources against the controls.

Step 5: Review recommendations

Investigate identified security weaknesses.

Step 6: Prioritize

Determine which recommendations represent the greatest risk.

Step 7: Remediate

Fix the underlying configuration or deployment problem.

Step 8: Reassess

Verify that the security issue has been resolved.

This continuous process is central to cloud security posture management.


22. Important Exam Distinctions

The following distinctions are especially useful when preparing for SC-500.

ConceptRemember It As
Security policyDefines how security is evaluated
Security standardDefines a security framework/baseline
MCSBMicrosoft’s cloud security benchmark
Security controlSpecific security requirement or logical group
AssessmentEvaluates whether a resource meets a requirement
RecommendationActionable guidance for a security issue
Secure ScoreOverall security posture improvement indicator
Regulatory ComplianceAssessment against selected standards
Security alertDetected threat or suspicious activity
Azure PolicyGovernance and policy enforcement
Custom recommendationOrganization-specific security check
Custom standardOrganization-defined collection of security requirements
AuditIdentify noncompliance
DenyPrevent noncompliant deployment/action

23. Common Exam Traps

Trap 1: Assuming MCSB is a regulatory certification

It isn’t.

MCSB is a Microsoft security benchmark that provides security guidance.


Trap 2: Confusing an assessment with a recommendation

An assessment determines whether a resource meets a requirement.

A recommendation provides actionable guidance when a security issue is identified.


Trap 3: Confusing recommendations with alerts

Recommendations generally identify weaknesses in security posture.

Alerts generally indicate detected threats or suspicious activity.


Trap 4: Assuming Defender for Cloud automatically enforces every recommendation

Detection and remediation are not necessarily the same thing.

Defender for Cloud identifies issues and provides remediation capabilities and guidance. Enforcement may require Azure Policy or other governance mechanisms.


Trap 5: Assuming every security control can be automatically assessed

Not every security requirement can necessarily be evaluated automatically.

Some organizational or procedural requirements may require additional evidence or manual validation.


Trap 6: Assuming Azure Policy and Defender for Cloud are the same service

They are not.

Azure Policy is primarily a governance and policy enforcement service.

Defender for Cloud is a broader cloud security platform that uses policy-based assessment as part of its capabilities.


Trap 7: Thinking a higher Secure Score means regulatory certification

It doesn’t.

Secure Score is a security posture indicator, not a certification.


Trap 8: Fixing recommendations one-by-one without addressing the underlying deployment process

For recurring configuration problems, the better solution may be to enforce the requirement through:

  • Azure Policy
  • Infrastructure as code
  • Deployment templates
  • CI/CD controls
  • Governance processes

24. Best Practices

When implementing Defender for Cloud security controls:

1. Start with MCSB

Use MCSB as a foundational security baseline.

2. Add applicable standards

Add regulatory and industry standards that apply to the organization’s requirements.

3. Prioritize high-risk recommendations

Don’t treat every recommendation as equally urgent.

4. Address root causes

If the same issue repeatedly appears, fix the deployment or governance process that creates it.

5. Use policy-based governance

Use Azure Policy where appropriate to establish consistent requirements.

6. Automate deployments

Incorporate security controls into infrastructure-as-code and CI/CD processes.

7. Use custom recommendations when built-in controls aren’t sufficient

Organization-specific security requirements can be represented using custom recommendations and standards.

8. Regularly review security posture

Security configuration changes continuously as resources are created, modified, and retired.

9. Understand the difference between posture and threat detection

Use recommendations and posture management to harden resources, while using security alerts and workload protection capabilities to detect and respond to threats.

10. Treat Defender for Cloud as part of a broader security strategy

Defender for Cloud is not a replacement for:

  • Identity security
  • Network security
  • Data protection
  • Secure development
  • Governance
  • Monitoring
  • Incident response
  • Organizational security policies

It is an important component of the overall security architecture.


25. SC-500 Quick Review

Before taking the exam, make sure you can answer these questions:

What is Microsoft Defender for Cloud?

A cloud security platform providing CSPM and workload protection capabilities across Azure and supported multicloud environments.

What is MCSB?

The Microsoft Cloud Security Benchmark, a Microsoft security baseline that is enabled by default for Azure when Defender for Cloud is enabled.

What is a security standard?

A framework or baseline containing security requirements used to evaluate resources.

What is a security control?

A specific security requirement or logical group of related requirements.

What is an assessment?

An evaluation that determines whether a resource satisfies an applicable security requirement.

What is a recommendation?

Actionable guidance generated when a security issue is identified.

What is the difference between a recommendation and an alert?

A recommendation generally addresses security posture weaknesses; an alert generally represents a detected threat or suspicious activity.

What is Secure Score?

An indicator used to understand and improve overall security posture.

Can Defender for Cloud certify an organization as compliant?

No. It helps assess technical security posture against supported standards but doesn’t itself provide organizational certification.

What can custom recommendations accomplish?

They allow organizations to evaluate security requirements that aren’t adequately covered by built-in recommendations.


Practice Exam Questions

Question 1

An organization has recently enabled Microsoft Defender for Cloud on several Azure subscriptions. The security team wants to begin evaluating its Azure resources against Microsoft’s recommended cloud security baseline without manually assigning a standard first.

Which security standard should the security team expect to be enabled by default?

A. PCI DSS

B. ISO 27001

C. Microsoft Cloud Security Benchmark (MCSB)

D. NIST SP 800-53

Correct Answer: C

Explanation

The Microsoft Cloud Security Benchmark (MCSB) is the default security benchmark for Azure when Defender for Cloud is enabled. It provides Microsoft-recommended cloud security practices and controls.

PCI DSS, ISO 27001, and NIST standards may be available for additional assessment, but they aren’t the default Azure benchmark.


Question 2

A security administrator is reviewing Defender for Cloud terminology and wants to understand the difference between an assessment and a recommendation.

Which statement is correct?

A. An assessment determines whether a resource satisfies a security requirement, while a recommendation provides remediation guidance for an identified issue.

B. An assessment is a security alert, while a recommendation is a compliance certificate.

C. An assessment prevents deployment of a resource, while a recommendation creates an Azure subscription.

D. An assessment is an organizational policy, while a recommendation is an Azure Policy initiative.

Correct Answer: A

Explanation

An assessment evaluates a resource against an applicable security requirement.

When an issue is identified, Defender for Cloud can generate a recommendation describing the problem, affected resources, and remediation guidance.

The other choices incorrectly equate these concepts with alerts, certificates, Azure subscriptions, or policy definitions.


Question 3

A company discovers that Defender for Cloud has generated hundreds of security recommendations. The security team wants to determine which issues represent the greatest risk and should be addressed first.

Which Defender for Cloud capability is most useful for this requirement?

A. Resource locks

B. Risk prioritization

C. Azure Resource Graph tagging

D. Microsoft Entra ID Conditional Access

Correct Answer: B

Explanation

Defender for Cloud provides risk prioritization to help security teams focus on the most important recommendations.

Risk prioritization can consider factors such as exposure, data sensitivity, lateral movement potential, exploitability, and attack-path context when available.

Resource locks, tagging, and Conditional Access serve different purposes.


Question 4

A company wants to ensure that a particular security configuration is not merely identified after deployment but that resources violating the requirement are prevented from being deployed.

Which approach is most appropriate?

A. Generate a security recommendation only

B. Enable a security alert

C. Review Secure Score

D. Use an enforcement policy such as Azure Policy with an appropriate deny effect

Correct Answer: D

Explanation

A recommendation can identify a configuration problem, but identifying a problem is different from preventing deployment.

Azure Policy can enforce organizational requirements. A policy using an appropriate deny effect can prevent deployments or resource changes that violate the policy.

Secure Score and security alerts do not provide this type of deployment enforcement.


Question 5

An organization wants to create a security check that identifies production resources that don’t contain a mandatory Owner tag. No built-in Defender for Cloud recommendation adequately addresses this requirement.

What should the organization consider using?

A. A custom recommendation

B. A Microsoft Entra security group

C. A resource lock

D. A Microsoft Sentinel analytic rule

Correct Answer: A

Explanation

A custom recommendation is appropriate when an organization needs Defender for Cloud to evaluate a security requirement that isn’t adequately covered by built-in recommendations.

Current Defender for Cloud capabilities support custom recommendation logic using KQL when the required Defender CSPM capability is enabled.

A resource lock protects resources from deletion or modification; it doesn’t evaluate whether a resource has an Owner tag. Microsoft Entra groups and Sentinel analytic rules address different security requirements.


Question 6

A security engineer is explaining Defender for Cloud to an auditor. The auditor asks whether assigning an ISO 27001 standard to Defender for Cloud automatically certifies the organization as ISO 27001 compliant.

What should the engineer explain?

A. Yes, because Defender for Cloud certification replaces an external audit

B. Yes, but only when Secure Score exceeds 90 percent

C. No. Defender for Cloud assesses applicable technical controls and identifies gaps, but organizational certification requires additional processes and evidence

D. No, because Defender for Cloud cannot evaluate any compliance-related controls

Correct Answer: C

Explanation

Defender for Cloud can assess applicable resources against supported standards and identify technical gaps.

However, this does not mean the organization has automatically achieved formal certification.

Certification can require organizational policies, procedures, documentation, evidence, and potentially an independent assessment.

Defender for Cloud is a valuable component of the compliance process, but it does not replace the entire certification process.


Question 7

A company wants to distinguish between an overall security posture measurement and individual configuration issues that need remediation.

Which statement correctly describes the relationship?

A. Secure Score identifies individual vulnerabilities, while recommendations provide the overall security score

B. Secure Score provides an overall security posture indicator, while recommendations identify specific security improvements

C. Secure Score is used only for regulatory certification, while recommendations are used only for identity management

D. Secure Score and recommendations are identical concepts with different names

Correct Answer: B

Explanation

Secure Score provides an overall indication of security posture and helps organizations measure security improvement.

Recommendations identify specific security issues and provide remediation guidance.

The two concepts are related but are not interchangeable.


Question 8

A security architect wants to establish a company-specific security baseline containing several custom security requirements and associated custom recommendations.

What Defender for Cloud capability is designed for this scenario?

A. Security alerts

B. Secure Score

C. Workload protection

D. Custom security standards

Correct Answer: D

Explanation

A custom security standard allows an organization to establish its own collection of security requirements and recommendations.

Custom recommendations can be incorporated into custom standards, allowing organizations to extend Defender for Cloud beyond its built-in security standards.

Security alerts and workload protection address threat detection and workload security, while Secure Score measures security posture.


Question 9

A security administrator notices that a Defender for Cloud recommendation identifies a vulnerable configuration on several resources. The administrator wants to understand which resources are affected and how the problem should be fixed.

Where should the administrator look?

A. The security recommendation details

B. The Azure subscription billing page

C. Microsoft Entra authentication methods

D. The resource lock configuration

Correct Answer: A

Explanation

Defender for Cloud security recommendations provide actionable information about security issues.

Recommendation details can include:

  • Description of the problem
  • Affected resources
  • Remediation guidance
  • Severity and risk information
  • Attack-path context when available

The other choices aren’t where Defender for Cloud recommendation remediation information is provided.


Question 10

A company repeatedly receives the same Defender for Cloud recommendation whenever new resources are deployed. The security team wants to prevent the configuration problem rather than repeatedly remediate resources after deployment.

Which strategy is generally the best long-term approach?

A. Ignore the recommendation after the first remediation

B. Increase the Secure Score target

C. Incorporate the security requirement into governance and deployment processes, such as Azure Policy or infrastructure as code

D. Disable Defender for Cloud recommendations

Correct Answer: C

Explanation

Repeated recommendations often indicate that the underlying deployment or governance process is allowing insecure configurations.

The better long-term approach is to incorporate the requirement into:

  • Azure Policy
  • Infrastructure as code
  • CI/CD processes
  • Standardized deployment templates
  • Governance controls

This moves security left and prevents recurring configuration problems instead of continually fixing them afterward.


Final SC-500 Takeaways

For this exam objective, remember the following sequence:

Defender for Cloud → Security Policies → Security Standards → Security Controls → Assessments → Recommendations → Remediation

The most important concepts to remember are:

  1. MCSB is the default security benchmark for Azure Defender for Cloud environments.
  2. Security standards define the broader security requirements used for assessment.
  3. Security controls represent specific security requirements or logical groups of requirements.
  4. Assessments determine whether resources satisfy applicable requirements.
  5. Recommendations identify security issues and provide actionable remediation guidance.
  6. Secure Score measures overall security posture; it isn’t a compliance certification.
  7. Recommendations and security alerts serve different purposes.
  8. Azure Policy can provide governance and enforcement capabilities, including preventing noncompliant deployments.
  9. Custom recommendations and standards allow organizations to address requirements not adequately covered by built-in standards.
  10. Defender for Cloud helps organizations assess and improve security posture; it does not independently certify an organization as compliant.
  11. For recurring findings, address the underlying deployment and governance process rather than repeatedly fixing individual resources.
  12. Defender for Cloud supports security posture management across Azure and supported multicloud environments.

If you understand the relationship between standards, controls, assessments, recommendations, and remediation, you will have a strong foundation for answering the scenario-based questions that are likely to appear around this SC-500 objective.


Go to the SC-500 Exam Prep Hub main page

Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

This topic focuses on configuring Microsoft Defender for Servers in Microsoft Defender for Cloud, including:

  • Selecting Defender for Servers Plan 1 or Plan 2
  • Configuring vulnerability scanning
  • Understanding agent-based and agentless assessments
  • Integrating Microsoft Defender for Endpoint
  • Configuring endpoint detection and response (EDR)
  • Protecting Azure, on-premises, AWS, and GCP servers
  • Reviewing security recommendations and protection coverage
  • Troubleshooting incomplete or unhealthy protection

1. What Is Microsoft Defender for Servers?

Microsoft Defender for Servers is a workload protection plan in Microsoft Defender for Cloud that protects supported Windows and Linux servers and virtual machines.

It can provide:

  • Endpoint detection and response
  • Antivirus and antimalware protection
  • Vulnerability assessment
  • Software inventory
  • Security recommendations
  • Security configuration assessment
  • File Integrity Monitoring
  • Agentless secret scanning
  • Agentless malware scanning
  • Agentless software inventory
  • Operating-system update assessment
  • Regulatory compliance insights
  • Integration with Microsoft Defender for Endpoint
  • Integration with Microsoft Sentinel

Defender for Servers supports servers running in:

  • Azure
  • On-premises datacenters
  • Amazon Web Services
  • Google Cloud Platform
  • Other supported hybrid environments

For non-Azure servers, Azure Arc-enabled servers is generally the preferred onboarding method when the organization requires the broadest Defender for Servers functionality.

Defender for Servers is not a replacement for:

  • Operating-system hardening
  • Patch management
  • Identity security
  • Network segmentation
  • Secure application development
  • Backup protection
  • Firewall configuration
  • Incident response procedures

Instead, it provides centralized security visibility, assessment, detection, and protection capabilities across supported server environments.


2. Defender for Servers Plans

Defender for Servers has two primary paid plans:

  • Plan 1
  • Plan 2

Plan 1

Plan 1 is the entry-level plan and focuses primarily on endpoint protection capabilities provided through the Microsoft Defender for Endpoint integration.

Important capabilities include:

  • Endpoint detection and response
  • Microsoft Defender for Endpoint integration
  • Antivirus and antimalware protection
  • Threat detection
  • Endpoint investigation
  • Attack surface reduction capabilities
  • Vulnerability information through the Defender for Endpoint sensor

Plan 1 is appropriate when the primary requirement is server endpoint protection and EDR.

Plan 2

Plan 2 includes Plan 1 capabilities and adds advanced server security and assessment capabilities.

Depending on the supported server type and configuration, Plan 2 can provide:

  • Agentless vulnerability assessment
  • Agentless software inventory
  • Agentless secret scanning
  • Agentless malware scanning
  • File Integrity Monitoring
  • Operating-system configuration assessment
  • Security baseline assessment
  • Operating-system update assessment
  • Premium Microsoft Defender Vulnerability Management capabilities
  • Additional security posture capabilities
  • A free daily data-ingestion benefit for eligible data types and supported configurations

Plan 2 also supports advanced vulnerability-management capabilities such as certificate assessment, security baseline assessment, and vulnerable application blocking where supported.

Plan Comparison

CapabilityPlan 1Plan 2
Microsoft Defender for Endpoint integrationYesYes
EDRYesYes
Antivirus and antimalwareYesYes
Agent-based vulnerability assessmentYesYes
Agentless vulnerability assessmentNoYes
Agentless software inventoryLimited or not availableYes, where supported
Agentless secret scanningNoYes, where supported
Agentless malware scanningNoYes, where supported
File Integrity MonitoringNoYes
Advanced Defender Vulnerability Management capabilitiesNoYes
Operating-system security baseline assessmentNoYes, where supported
Operating-system update assessmentNoYes

Feature availability varies by:

  • Operating system
  • Azure or non-Azure environment
  • Azure Arc onboarding status
  • Subscription and resource scope
  • Defender for Servers plan
  • Agent availability
  • Current Microsoft support matrix

Do not assume that every feature is available for every Azure VM, Arc-enabled server, AWS instance, or GCP instance.


3. Where Defender for Servers Is Configured

Defender for Servers is configured in Microsoft Defender for Cloud.

A typical configuration path is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the relevant Azure subscription, AWS account, or GCP project.
  4. Open the Defender plans page.
  5. Locate Defender for Servers.
  6. Select the desired plan.
  7. Open the plan’s settings to configure monitoring and security features.

When Defender for Servers is enabled, several capabilities are enabled by default. You can then modify individual settings according to the organization’s requirements.

Common Configuration Areas

Defender for Servers settings can include:

  • Endpoint protection
  • Vulnerability assessment
  • Agentless scanning
  • File Integrity Monitoring
  • Security configuration assessment
  • Operating-system update assessment
  • Data collection
  • Log Analytics workspace configuration
  • Resource-level exclusions
  • Coverage and monitoring settings

4. Subscription-Level and Resource-Level Configuration

Microsoft generally recommends enabling Defender for Servers at the subscription level.

Subscription-level enablement provides:

  • Consistent coverage
  • Easier governance
  • Centralized configuration
  • Better visibility into protected and unprotected resources
  • Simplified licensing management
  • Easier policy-based deployment

However, resource-level configuration can be useful when:

  • Different machines require different plans.
  • A specific server must be excluded.
  • A phased deployment is required.
  • A test environment is being evaluated.
  • The organization needs more granular coverage.

Important Plan Scope Detail

Plan 1 can be enabled or disabled at the resource level.

Plan 2 is generally enabled at the subscription level. It can be disabled at the resource level, but it cannot be enabled at the resource level in the same way as Plan 1.

Exam Tip

If a question asks for the simplest way to protect all supported machines in a subscription, choose subscription-level Defender for Servers enablement unless the scenario specifically requires granular resource-level configuration.


5. Azure, Hybrid, and Multicloud Protection

Azure Virtual Machines

Azure VMs are already Azure resources. Defender for Cloud can associate them directly with the subscription and resource group.

The general process is:

  1. Enable Defender for Servers for the subscription.
  2. Select Plan 1 or Plan 2.
  3. Configure the required monitoring and scanning settings.
  4. Verify Defender for Endpoint and vulnerability-assessment status.

On-Premises Servers

On-premises servers should generally be onboarded as Azure Arc-enabled servers.

Azure Arc provides:

  • An Azure resource representation
  • An Azure resource ID
  • Resource-group placement
  • Azure RBAC integration
  • Azure Policy integration
  • Extension deployment
  • Defender for Cloud integration

AWS and GCP Servers

AWS accounts and GCP projects can be connected to Defender for Cloud through native multicloud connectors.

The connector can help discover and onboard supported machines as Azure Arc-enabled servers. This allows Defender for Cloud to apply supported server protection capabilities to those machines.

For the broadest Defender for Servers functionality, AWS and GCP machines generally require Azure Arc onboarding.


6. Azure Arc and Defender for Servers

Azure Arc is important because Defender for Servers is not simply a dashboard that reads cloud inventory.

The Azure Connected Machine agent can:

  • Establish the machine’s relationship with Azure
  • Provide the machine’s Azure resource identity
  • Enable supported extensions
  • Support policy and configuration assessment
  • Allow Defender for Cloud to deploy required components
  • Provide management and security connectivity

A typical architecture is:

Azure VM
|
+-----------------------------+
|
On-premises server |
| |
AWS EC2 instance |
| |
GCP Compute Engine instance |
| |
v v
Azure Arc-enabled server ---> Microsoft Defender for Cloud
|
+--> Defender for Servers
|
+--> Defender for Endpoint
|
+--> Defender Vulnerability Management
|
+--> Security recommendations
|
+--> Microsoft Sentinel

Directly installing the Defender for Endpoint agent on a non-Azure server can provide endpoint protection and EDR, but it is not equivalent to full Azure Arc onboarding. Some Defender for Servers capabilities require Arc-enabled onboarding.


7. Vulnerability Scanning

Vulnerability scanning identifies weaknesses in software and operating-system configurations.

Examples include:

  • Missing security updates
  • Vulnerable software versions
  • Known CVEs
  • Unsupported applications
  • Insecure configurations
  • Vulnerable browser extensions
  • Weak certificates
  • Exposed secrets
  • Applications that should be blocked or remediated

Defender for Servers integrates with Microsoft Defender Vulnerability Management.

Vulnerability information can be viewed through Defender for Cloud and the unified vulnerability-management experience in the Microsoft Defender portal.

Vulnerability Scanning Methods

Defender for Servers supports two main scanning approaches:

  1. Agent-based vulnerability scanning
  2. Agentless vulnerability scanning

8. Agent-Based Vulnerability Scanning

Agent-based scanning uses the Microsoft Defender for Endpoint sensor on the machine.

The sensor collects information about:

  • Installed software
  • Software versions
  • Operating-system information
  • Vulnerability exposure
  • Security configuration
  • Endpoint security state

Agent-based scanning is available with Defender for Servers Plan 1 and Plan 2 when the Defender for Endpoint integration is enabled and supported.

Advantages

  • Detailed machine-level information
  • Continuous assessment
  • Integration with endpoint protection
  • Fresh vulnerability data
  • Unified endpoint and vulnerability view
  • Works across supported Azure, Arc, AWS, and GCP machines

Requirements

Agent-based scanning generally requires:

  • A supported operating system
  • Defender for Servers Plan 1 or Plan 2
  • Defender for Endpoint integration
  • A healthy Defender for Endpoint sensor
  • Required network connectivity
  • Successful agent provisioning

For on-premises machines, Defender for Endpoint must generally be installed for agent-based vulnerability scanning.


9. Agentless Vulnerability Scanning

Agentless scanning evaluates supported machines without requiring a traditional scanning agent inside the operating system.

Agentless scanning is available with Defender for Servers Plan 2.

It can provide information about:

  • Software inventory
  • Vulnerabilities
  • Secrets
  • Malware
  • Machine posture
  • Other supported security assessments

Advantages

  • Minimal impact on machine performance
  • No additional operating-system scanning agent for supported capabilities
  • Useful when another EDR product is installed
  • Useful for broad cloud coverage
  • Can identify security issues even when agent-based coverage is incomplete

Limitations

Agentless scanning is not universally available for every:

  • Operating system
  • Cloud platform
  • Server type
  • Feature
  • Configuration
  • Security assessment

Always verify support before designing an architecture around agentless scanning.


10. How Agent-Based and Agentless Scanning Work Together

When both agent-based and agentless scanning are available, Defender for Cloud can present a unified view.

Typical behavior includes:

  • Machines with only agent-based scanning show agent-based results.
  • Machines with only agentless scanning show agentless results.
  • Machines with both methods generally use agent-based results for better freshness.
  • Machines using a partner vulnerability solution may show partner results by default.
  • Agentless results can be used for machines without a functioning partner scanner or when Defender Vulnerability Management results are explicitly selected.

This behavior prevents duplicate findings and helps Defender for Cloud select the most appropriate available source.


11. Partner Vulnerability Scanners

Organizations may already use a third-party vulnerability scanner.

Defender for Cloud supports partner-based vulnerability assessment solutions, including supported Qualys and Rapid7 integrations.

With a partner solution:

  1. The partner scanner evaluates the machine.
  2. Vulnerability results are reported to the partner management platform.
  3. The partner platform sends relevant findings to Defender for Cloud.
  4. Security teams can review the findings in Defender for Cloud.
  5. Administrators can open the partner console for detailed information.

A paid Defender for Servers plan is not necessarily required merely to use a supported partner vulnerability-assessment solution. However, other Defender for Cloud capabilities may require a paid plan.

Exam Tip

If the question asks for a Microsoft-native vulnerability solution, choose Microsoft Defender Vulnerability Management.

If the question describes an existing Qualys or Rapid7 deployment, consider the supported partner integration instead of automatically deploying another scanner.


12. Configuring Vulnerability Assessment

A typical configuration process is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the target subscription.
  4. Open Defender for Servers settings.
  5. Select Monitoring coverage or the relevant settings area.
  6. Locate Vulnerability assessment for machines.
  7. Select the required assessment solution.
  8. Apply the configuration.
  9. Verify that the scanner is deployed or active.
  10. Review the resulting recommendations and findings.

Vulnerability scanning is enabled by default in many Defender for Servers configurations, but administrators can manually modify the scanning settings when necessary.

Required Permissions

The permissions needed depend on the deployment method.

For example:

  • An administrator deploying the scanner may require Owner-level permissions at the resource-group level.
  • A security reader can view vulnerability findings.
  • Additional permissions may be required to modify Defender for Cloud plans or resource settings.

Use least privilege and avoid granting broad subscription-wide permissions unnecessarily.


13. Microsoft Defender for Endpoint Integration

Defender for Endpoint is the primary endpoint protection and EDR integration used by Defender for Servers.

The integration can provide:

  • Antivirus
  • Antimalware protection
  • Endpoint detection and response
  • Behavioral detection
  • Threat intelligence
  • Automated investigation and response
  • Threat hunting
  • Attack surface reduction
  • Security alerts
  • Vulnerability information
  • Software inventory

When Defender for Servers is enabled, Defender for Endpoint integration is enabled by default in supported configurations. Defender for Cloud can automatically provision the Defender for Endpoint sensor on supported machines.

EDR Data Flow

Protected server
|
v
Microsoft Defender for Endpoint sensor
|
v
Microsoft Defender for Endpoint service
|
v
Microsoft Defender for Cloud
|
+--> Security recommendations
+--> Security alerts
+--> Vulnerability findings
+--> Incident investigation
|
v
Microsoft Sentinel, when integrated

Security teams can review alerts in Defender for Cloud and pivot to the Microsoft Defender portal for deeper investigation and response.


14. Configuring Endpoint Protection

Endpoint protection settings are configured within the Defender for Servers plan settings.

Administrators should verify:

  • Defender for Endpoint integration is enabled.
  • The server is supported.
  • The endpoint sensor is installed.
  • The sensor is healthy.
  • Antivirus is enabled.
  • Security intelligence is current.
  • The machine is reporting to the correct tenant.
  • Conflicting endpoint security products are not preventing operation.
  • Required network endpoints are reachable.

Important Distinction

Enabling Defender for Servers does not guarantee that every machine is healthy immediately.

A server can be:

  • Connected to Azure Arc but missing Defender for Endpoint
  • Onboarded to Defender for Endpoint but not reporting correctly
  • Reporting EDR alerts but missing vulnerability data
  • Protected by antivirus but failing security configuration checks
  • Covered by Defender for Cloud but excluded from a specific feature

Protection status must be verified at the machine level.


15. Assessing EDR Configuration

Defender for Cloud can assess whether Defender for Endpoint is configured correctly.

Examples of EDR configuration checks include:

  • Antivirus is disabled or only partially configured.
  • Antivirus signatures are outdated.
  • Full or quick scans have not run recently.
  • Endpoint protection settings are incomplete.
  • The EDR solution is not functioning as expected.

Defender for Cloud can generate recommendations such as:

  • Resolve EDR configuration issues.
  • Enable or correctly configure antivirus.
  • Update outdated antivirus signatures.
  • Run required endpoint scans.

These checks help identify machines that technically have an EDR product installed but are not adequately protected.


16. EDR and Non-Microsoft Endpoint Products

An organization may already use a non-Microsoft EDR product.

In that situation, the organization should evaluate:

  • Whether Defender for Endpoint can coexist with the existing product
  • Whether the existing product must be removed
  • Whether passive or limited Defender for Endpoint modes are supported
  • Whether agentless scanning can provide vulnerability visibility
  • Whether the desired Defender for Servers features require Defender for Endpoint
  • Whether the existing EDR product provides equivalent capabilities

Agentless scanning can be useful for supported cloud machines when another EDR solution is installed. However, agentless scanning does not replace the full detection and response capabilities of Defender for Endpoint.


17. File Integrity Monitoring

File Integrity Monitoring, available with Defender for Servers Plan 2, helps identify changes to important files and registry settings.

It can help detect:

  • Unauthorized configuration changes
  • Changes to critical system files
  • Changes to security settings
  • Suspicious modifications
  • Potential persistence mechanisms
  • Changes that may indicate compromise

File Integrity Monitoring requires additional configuration after enabling Plan 2 and generally requires a Log Analytics workspace.

Administrators should identify:

  • Critical files
  • Critical directories
  • Important registry paths
  • Appropriate monitoring rules
  • Alerting requirements
  • Retention requirements

File Integrity Monitoring is not the same as a full backup solution. It identifies changes; it does not automatically restore files to a previous state.


18. Operating-System Security Configuration Assessment

Defender for Servers Plan 2 can assess operating-system configuration against supported security baselines.

Examples include:

  • Password policy
  • Security options
  • Services
  • Registry settings
  • File permissions
  • Operating-system security configuration
  • Other baseline settings

Some assessments require the Azure Policy machine configuration extension.

Machine Configuration can evaluate and, in supported scenarios, enforce settings inside the operating system.

Difference Between Defender Recommendations and Machine Configuration

  • Defender for Cloud recommendations identify security weaknesses.
  • Machine Configuration evaluates and can enforce specific configuration settings.
  • Azure Policy governs Azure resources and can assign or deploy configuration requirements.

These capabilities work together but are not interchangeable.


19. Data Collection and Log Analytics

Some Defender for Servers features require data collection through supported monitoring methods.

A Log Analytics workspace may be required for:

  • File Integrity Monitoring
  • Certain Plan 2 data-ingestion benefits
  • Supported monitoring and security data collection

When Plan 2 is enabled, eligible data types may receive a free daily ingestion benefit, subject to the current requirements and supported collection methods.

The benefit does not mean that all Log Analytics ingestion is free. It applies only to eligible data types and supported configurations.

Verify the Following

  • The machine reports to the intended workspace.
  • The appropriate data collection rule is configured.
  • Azure Monitor Agent is installed where required.
  • The workspace is in an appropriate region.
  • Data is actually arriving.
  • Retention and cost settings are appropriate.
  • Security data is not being collected unnecessarily.

20. Security Recommendations and Remediation

Defender for Cloud can generate recommendations for issues such as:

  • Defender for Endpoint is not installed.
  • Antivirus is disabled.
  • Vulnerability assessment is missing.
  • Vulnerable software is installed.
  • Security updates are missing.
  • EDR configuration is incomplete.
  • The server is not connected to Azure Arc.
  • Required extensions are missing.
  • Security configuration does not meet the baseline.
  • File Integrity Monitoring is not configured.

Recommendations can be remediated by:

  • Installing required agents
  • Enabling Defender for Servers
  • Updating software
  • Applying security configurations
  • Enabling antivirus
  • Correcting network access
  • Deploying extensions
  • Assigning appropriate policies
  • Reconfiguring the machine

A recommendation is not necessarily proof of an active attack. It usually indicates a security weakness or missing control.


21. Monitoring Protection Coverage

Defender for Cloud provides coverage information that helps identify:

  • Protected machines
  • Unprotected machines
  • Machines with incomplete onboarding
  • Machines missing required agents
  • Machines with unhealthy extensions
  • Machines without vulnerability assessment
  • Machines without EDR
  • Machines excluded from protection

Use coverage information to verify that the intended machines are actually protected.

A successful Arc connection alone does not prove that Defender for Servers, Defender for Endpoint, and vulnerability scanning are all functioning.


22. Troubleshooting Defender for Servers

The Server Is Missing from Defender for Cloud

Check:

  • Azure Arc connection status
  • Subscription and resource group
  • Onboarding credentials
  • Agent installation
  • Operating-system support
  • Network connectivity
  • Azure permissions
  • Resource provider registration

Defender for Endpoint Is Missing

Check:

  • Defender for Servers plan
  • Defender for Endpoint integration
  • Extension provisioning
  • Operating-system support
  • Proxy configuration
  • Firewall rules
  • TLS inspection
  • Existing endpoint security software
  • Local administrative permissions

Vulnerability Findings Are Missing

Check:

  • Whether vulnerability scanning is enabled
  • Whether the selected plan supports the desired scanning method
  • Whether the Defender for Endpoint sensor is healthy
  • Whether agentless scanning is supported
  • Whether a partner scanner is being used
  • Whether the initial scan has completed
  • Whether the machine is reporting current data

EDR Recommendations Appear

Check:

  • Antivirus status
  • Signature update status
  • Recent scan activity
  • Defender for Endpoint sensor health
  • Security policy configuration
  • Whether the machine is reporting to the correct tenant

File Integrity Monitoring Is Not Working

Check:

  • Defender for Servers Plan 2
  • Log Analytics workspace
  • Required monitoring configuration
  • Data collection rules
  • Azure Monitor Agent
  • Workspace connectivity
  • Monitored file and registry paths

23. Best Practices

Select the Plan Based on Requirements

Use Plan 1 when the primary need is endpoint protection and EDR.

Use Plan 2 when the organization requires advanced capabilities such as:

  • Agentless scanning
  • File Integrity Monitoring
  • Advanced vulnerability management
  • Security baseline assessment
  • Agentless secret or malware scanning
  • Additional server posture capabilities

Enable at the Appropriate Scope

Prefer subscription-level enablement for consistent coverage, but use resource-level controls when the deployment requires exceptions or phased adoption.

Use Azure Arc for Non-Azure Servers

Use Azure Arc-enabled servers for on-premises, AWS, and GCP servers when the organization needs the broadest supported Defender for Servers functionality.

Verify Protection, Not Just Enrollment

After onboarding, verify:

  • Arc connection
  • Defender for Endpoint status
  • Vulnerability scanning
  • Security recommendations
  • EDR alerts
  • Extension health
  • Data collection
  • Policy compliance

Use Least Privilege

Restrict access to:

  • Defender for Cloud configuration
  • Defender for Endpoint administration
  • Extension deployment
  • Vulnerability assessment configuration
  • Log Analytics workspaces
  • Resource groups and subscriptions

Avoid Duplicate Scanners

If a partner vulnerability scanner is already deployed, determine whether it should remain the authoritative scanner or whether Defender Vulnerability Management should be used.

Keep Security Components Updated

Maintain:

  • Operating-system updates
  • Defender for Endpoint sensor
  • Azure Connected Machine agent
  • Azure Monitor Agent
  • Security extensions
  • Vulnerability-scanning components

24. Key Exam Takeaways

  1. Defender for Servers Plan 1 focuses primarily on endpoint protection and EDR.
  2. Plan 2 includes Plan 1 capabilities plus advanced posture, scanning, and monitoring features.
  3. Agent-based vulnerability scanning uses the Defender for Endpoint sensor.
  4. Agentless vulnerability scanning is available with Plan 2 for supported machines.
  5. Defender Vulnerability Management is integrated with Defender for Servers.
  6. Direct Defender for Endpoint onboarding is not equivalent to full Azure Arc onboarding.
  7. Azure Arc is generally required for the broadest Defender for Servers functionality on non-Azure servers.
  8. AWS and GCP accounts can be connected to Defender for Cloud through native multicloud connectors.
  9. Defender for Cloud can assess EDR configuration, including antivirus status, signatures, and scan activity.
  10. A machine can be connected to Azure Arc but still lack healthy Defender for Endpoint protection.
  11. File Integrity Monitoring requires Plan 2 and additional configuration.
  12. Some Plan 2 capabilities require a Log Analytics workspace.
  13. Vulnerability scanning results can come from Defender Vulnerability Management or a supported partner scanner.
  14. Always check feature support for the specific operating system and cloud environment.
  15. Subscription-level enablement is generally preferred for consistent coverage.

Practice Exam Questions

Question 1

An organization wants to protect Azure VMs with endpoint detection and response and antivirus capabilities, but it does not require advanced agentless scanning or File Integrity Monitoring.

Which Defender for Servers plan is the most appropriate starting point?

A. Defender for Servers Plan 1
B. Defender for Servers Plan 2
C. Defender for Storage
D. Defender for Containers

Answer: A

Explanation: Plan 1 focuses primarily on endpoint protection capabilities provided through the Microsoft Defender for Endpoint integration. Plan 2 is required for additional advanced capabilities such as agentless scanning and File Integrity Monitoring.


Question 2

A company wants to perform vulnerability assessments on supported AWS EC2 instances without installing a traditional vulnerability-scanning agent inside the operating system.

Which configuration should the company use?

A. Defender for Servers Plan 1 with Azure Bastion
B. Defender for Servers Plan 2 with agentless scanning
C. Microsoft Sentinel only
D. Azure Firewall Premium only

Answer: B

Explanation: Defender for Servers Plan 2 supports agentless vulnerability scanning for supported machines, including supported onboarded AWS machines.


Question 3

An administrator has enabled Defender for Servers Plan 1. The organization wants vulnerability information based on installed software and the Microsoft Defender for Endpoint sensor.

What should the administrator configure?

A. Agent-based vulnerability scanning through Defender for Endpoint
B. Azure Front Door
C. Azure Private Link
D. File Integrity Monitoring

Answer: A

Explanation: Agent-based vulnerability scanning uses the Defender for Endpoint sensor and is available with Defender for Servers Plan 1 or Plan 2 when the required integration is enabled.


Question 4

An on-premises server is directly onboarded to Microsoft Defender for Endpoint. The administrator expects all Defender for Servers Plan 2 features to be available.

What is the correct conclusion?

A. All Plan 2 features are available automatically.
B. Direct Defender for Endpoint onboarding provides no protection.
C. Some advanced Defender for Servers capabilities require Azure Arc onboarding.
D. Plan 2 is available only for Windows client devices.

Answer: C

Explanation: Direct Defender for Endpoint onboarding can provide endpoint protection and EDR, but some Defender for Servers capabilities require the machine to be onboarded through Azure Arc.


Question 5

Which capability is primarily responsible for endpoint detection and response in Defender for Servers?

A. Azure Resource Graph
B. Microsoft Defender for Endpoint
C. Azure Policy
D. Azure Backup

Answer: B

Explanation: Microsoft Defender for Endpoint provides endpoint protection and EDR capabilities that are integrated into Defender for Servers.


Question 6

Defender for Cloud reports that a server’s antivirus signatures are outdated and that recent scans have not been completed.

What type of issue is this?

A. An EDR configuration issue
B. An Azure subscription billing issue
C. A storage firewall issue
D. An Azure Arc resource-group issue

Answer: A

Explanation: Defender for Cloud can assess EDR configuration and identify issues such as outdated signatures, disabled antivirus, or missing recent scans.


Question 7

An organization wants to monitor unauthorized changes to critical files and registry settings on supported servers.

Which Defender for Servers capability should it configure?

A. Agentless secret scanning
B. File Integrity Monitoring
C. Azure Bastion
D. Azure DDoS Protection

Answer: B

Explanation: File Integrity Monitoring helps detect changes to monitored files and registry settings. It is available with Defender for Servers Plan 2 and requires additional configuration.


Question 8

An organization already uses a supported Qualys vulnerability scanner and wants its findings to appear in Defender for Cloud.

What should the organization use?

A. A supported partner vulnerability-assessment integration
B. Azure Bastion
C. Microsoft Sentinel automation rules only
D. Azure Firewall application rules

Answer: A

Explanation: Defender for Cloud supports partner vulnerability-assessment integrations, including supported Qualys and Rapid7 scenarios.


Question 9

A server is shown as connected in Azure Arc, but Defender for Endpoint alerts and vulnerability information are missing.

What should the administrator check first?

A. Whether Azure Front Door is deployed
B. Whether Defender for Servers is enabled and the required Defender for Endpoint components are healthy
C. Whether the server has an Azure public IP address
D. Whether Azure Bastion is configured

Answer: B

Explanation: An Azure Arc connection does not automatically prove that Defender for Servers and Defender for Endpoint are fully operational. The administrator should verify the plan, integration, extension status, and sensor health.


Question 10

An organization wants to assess operating-system security settings against supported security baselines on Arc-enabled servers.

Which combination is most appropriate?

A. Azure DNS and Azure Firewall
B. Microsoft Sentinel and Azure Bastion
C. Defender for Servers Plan 2 and supported machine-configuration capabilities
D. Azure Storage and Azure Backup

Answer: C

Explanation: Defender for Servers Plan 2 supports operating-system configuration assessment, and supported scenarios may require the Azure Policy machine configuration extension.


Go to the SC-500 Exam Prep Hub main page

Evaluate compliance against security frameworks by using Defender for Cloud (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Evaluate compliance against security frameworks by using Defender for Cloud


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Cloud security is not limited to protecting resources from attacks. Organizations must also demonstrate that their cloud environments are configured and operated in accordance with applicable security frameworks, industry standards, regulatory requirements, and organizational policies.

For example, an organization might need to evaluate its Azure environment against:

  • Microsoft Cloud Security Benchmark (MCSB)
  • NIST
  • ISO 27001
  • PCI DSS
  • CIS Benchmarks
  • SOC requirements
  • HIPAA
  • FedRAMP
  • CMMC
  • GDPR
  • NIS2
  • Other industry-specific or regional frameworks

Microsoft Defender for Cloud provides a Regulatory compliance experience that helps organizations assess their cloud resources against supported security standards, identify compliance gaps, investigate failing controls, remediate issues, and communicate compliance status.

For the SC-500 exam, it is important to understand the relationship between:

Security Standard → Compliance Control → Assessment → Recommendation → Remediation → Compliance Posture


1. What Is Regulatory Compliance?

Regulatory compliance is the process of ensuring that an organization satisfies applicable legal, regulatory, industry, and security requirements.

In cloud environments, compliance can involve requirements related to:

  • Identity and access management
  • Data protection
  • Encryption
  • Network security
  • Logging and monitoring
  • Vulnerability management
  • Configuration management
  • Incident response
  • Business continuity
  • Physical security
  • Privacy
  • Data retention

A security framework may contain hundreds of individual requirements.

Defender for Cloud helps organizations translate those requirements into technical security controls that can be evaluated against cloud resources.


2. Defender for Cloud Regulatory Compliance

The Regulatory compliance dashboard in Defender for Cloud provides an interactive view of compliance posture against assigned security standards.

The dashboard allows security teams to:

  • View assigned standards
  • Review compliance controls
  • Identify failed assessments
  • Investigate affected resources
  • Review remediation recommendations
  • Track compliance posture
  • Generate compliance reports
  • Monitor compliance over time
  • Work with manual assessments and attestations
  • Integrate compliance information with Microsoft Purview Compliance Manager

Microsoft describes security standards in Defender for Cloud as representations of industry standards, regulatory standards, and benchmarks.


3. Security Standards

A security standard represents a framework, benchmark, or regulatory requirement against which an environment can be evaluated.

Examples include:

CategoryExample
Security benchmarkMicrosoft Cloud Security Benchmark
Industry benchmarkCIS
Security frameworkNIST
International standardISO 27001
Payment securityPCI DSS
HealthcareHIPAA
GovernmentFedRAMP
Financial servicesSWIFT
PrivacyGDPR
Cybersecurity regulationNIS2

The exact standards available depend on the cloud environment and Microsoft’s current supported standards.

Current Defender for Cloud documentation lists standards including NIST CSF, NIST SP 800-53, PCI DSS, CIS, ISO 27001, HIPAA, FedRAMP, CMMC, GDPR, NIS2, DORA, and others across supported Azure, AWS, and GCP environments.


4. Microsoft Cloud Security Benchmark

The Microsoft Cloud Security Benchmark (MCSB) is particularly important for the SC-500 exam.

MCSB provides Microsoft security recommendations and technical guidance for cloud environments.

It covers security areas such as:

  • Network security
  • Identity management
  • Privileged access
  • Data protection
  • Logging
  • Incident response
  • Vulnerability management
  • Endpoint security
  • Application security
  • Cloud governance

When Defender for Cloud is enabled, the MCSB is automatically used as the default security benchmark for Azure environments.

Exam Tip

If a question asks which benchmark is automatically available when Defender for Cloud is enabled for Azure, think:

Microsoft Cloud Security Benchmark (MCSB).


5. Security Standards vs. Security Controls

A security standard is not simply one large requirement.

A standard is broken down into controls.

For example:

Security Standard
|
+--- Identity Control
|
+--- Network Security Control
|
+--- Data Protection Control
|
+--- Logging Control
|
+--- Vulnerability Control

Each control represents a logical group of related security requirements.

Defender for Cloud evaluates applicable resources against controls that can be assessed automatically.


6. Compliance Controls

A compliance control is a logical grouping of security requirements within a standard.

Controls can contain one or more security assessments or recommendations.

Conceptually:

PCI DSS
|
+--- Network Security
| |
| +--- Assessment
| +--- Assessment
|
+--- Access Control
| |
| +--- Assessment
| +--- Assessment
|
+--- Data Protection
|
+--- Assessment
+--- Assessment

This hierarchy makes it easier to determine where an organization is meeting requirements and where gaps exist.


7. Assessments

An assessment determines whether a resource satisfies a particular security requirement.

For example, an assessment might determine whether:

  • Storage data is encrypted
  • Administrative access is restricted
  • Network traffic is appropriately protected
  • A VM has disk encryption enabled
  • A resource has an insecure configuration
  • Logging is configured

If a resource fails an automated assessment, Defender for Cloud can generate a security recommendation explaining what needs to be changed.

The relationship can therefore be thought of as:

Standard
↓
Control
↓
Assessment
↓
Resource Evaluation
↓
Pass / Fail / Unavailable

8. Compliance Assessment States

Defender for Cloud uses compliance assessment states to communicate whether resources satisfy a control.

The Regulatory compliance experience uses three important states:

Compliant

Resources in scope satisfy the applicable assessment.

Noncompliant

One or more resources do not satisfy the applicable requirement.

Unavailable

Defender for Cloud cannot automatically determine compliance for that control.

This distinction is important.

Unavailable does not necessarily mean noncompliant.

It means Defender for Cloud cannot automatically determine the compliance state for that control.


9. Why Some Controls Are Unavailable

Not every compliance requirement can be evaluated automatically.

Some requirements require:

  • Human review
  • Organizational documentation
  • Policies
  • Procedures
  • Evidence
  • Interviews
  • Physical security verification
  • Business processes
  • External audit evidence

For example, a framework might require an organization to have a documented incident-response procedure.

Defender for Cloud cannot determine solely from Azure resource configuration whether that procedure exists and is being followed.

The control may therefore be unavailable for automatic assessment.


10. Automated vs. Manual Assessments

This distinction is particularly important for the SC-500 exam.

Automated assessment

Defender for Cloud can evaluate the requirement using available technical information.

Example:

Are storage accounts configured according to the required security configuration?

Defender for Cloud can inspect resource configuration and determine the result.

Manual assessment

The requirement requires customer input or evidence.

Example:

Does the organization maintain a documented security incident-response procedure?

A cloud platform cannot necessarily determine this automatically.

Manual assessments can require the organization to provide an attestation and evidence. Current Microsoft documentation explicitly supports manual attestation and evidence through the Regulatory compliance experience.


11. The Regulatory Compliance Dashboard

The Regulatory compliance dashboard is the central location for reviewing compliance posture.

Security teams can use it to:

  • View assigned standards
  • Review compliance scores/status
  • Examine controls
  • Identify failing assessments
  • Investigate resources
  • Review remediation actions
  • Track compliance over time
  • Generate reports
  • Access audit-related reports

The dashboard provides an interactive overview of the organization’s compliance state.


12. Understanding the Compliance Dashboard

A simplified view of the workflow is:

Regulatory Compliance
|
+--- Standards
|
+--- Controls
|
+--- Assessments
|
+--- Resources
|
+--- Recommendations
|
+--- Remediation
|
+--- Reports

A security administrator can start at the standard level and drill down toward individual resources.

For example:

PCI DSS
↓
Requirement / Control
↓
Failed Assessment
↓
Azure Resource
↓
Security Recommendation
↓
Remediation

13. Assigning a Compliance Standard

Organizations can assign supported regulatory compliance standards to applicable scopes.

The scope can include supported:

  • Azure subscriptions
  • AWS accounts
  • GCP projects

Defender for Cloud uses Azure Policy initiatives to represent regulatory compliance standards and evaluates the selected scope against those standards.

Example

Suppose a company has an Azure subscription supporting a payment-processing application.

The company may choose to apply:

PCI DSS

to the appropriate scope.

Defender for Cloud can then assess applicable resources against the controls represented by that standard.


14. Why Scope Matters

Compliance assessments are performed against a defined scope.

For example:

Tenant
|
+--- Subscription A
| |
| +--- Production
|
+--- Subscription B
|
+--- Development

The organization might apply a compliance standard to only the production subscription.

This is important because compliance requirements may differ between environments.

For example:

  • Production may contain regulated data.
  • Development may contain synthetic data.
  • A specific subscription may host payment-processing workloads.
  • Another subscription may host unrelated applications.

Therefore, applying the correct standard to the correct scope is an important part of compliance management.


15. Security Policies and Azure Policy Initiatives

Defender for Cloud regulatory standards are closely related to Azure Policy.

A useful conceptual model is:

Regulatory Standard
↓
Azure Policy Initiative
↓
Policies / Controls
↓
Resource Evaluation
↓
Assessment Results

Microsoft documentation states that regulatory compliance standards in Defender for Cloud use Azure Policy initiatives.

This is an important SC-500 relationship.

Exam Tip

If a question asks what mechanism is used to represent regulatory compliance standards for assessment, remember:

Azure Policy initiatives.


16. Compliance Gaps

A compliance gap exists when a resource or configuration does not satisfy an applicable compliance requirement.

For example:

ISO 27001
|
+--- Access Control
|
+--- PASS
|
+--- PASS
|
+--- FAIL
|
↓
VM01
|
↓
Security Recommendation

The failing assessment tells the security administrator where attention is required.


17. Investigating a Compliance Gap

A typical investigation might follow this sequence:

Step 1

Open Regulatory compliance.

Step 2

Select the relevant standard.

Step 3

Select the control with a failing assessment.

Step 4

Review the affected resources.

Step 5

Review the associated security recommendation.

Step 6

Review remediation instructions.

Step 7

Remediate the resource.

Step 8

Wait for the assessment to run again.

Step 9

Confirm that the compliance status has improved.

This creates a continuous improvement cycle.


18. Compliance Recommendations

A failed compliance assessment frequently maps to a security recommendation.

For example:

Control:

Protect data at rest.

Assessment:

Storage resource does not meet encryption requirement.

Recommendation:

Configure the required encryption settings.

Remediation:

Modify the resource configuration.

This creates a practical relationship between compliance and security operations.

Compliance does not merely tell an organization:

“You failed.”

It can help explain:

“Here is the resource causing the problem and what you can do about it.”


19. Compliance Scores and Posture

The Regulatory compliance dashboard provides a way to monitor compliance posture.

For example:

PCI DSS
Passed Controls: 82%
Failed Controls: 18%

An organization can use this information to:

  • Identify weak areas
  • Prioritize remediation
  • Communicate progress
  • Track improvements
  • Prepare for audits

However, a compliance percentage should not automatically be interpreted as a legal certification.


20. Defender for Cloud Does Not Make an Organization “Certified”

This is a critical concept.

Suppose Defender for Cloud shows:

ISO 27001 — 95% compliant

That does not automatically mean:

“The company is ISO 27001 certified.”

Similarly:

PCI DSS — 100% of automatically assessed controls passed

does not necessarily mean the organization has satisfied every PCI DSS obligation or received a formal certification/attestation from the appropriate authority.

Defender for Cloud provides assessment and posture-management capabilities.

Organizations may still need:

  • Policies
  • Procedures
  • Evidence
  • Manual attestations
  • Independent audits
  • External certification
  • Other organizational controls

Exam Principle

Compliance tooling supports compliance; it does not automatically confer legal or regulatory certification.


21. Shared Responsibility

Cloud compliance must also be understood in the context of the shared responsibility model.

Microsoft is responsible for security aspects of the cloud platform that are under Microsoft’s control.

The customer remains responsible for many aspects of its own:

  • Data
  • Identities
  • Configurations
  • Applications
  • Access
  • Policies
  • Processes

Therefore, passing a technical cloud assessment does not necessarily mean every organizational compliance requirement has been satisfied.


22. Microsoft Actions vs. Your Actions

The Regulatory compliance experience can help distinguish responsibilities associated with compliance.

For a selected control, the dashboard can provide information about:

Your Actions

Actions the customer needs to take to improve compliance.

Microsoft Actions

Actions Microsoft has taken to support compliance with the applicable standard.

This is particularly useful when communicating compliance responsibilities to auditors and stakeholders.


23. Manual Attestation

Manual assessments require customer participation.

A security administrator can provide:

  • An attestation
  • Supporting information
  • Evidence

This allows the organization to document compliance for requirements that Defender for Cloud cannot technically evaluate on its own.

Conceptually:

Manual Control
|
↓
Customer Review
|
↓
Attestation
|
↓
Evidence
|
↓
Compliance Record

Example

A framework requires:

Security incidents must be reviewed according to a documented organizational process.

Defender for Cloud may not be able to prove that the organization follows the process.

The organization may therefore provide an attestation and supporting evidence.


24. Compliance Reporting

Organizations often need to communicate compliance posture to:

  • Security leadership
  • IT leadership
  • Auditors
  • Compliance officers
  • Risk management teams
  • Regulators
  • Business stakeholders

Defender for Cloud supports reporting capabilities that can help communicate compliance status.

The Regulatory compliance dashboard can generate reports for a selected standard, including a summary of compliance status based on Defender for Cloud assessment data.


25. Compliance Over Time

Compliance is not a one-time activity.

A company might be compliant today and become noncompliant tomorrow because:

  • A new resource is deployed.
  • A configuration changes.
  • A firewall rule is modified.
  • A new identity receives excessive permissions.
  • Encryption is disabled.
  • A security policy changes.
  • A new vulnerability is discovered.

Therefore:

Compliance must be continuously monitored.

Defender for Cloud’s compliance capabilities allow organizations to track their compliance posture over time.


26. Compliance Workbooks

Compliance information can also be presented through workbooks.

Workbooks can help security teams visualize and communicate information such as:

  • Compliance trends
  • Standard performance
  • Control status
  • Remediation progress
  • Compliance changes over time

This can be particularly useful for executive reporting.


27. Microsoft Purview Compliance Manager Integration

Defender for Cloud compliance information can integrate with Microsoft Purview Compliance Manager.

This provides an opportunity to bring compliance information into a broader compliance-management experience.

Current Microsoft documentation states that compliance data from Defender for Cloud can be surfaced in Compliance Manager for the same standards, including standards monitoring supported AWS and GCP environments.

Think of the distinction this way:

Defender for Cloud

Cloud security posture and technical compliance assessment

Microsoft Purview Compliance Manager

Broader compliance-management experience across the organization’s digital estate


28. Compliance Reporting vs. Audit Reports

These concepts should not be confused.

Compliance status report

Communicates the organization’s current compliance posture based on Defender for Cloud assessment data.

Audit report

Provides Microsoft audit/certification documentation for applicable Microsoft services and standards.

An organization’s own compliance posture is not the same thing as Microsoft’s certification of its cloud services.

This distinction can matter when preparing evidence for auditors.


29. Compliance Assessment Refresh

After correcting a compliance issue, the dashboard may not immediately show the new result.

Defender for Cloud assessments run periodically.

Current Microsoft documentation states that compliance assessments run approximately every 12 hours for the applicable assessments.

Therefore, if an administrator fixes a resource and immediately checks the compliance dashboard, the old result may still be displayed.

Exam Scenario

A security engineer fixes a failed recommendation but the compliance dashboard still shows the resource as noncompliant.

What should the engineer consider?

The assessment may not have run again yet.


30. Automating Compliance Responses

Defender for Cloud supports workflow automation.

For example, an organization could configure an automation workflow that responds when a regulatory compliance assessment changes.

A Logic App can be used to perform actions such as:

  • Sending notifications
  • Triggering workflows
  • Initiating downstream processes
  • Alerting compliance personnel

Current Microsoft documentation specifically describes triggering Logic Apps when regulatory compliance assessments change state.


31. Compliance Across Multiple Clouds

Modern organizations often use:

  • Azure
  • AWS
  • Google Cloud

Defender for Cloud can provide regulatory compliance visibility across supported multicloud environments.

This allows organizations to use a centralized security posture experience rather than maintaining completely separate compliance-management processes for each cloud.

Supported standards vary by cloud provider.

For example:

Microsoft Defender for Cloud
|
+------+------+
| | |
Azure AWS GCP
| | |
Standards / Compliance Assessments

The specific standards available depend on the cloud provider and the current Defender for Cloud capabilities.


32. Custom Standards

Organizations may have security requirements that aren’t fully represented by a built-in regulatory standard.

Defender for Cloud supports custom standards and custom recommendations.

Custom recommendations can be created with organization-specific logic, including KQL-based evaluation, and can then be associated with custom standards.

Example

An organization might require:

All production storage resources must use a specific approved configuration.

If a built-in framework does not provide the exact requirement, the organization can create a custom recommendation and incorporate it into a custom standard.


33. Built-In Standards vs. Custom Standards

CapabilityBuilt-In StandardCustom Standard
Based on recognized frameworkYesNot necessarily
Microsoft-providedYesOrganization-defined
Standard controls includedYesOrganization selects/defines
Custom organizational requirementsLimitedStrong
Useful for regulatory frameworksYesCan supplement them
Can use custom recommendationsNot the primary purposeYes

Custom standards are particularly useful when organizations need to enforce internal security requirements that aren’t adequately represented by an existing framework.


34. Example: PCI DSS Assessment

Consider a company processing credit-card transactions.

The organization assigns PCI DSS to the appropriate environment.

The resulting workflow might be:

PCI DSS
|
↓
Compliance Controls
|
↓
Azure Resources
|
↓
Assessments
|
+---- PASS
|
+---- FAIL
|
↓
Recommendation
|
↓
Remediation
|
↓
Reassessment

The security team can then identify which controls are failing and which resources are responsible.


35. Example: ISO 27001 Assessment

Suppose an organization wants to evaluate its Azure environment against ISO 27001.

The organization can:

  1. Assign the appropriate standard.
  2. Review the Regulatory compliance dashboard.
  3. Examine the applicable controls.
  4. Identify failed assessments.
  5. Investigate affected resources.
  6. Remediate applicable technical issues.
  7. Provide manual evidence where required.
  8. Generate compliance reports.
  9. Track progress over time.

The process helps the organization identify technical gaps, but formal ISO certification involves additional organizational and audit requirements.


36. Example: NIST Assessment

Suppose an organization uses NIST as its security framework.

Defender for Cloud can help map technical cloud configurations and recommendations to the applicable supported NIST standard.

The security team can then determine:

  • Which controls are passing
  • Which controls are failing
  • Which resources are affected
  • Which recommendations need remediation
  • Which controls require manual assessment

This provides a technical starting point for broader compliance activities.


37. Compliance vs. Security Posture

These concepts overlap but are not identical.

Security posture

Answers:

How secure is our environment?

Regulatory compliance

Answers:

How closely does our environment align with the requirements of a particular standard or framework?

For example, an organization could have:

  • Strong security posture
  • But not satisfy a particular regulatory requirement

Conversely, an organization could satisfy many technical controls in a framework while still having broader security risks that aren’t fully captured by that framework.

Therefore, organizations should manage both.


38. Compliance vs. Secure Score

Secure Score and Regulatory Compliance serve different purposes.

Secure ScoreRegulatory Compliance
Measures security postureMeasures alignment with a selected standard
Broad security recommendationsFramework-specific controls
Helps improve security postureHelps evaluate compliance requirements
Not a certificationNot automatically a certification
Security-focusedCompliance/framework-focused

Exam Tip

If the question mentions:

“Improve overall security posture”

think Secure Score.

If it mentions:

“Evaluate against PCI DSS, ISO, NIST, CIS, or another framework”

think Regulatory compliance.


39. Compliance vs. Defender for Cloud Recommendations

Security recommendations are often the technical mechanism through which compliance issues are addressed.

For example:

Compliance Requirement
↓
Control
↓
Failed Assessment
↓
Security Recommendation
↓
Remediation

This makes recommendations extremely important to compliance operations.


40. Common Mistakes

Mistake 1: Assuming a passing compliance score equals certification

A Defender for Cloud compliance result does not automatically constitute formal certification.


Mistake 2: Treating “Unavailable” as “Noncompliant”

Unavailable means Defender for Cloud cannot automatically determine the result.


Mistake 3: Assuming every control can be automated

Some controls require manual evidence or attestation.


Mistake 4: Forgetting the scope

Standards are assigned to specific scopes.

Always determine which subscription, account, project, or other supported scope is being assessed.


Mistake 5: Expecting remediation results immediately

Compliance assessments run periodically. Changes may not appear immediately.


Mistake 6: Confusing MCSB with a regulatory certification

MCSB is Microsoft’s cloud security benchmark. It is not itself a regulatory certification.


Mistake 7: Confusing compliance standards with individual policies

A standard represents a framework or benchmark containing multiple controls. Azure Policy initiatives are used to implement regulatory compliance standards for assessment.


Mistake 8: Assuming Microsoft is responsible for every compliance requirement

Cloud compliance follows a shared-responsibility model.


41. SC-500 Exam-Focused Comparison

If the question asks about…Think about…
Overall cloud security postureSecure Score
A specific security weaknessSecurity recommendation
Evaluating against ISO, PCI DSS, NIST, CIS, etc.Regulatory compliance
Default Azure security benchmarkMCSB
Logical grouping of related requirementsCompliance control
Technical evaluation of a controlAssessment
Cannot automatically determine complianceUnavailable/manual assessment
Customer-provided evidenceManual attestation
Applying a standard to a subscriptionAssign compliance standard
Framework implementation mechanismAzure Policy initiative
Fixing a failed technical assessmentSecurity recommendation/remediation
Communicating compliance postureCompliance report/workbook
Broader compliance managementMicrosoft Purview Compliance Manager
Automatic response to assessment changesWorkflow automation / Logic Apps
Organization-specific requirementsCustom standards/recommendations

42. A Complete Compliance Management Workflow

The entire process can be summarized as:

                   SELECT STANDARD
                         |
                         v
                DEFINE THE SCOPE
                         |
                         v
                 ASSESS RESOURCES
                         |
              +----------+----------+
              |                     |
             PASS                  FAIL
              |                     |
              |                     v
              |              INVESTIGATE GAP
              |                     |
              |                     v
              |              REVIEW RECOMMENDATION
              |                     |
              |                     v
              |                 REMEDIATE
              |                     |
              |                     v
              |                REASSESS
              |                     |
              +----------+----------+
                         |
                         v
                 MONITOR OVER TIME
                         |
                         v
                REPORT COMPLIANCE

For controls that cannot be automatically evaluated:

Manual Control
|
v
Customer Review
|
v
Attestation + Evidence
|
v
Compliance Record

43. Key Takeaways

For the SC-500 exam, remember the following:

  1. Defender for Cloud provides a Regulatory compliance experience for evaluating cloud environments against supported standards and frameworks.
  2. A security standard represents a framework, benchmark, or regulatory requirement.
  3. Standards are divided into compliance controls.
  4. Controls are evaluated through assessments.
  5. Failed assessments can produce security recommendations.
  6. Security recommendations provide remediation guidance.
  7. MCSB is the default security benchmark for Azure when Defender for Cloud is enabled.
  8. Regulatory compliance standards use Azure Policy initiatives.
  9. Standards can be assigned to appropriate scopes such as Azure subscriptions and supported multicloud scopes.
  10. Some controls can be assessed automatically.
  11. Other controls require manual attestation and evidence.
  12. Unavailable does not mean noncompliant; it means Defender for Cloud cannot automatically determine the status.
  13. Compliance status can be investigated through the Regulatory compliance dashboard.
  14. Compliance reports can communicate assessment results to stakeholders.
  15. Compliance can be monitored over time rather than evaluated only once.
  16. Compliance assessment results may take time to update after remediation because assessments run periodically.
  17. Defender for Cloud compliance information can integrate with Microsoft Purview Compliance Manager.
  18. Workflow automation can trigger Logic Apps when compliance assessments change.
  19. Custom standards and recommendations can address organization-specific requirements.
  20. Passing Defender for Cloud assessments does not by itself constitute legal or regulatory certification.

Practice Exam Questions

Question 1

A security administrator wants to evaluate an Azure subscription against the requirements of a recognized security framework such as ISO 27001.

Which Microsoft Defender for Cloud capability should the administrator use?

A. Secure Score only

B. Cloud Security Explorer

C. Microsoft Defender Vulnerability Management

D. Regulatory compliance

Answer: D

Explanation

The Regulatory compliance experience is designed to evaluate cloud environments against supported security standards, regulatory standards, and benchmarks.

Secure Score is useful for evaluating overall security posture, but it does not replace framework-specific compliance assessment.


Question 2

An organization enables Microsoft Defender for Cloud on an Azure subscription. The security team wants to begin evaluating the environment against Microsoft’s default cloud security benchmark.

Which benchmark should the team expect?

A. PCI DSS

B. Microsoft Cloud Security Benchmark

C. ISO 27001

D. NIST SP 800-53

Answer: B

Explanation

The Microsoft Cloud Security Benchmark (MCSB) is the default security benchmark used for Azure when Defender for Cloud is enabled.

Other regulatory and industry standards can be added as appropriate.


Question 3

A compliance administrator selects a regulatory standard and wants to understand why several resources are reported as failing a particular requirement.

What should the administrator investigate first?

A. Microsoft Security Copilot

B. Secure Score history

C. The compliance control and its failing assessments

D. Azure Activity Log only

Answer: C

Explanation

The Regulatory compliance dashboard organizes standards into controls, which contain assessments.

The administrator can expand the applicable control, investigate failing assessments, identify affected resources, and review associated remediation guidance.


Question 4

A regulatory framework contains a requirement that an organization maintain a documented incident-response procedure. Defender for Cloud cannot determine automatically whether the organization has such a procedure.

How should this type of requirement be handled?

A. Mark the resource as vulnerable

B. Automatically pass the control

C. Disable the entire compliance standard

D. Use a manual assessment and provide appropriate attestation or evidence

Answer: D

Explanation

Not every compliance requirement can be evaluated from cloud resource configuration.

For requirements that cannot be automatically assessed, Defender for Cloud can use manual assessments, where the customer provides an attestation and supporting evidence.

An unavailable assessment should not automatically be interpreted as a failed assessment.


Question 5

An administrator fixes a resource that previously failed a compliance assessment. Immediately afterward, the Regulatory compliance dashboard still shows the resource as noncompliant.

What is the most likely explanation?

A. The compliance standard must always be deleted and reassigned

B. The assessment has not yet run again

C. Secure Score must reach 100 percent first

D. The resource must be moved to another subscription

Answer: B

Explanation

Defender for Cloud compliance assessments run periodically. Current Microsoft documentation indicates that applicable assessments run approximately every 12 hours.

Therefore, a remediation change may not be reflected immediately in the compliance dashboard.


Question 6

A company wants to apply a PCI DSS standard only to the Azure subscription hosting its payment-processing workloads.

What should the security administrator configure?

A. Assign the PCI DSS standard to the appropriate scope

B. Enable Microsoft Sentinel on every subscription

C. Increase the Secure Score target

D. Create a Microsoft Purview eDiscovery case

Answer: A

Explanation

Regulatory compliance standards can be assigned to appropriate scopes.

If only one subscription contains the applicable workload, the organization can apply the standard to that subscription rather than unnecessarily applying it to unrelated environments.


Question 7

Which technology mechanism is used to represent regulatory compliance standards for assessment in Microsoft Defender for Cloud?

A. Microsoft Sentinel analytics rules

B. Azure Monitor alerts

C. Azure Policy initiatives

D. Microsoft Entra Conditional Access policies

Answer: C

Explanation

Defender for Cloud regulatory compliance standards use Azure Policy initiatives.

These provide the policy structure used to evaluate applicable resources against the controls represented by the standard.

This is an important SC-500 distinction: Conditional Access is primarily an identity access-control mechanism, while Azure Policy initiatives are used for resource governance and compliance evaluation.


Question 8

A security administrator sees that a compliance control is displayed as unavailable rather than compliant or noncompliant.

What does this generally indicate?

A. The subscription has been compromised

B. The standard has been permanently disabled

C. The resource has failed the control

D. Defender for Cloud cannot automatically determine compliance for that control

Answer: D

Explanation

An unavailable control indicates that Defender for Cloud cannot automatically assess the requirement.

This is different from a noncompliant result.

Some controls require manual assessment, organizational evidence, or other information that cannot be determined from cloud resource configuration alone.


Question 9

An organization wants to provide executives with a summary of its current compliance posture against a selected security standard.

Which Defender for Cloud capability is most appropriate?

A. Compliance status reporting

B. Just-in-time VM access

C. Cloud Security Explorer

D. Network Security Groups

Answer: A

Explanation

The Regulatory compliance experience supports compliance reporting, including reports summarizing the organization’s current compliance status for a selected standard.

These reports can help communicate compliance posture to stakeholders and support audit activities.

The other options address unrelated security functions.


Question 10

A company wants Defender for Cloud to notify its compliance team when a regulatory compliance assessment changes state.

Which solution should the company use?

A. Azure Bastion

B. Logic Apps with Defender for Cloud workflow automation

C. Azure Firewall

D. Microsoft Entra PIM

Answer: B

Explanation

Defender for Cloud supports workflow automation that can respond to changes in regulatory compliance assessments.

A Logic App can be configured to perform downstream actions such as notifications or other workflow processing when the relevant Defender for Cloud event occurs.


Final SC-500 Exam Reminder

The most important mental model for this topic is:

Standard → Control → Assessment → Finding → Recommendation → Remediation → Reassessment

And remember these four distinctions:

MCSB
→ Microsoft’s cloud security benchmark

Regulatory Compliance
→ Evaluate your environment against a selected framework or standard

Security Recommendation
→ Identifies a technical security issue and provides remediation guidance

Manual Attestation
→ Used when Defender for Cloud cannot automatically determine whether a compliance requirement is satisfied

Finally, remember:
Defender for Cloud can help an organization measure, improve, and document its compliance posture, but a passing Defender for Cloud assessment does not by itself constitute formal regulatory certification.

Defender for Cloud can help an organization measure, improve, and document its compliance posture, but a passing Defender for Cloud assessment does not by itself constitute formal regulatory certification.


Go to the SC-500 Exam Prep Hub main page

Onboard servers to Defender for Servers in Defender for Cloud, including hybrid and multicloud scenarios (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Onboard servers to Defender for Servers in Defender for Cloud, including hybrid and multicloud scenarios


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Secure compute (20–25%) → Implement security for servers and virtual machines (VMs)

This topic focuses on how to onboard servers to Microsoft Defender for Servers through Microsoft Defender for Cloud, including servers running in:

  • Microsoft Azure
  • On-premises datacenters
  • Amazon Web Services (AWS)
  • Google Cloud Platform (GCP)
  • Other supported hybrid environments

The goal is to extend security posture management, vulnerability assessment, endpoint detection and response, and other workload protection capabilities beyond Azure.


1. What Is Microsoft Defender for Servers?

Microsoft Defender for Servers is a cloud workload protection plan in Microsoft Defender for Cloud that helps protect Windows and Linux servers and virtual machines.

It provides capabilities such as:

  • Security recommendations
  • Vulnerability assessment
  • Microsoft Defender for Endpoint integration
  • Endpoint detection and response (EDR)
  • Threat detection and investigation
  • File Integrity Monitoring
  • Agentless software inventory
  • Agentless secret scanning
  • Agentless malware scanning
  • Security configuration assessment
  • Regulatory compliance reporting
  • Just-in-time VM access in supported scenarios
  • Security posture visibility across hybrid and multicloud environments

Defender for Servers can protect servers running in Azure, on-premises environments, AWS, and GCP.

However, Defender for Servers does not replace operating-system hardening, patch management, identity security, network segmentation, or application security. It extends Microsoft’s security management and protection capabilities to supported servers.


2. Understanding the Main Components

Several services work together when protecting non-Azure servers.

Microsoft Defender for Cloud

Defender for Cloud provides:

  • Cloud security posture management
  • Security recommendations
  • Regulatory compliance dashboards
  • Workload protection plans
  • Security alerts
  • Centralized security visibility

Defender for Cloud is the primary management experience where you enable Defender for Servers and review recommendations and alerts.

Azure Arc-Enabled Servers

Azure Arc-enabled servers allows a physical or virtual server outside Azure to become an Azure resource.

After onboarding:

  • The server receives an Azure resource ID.
  • It can be placed in an Azure resource group.
  • Azure RBAC can be applied.
  • Azure Policy can evaluate the resource.
  • Azure extensions can be deployed.
  • Defender for Cloud can use the server as part of its protected server inventory.

Azure Arc provides the management connection between the external server and Azure.

Azure Connected Machine Agent

The Azure Connected Machine agent is installed on the server.

The agent:

  • Establishes the server’s relationship with Azure.
  • Communicates outbound to Azure.
  • Provides the Azure resource identity.
  • Enables supported extensions.
  • Allows Azure services to evaluate and manage the connected machine.
  • Helps Defender for Cloud deploy required security components.

Azure does not generally initiate inbound management connections into the customer’s network. The agent establishes outbound communication to Azure over encrypted connections.

Microsoft Defender for Endpoint

Defender for Servers integrates with Microsoft Defender for Endpoint to provide endpoint protection and EDR capabilities.

Defender for Endpoint can provide:

  • Antivirus and antimalware protection
  • Attack surface reduction
  • Threat detection
  • Behavioral analysis
  • Threat hunting
  • Automated investigation and response
  • Endpoint security alerts

Defender for Servers Plan 1 and Plan 2 provide Defender for Endpoint capabilities through the Defender for Cloud integration.


3. Defender for Servers Plan 1 and Plan 2

Defender for Servers provides two primary paid plans.

Plan 1

Plan 1 is the entry-level plan and focuses primarily on endpoint protection through Microsoft Defender for Endpoint integration.

Important capabilities include:

  • Microsoft Defender for Endpoint integration
  • Endpoint detection and response
  • Antivirus and antimalware capabilities
  • Threat detection and investigation
  • Attack surface reduction
  • Security recommendations

Plan 2

Plan 2 includes the capabilities of Plan 1 and adds advanced server protection and assessment capabilities.

Depending on the supported server type and scenario, Plan 2 can provide capabilities such as:

  • File Integrity Monitoring
  • Just-in-time VM access
  • Agentless scanning
  • Advanced vulnerability assessment
  • Agentless software inventory
  • Agentless secret scanning
  • Agentless malware scanning
  • Additional security posture assessments
  • System updates and patch-management capabilities

The exact feature availability depends on the operating system, cloud environment, onboarding method, and current Defender for Cloud support matrix.

Exam Tip

Do not assume that every Defender for Servers feature is available for every server type.

For example:

  • Some Azure VM features are not available for Arc-enabled servers.
  • Some features available for Azure VMs are not available for AWS or GCP machines.
  • Some Plan 2 capabilities require Azure Arc.
  • Direct Defender for Endpoint onboarding does not provide the complete set of Defender for Servers capabilities.

4. Azure VMs Versus Hybrid and Multicloud Servers

Azure Virtual Machines

Azure VMs are already Azure resources. Defender for Cloud can associate them directly with the subscription and resource group where they exist.

The onboarding process generally involves:

  1. Enable Defender for Servers for the subscription.
  2. Select Plan 1 or Plan 2.
  3. Configure the required agent or agentless capabilities.
  4. Verify that the VM is protected.

On-Premises Servers

On-premises servers should generally be onboarded as Azure Arc-enabled servers.

The server remains physically in the organization’s datacenter, but Azure represents it as a resource for management and security purposes.

AWS and GCP Servers

AWS and GCP environments can be connected to Defender for Cloud through native cloud connectors.

For complete server protection, AWS and GCP machines are generally onboarded as Azure Arc-enabled machines. Microsoft recommends onboarding AWS and GCP machines as Arc-enabled servers to take advantage of the full Defender for Servers capability set.


5. High-Level Onboarding Architecture

The typical hybrid or multicloud architecture is:

On-premises / AWS / GCP Server
|
| Azure Connected Machine agent
|
v
Azure Arc-enabled server
|
v
Microsoft Defender for Cloud
|
+--> Defender for Servers
|
+--> Microsoft Defender for Endpoint
|
+--> Vulnerability Assessment
|
+--> Azure Policy / Machine Configuration
|
+--> Azure Monitor / Log Analytics
|
+--> Microsoft Sentinel

The Azure Arc agent provides the connection, while Defender for Cloud provides the security management and protection experience.


6. Planning Before Onboarding

Before onboarding servers, plan the following.

Subscription and Resource Group Design

Decide:

  • Which Azure subscription will contain the connected servers
  • Which resource groups will be used
  • Whether servers should be grouped by environment, business unit, application, or ownership
  • Which administrators need access
  • Whether Tier 0 or highly sensitive servers require a dedicated subscription or resource group

Resource groups can be used to apply access control and organize servers according to operational responsibility.

Azure Region and Data Residency

The Azure region selected for Arc-enabled servers affects where resource metadata and certain security-related data are processed or stored.

Before onboarding, evaluate:

  • Regulatory requirements
  • Data residency requirements
  • Internal security policies
  • Cross-border data transfer restrictions
  • Log storage locations
  • Defender for Cloud and Defender for Endpoint data-handling requirements

CSPM capabilities are generally agentless, while workload protection capabilities can require agents and extensions. Therefore, data residency planning must consider both the Azure service and the agents deployed to the server.

Supported Operating Systems

Verify that the server’s:

  • Operating system
  • Version
  • Architecture
  • Installed dependencies
  • Network configuration

are supported by Azure Arc and Defender for Servers.

An unsupported operating system can prevent successful onboarding or limit available protection features.

Network Connectivity

The server must be able to communicate outbound to required Azure endpoints.

Review:

  • Firewall rules
  • Proxy configuration
  • DNS resolution
  • TLS inspection
  • Outbound port 443 access
  • Private endpoint requirements
  • AWS or GCP connector-specific endpoints

Most Arc communication is outbound and encrypted using TLS. Extensions may require additional endpoints beyond those required by the core Arc agent.


7. Required Permissions and Identity

Azure Permissions

The person or automation process performing onboarding needs sufficient permissions to:

  • Register or use the required resource providers
  • Create Azure Arc resources
  • Place resources in the target resource group
  • Enable Defender for Cloud plans
  • Configure extensions or related services

Use the principle of least privilege. Avoid granting subscription-wide Owner access when a narrower role is sufficient.

Onboarding Credentials

Onboarding credentials must be protected because they can be used to create or connect resources in Azure.

Best practices include:

  • Use a dedicated onboarding identity.
  • Use least-privilege permissions.
  • Avoid embedding credentials in scripts or source code.
  • Protect service principal secrets.
  • Rotate credentials regularly.
  • Prefer short-lived or federated authentication where supported.
  • Remove temporary onboarding permissions after deployment.
  • Store secrets in a secure secret-management service.

Local Server Permissions

Installing the Azure Connected Machine agent generally requires administrative privileges on the server.

After installation, the agent’s service model is designed to avoid requiring a permanently privileged domain service account. Microsoft documents different service-account behavior for Windows and Linux, and domain-joined service accounts or alternate user identities are not supported for the agent service model.


8. Onboarding On-Premises Servers

A typical on-premises onboarding process is:

Step 1: Prepare the Environment

Confirm:

  • Azure subscription availability
  • Target resource group
  • Azure region
  • Supported operating system
  • Required outbound connectivity
  • Appropriate Azure permissions
  • Defender for Cloud configuration

Step 2: Install the Azure Connected Machine Agent

Install the Azure Connected Machine agent on the server.

The agent can be installed:

  • Manually
  • Through scripted deployment
  • Through configuration-management tools
  • At scale using supported automation methods

Step 3: Authenticate the Machine

Use an approved onboarding method, such as:

  • Interactive authentication
  • Service principal authentication
  • Other supported automated authentication methods

The authentication method should be selected based on the scale of deployment and the organization’s identity-management standards.

Step 4: Connect the Server to Azure

After successful authentication, the server appears as an Azure Arc-enabled server.

It receives:

  • An Azure resource ID
  • A resource group association
  • A location
  • A managed identity
  • A connection status

Step 5: Enable Defender for Servers

Enable Defender for Servers for the subscription or appropriate scope.

Select Plan 1 or Plan 2 based on the required capabilities and licensing needs.

Step 6: Verify Protection

Verify:

  • The server appears in Defender for Cloud.
  • The Arc connection is healthy.
  • Defender for Endpoint is onboarded where required.
  • Vulnerability assessment is active.
  • Security recommendations are being generated.
  • Security alerts can be viewed.
  • Required extensions are provisioned successfully.

Microsoft provides a workflow for connecting on-premises machines to Defender for Cloud through Azure Arc and verifying the Defender for Endpoint integration.


9. Onboarding AWS Servers

AWS servers are generally connected through a native AWS connector in Defender for Cloud.

The process typically includes:

  1. Connect the AWS account to Defender for Cloud.
  2. Configure the required AWS IAM permissions.
  3. Select the subscriptions and regions to protect.
  4. Enable the appropriate Defender for Cloud plans.
  5. Configure Azure Arc onboarding for supported EC2 instances.
  6. Install or provision the Azure Connected Machine agent.
  7. Enable Defender for Servers.
  8. Verify security coverage.

AWS Systems Manager Agent can be used to help provision the Azure Arc agent automatically on supported AWS EC2 instances.

For full Defender for Servers functionality, AWS machines generally require:

  • Azure Arc agent
  • Microsoft Defender for Endpoint integration
  • Vulnerability assessment
  • Required agentless scanning capabilities
  • Appropriate AWS and Azure permissions
  • Required outbound network access

AWS and GCP server support is not identical. For example, some network-based security alerts and just-in-time access capabilities have different availability depending on the cloud platform.


10. Onboarding GCP Servers

GCP servers are connected through a native GCP connector in Defender for Cloud.

The process typically includes:

  1. Connect the GCP project to Defender for Cloud.
  2. Configure the required GCP permissions.
  3. Select the projects and resources to protect.
  4. Enable the required Defender for Cloud plans.
  5. Configure Azure Arc onboarding.
  6. Install or provision the Azure Connected Machine agent.
  7. Enable Defender for Servers.
  8. Verify that the server appears in Defender for Cloud.

The GCP OS Config agent can be used to help provision the Azure Arc agent automatically on supported Google Compute Engine instances.

Required components can include:

  • Azure Arc agent
  • Microsoft Defender for Endpoint
  • Vulnerability assessment
  • Agentless scanning
  • GCP IAM permissions
  • Required outbound network connectivity

GCP and AWS machines can both receive Defender for Servers protection, but feature support must be checked against the current support matrix.


11. Direct Defender for Endpoint Onboarding Versus Azure Arc

Some non-Azure servers can be onboarded directly to Microsoft Defender for Endpoint.

However, direct onboarding is not equivalent to onboarding through Azure Arc.

Direct Defender for Endpoint onboarding can provide endpoint protection and EDR capabilities, but some Defender for Servers Plan 2 capabilities still require Azure Arc.

Microsoft documents that directly onboarded servers receive Plan 1 capabilities and selected additional capabilities, while some Plan 2 features require Arc-enabled onboarding.

Use Azure Arc When You Need:

  • Azure resource representation
  • Azure RBAC
  • Azure Policy
  • Machine Configuration
  • Azure extensions
  • Defender for Servers capabilities that require Arc
  • Centralized hybrid and multicloud inventory
  • Azure management and governance
  • Integration with other Azure services

Use Direct Defender for Endpoint Onboarding When:

  • Endpoint protection is the primary requirement
  • Azure Arc is not appropriate for the scenario
  • The required Defender for Servers features do not depend on Arc
  • The organization wants direct EDR onboarding

For exam questions, carefully distinguish between Defender for Endpoint onboarding and Defender for Servers onboarding through Azure Arc.


12. Vulnerability Assessment

Defender for Servers can provide vulnerability assessment through supported capabilities, including:

  • Microsoft Defender Vulnerability Management
  • Integrated vulnerability assessment solutions
  • Agentless vulnerability scanning in supported scenarios

Vulnerability assessment helps identify:

  • Missing security updates
  • Vulnerable software
  • Unsupported software
  • Misconfigured applications
  • Security weaknesses that attackers could exploit

The assessment method depends on the server type, operating system, Defender for Servers plan, and current feature support.

Agent-Based Assessment

An agent-based solution runs on the server and can collect detailed information about software and vulnerabilities.

Agentless Assessment

Agentless assessment can analyze supported resources without installing a traditional scanning agent on the operating system.

Agentless capabilities may be available for:

  • Software inventory
  • Vulnerability assessment
  • Secret scanning
  • Malware scanning
  • Other supported assessments

Agentless features are not universally available across all operating systems and cloud environments.


13. Microsoft Defender for Endpoint Integration

Defender for Servers uses Microsoft Defender for Endpoint to provide endpoint protection.

The integration can provide:

  • Endpoint detection and response
  • Antivirus
  • Threat intelligence
  • Behavioral detections
  • Automated investigation and response
  • Threat hunting
  • Attack surface reduction
  • Security alerts

When Defender for Endpoint detects a threat, the alert can be surfaced in Defender for Cloud. Security teams can pivot to the Defender for Endpoint experience for deeper investigation.

This integration is particularly useful when an organization wants one endpoint security platform across Azure, on-premises, AWS, and GCP servers.


14. Security Recommendations and Compliance

After servers are connected, Defender for Cloud can evaluate their security posture.

Recommendations can address:

  • Missing operating-system updates
  • Weak security configurations
  • Missing endpoint protection
  • Vulnerable software
  • Unprotected servers
  • Insecure network configurations
  • Missing disk encryption
  • File integrity concerns
  • Security baseline deviations

Defender for Cloud can also provide regulatory compliance dashboards and reports.

The compliance dashboard does not automatically mean that the organization is compliant. It provides an assessment of how resources compare with selected regulatory standards and security controls.


15. Azure Policy and Machine Configuration

Azure Policy can be used to govern Arc-enabled servers.

Examples include:

  • Require specific tags.
  • Restrict allowed resource locations.
  • Audit whether servers are connected.
  • Audit security configuration.
  • Enforce configuration requirements.
  • Deploy required extensions.
  • Identify noncompliant machines.

Azure Machine Configuration, formerly associated with guest configuration, can evaluate and enforce settings inside supported servers.

Examples include:

  • Password policy settings
  • Security baseline settings
  • Required services
  • Registry settings
  • File permissions
  • Operating-system configuration
  • Compliance with organizational standards

Azure Policy evaluates the Azure resource and can use machine configuration to assess settings inside the operating system.

Important Security Consideration

Extensions can perform powerful operations on a connected machine. Therefore:

  • Restrict who can deploy extensions.
  • Use RBAC carefully.
  • Limit extension permissions.
  • Review inherited policy assignments.
  • Use local agent security controls where stronger restrictions are required.

For highly sensitive or Tier 0 servers, Microsoft recommends stronger isolation, dedicated subscriptions, limited persistent administration, and careful review of inherited access and policies.


16. Network Requirements

The Azure Connected Machine agent normally communicates outbound to Azure.

Common requirements include:

  • DNS resolution
  • Outbound HTTPS connectivity
  • Port 443 access
  • Access to required Azure endpoints
  • Proxy configuration when applicable
  • Trusted TLS certificates
  • Firewall allowlists

For AWS and GCP deployments, additional cloud-specific endpoints may be required.

TLS Inspection

TLS inspection can work if:

  • The server trusts the inspection certificate.
  • The inspection device does not interfere with the connection.
  • Required extensions do not use certificate pinning.

Some extensions may use certificate pinning, which can cause failures when traffic is intercepted or modified.

Private Endpoints

Private endpoints can be used for supported scenarios to restrict traffic paths.

However:

  • Not every Arc endpoint supports private endpoints.
  • Microsoft Entra ID may still require firewall exceptions.
  • SSH and Windows Admin Center access over a private endpoint are not automatically supported by the Arc connection.
  • Extension-specific connectivity requirements may remain.

17. Monitoring and Logging

Defender for Servers should be monitored after onboarding.

Check:

  • Arc agent connection status
  • Last heartbeat
  • Defender for Endpoint health
  • Extension provisioning status
  • Vulnerability assessment status
  • Policy compliance
  • Security recommendations
  • Security alerts
  • Log ingestion
  • Data collection configuration

Azure Monitor and Log Analytics can be used for supported monitoring and logging scenarios.

Microsoft Sentinel can provide centralized security information and event management across:

  • Azure
  • On-premises servers
  • AWS
  • GCP
  • Microsoft Defender for Cloud
  • Microsoft Defender for Endpoint
  • Other security products

Defender for Cloud integrates with Microsoft Sentinel so that security alerts can be centralized for investigation, correlation, and automated response.


18. Common Onboarding Problems

Problem 1: The Server Does Not Appear in Azure

Possible causes include:

  • Invalid onboarding credentials
  • Insufficient Azure permissions
  • Failed agent installation
  • Unsupported operating system
  • Blocked outbound connectivity
  • Incorrect subscription or resource group
  • Failed authentication

Problem 2: The Arc Agent Is Connected but Defender for Servers Is Not Active

Possible causes include:

  • Defender for Servers is not enabled for the correct subscription.
  • The server is associated with a different subscription.
  • The required plan has not been selected.
  • The Defender for Endpoint extension failed.
  • The server is not supported for the selected capability.
  • Licensing or provisioning has not completed.

Problem 3: Defender for Endpoint Is Not Onboarded

Check:

  • Extension provisioning status
  • Operating-system support
  • Outbound connectivity
  • Proxy and TLS inspection
  • Defender for Endpoint licensing
  • Conflicting endpoint security software
  • Local administrative permissions

Problem 4: Vulnerability Data Is Missing

Possible causes include:

  • Vulnerability assessment is not enabled.
  • The required agent or extension failed.
  • The server is not supported.
  • The assessment has not completed its initial scan.
  • Network access is blocked.
  • The selected Defender for Servers plan does not include the required capability.

Problem 5: Policy Reports Noncompliance

Possible causes include:

  • The server does not meet the assigned configuration.
  • The policy assignment is inherited.
  • The machine configuration extension is missing.
  • The policy has not evaluated recently.
  • The server is disconnected.
  • The policy definition does not support the operating system.

19. Best Practices

Use a Standardized Onboarding Process

Create a repeatable process that includes:

  1. Inventory the server.
  2. Confirm support.
  3. Assign the target subscription and resource group.
  4. Validate network access.
  5. Use least-privilege onboarding credentials.
  6. Install the Arc agent.
  7. Enable Defender for Servers.
  8. Verify protection.
  9. Apply policies and security baselines.
  10. Monitor the server continuously.

Onboard at Scale

For large environments, use:

  • Automation
  • Infrastructure as code
  • Configuration-management tools
  • AWS Systems Manager
  • GCP OS Config
  • Standardized deployment scripts
  • Centralized policy assignments

Protect Onboarding Credentials

Do not store service principal secrets in:

  • Source code
  • Public repositories
  • Unencrypted scripts
  • Shared documents
  • Local administrator profiles

Restrict Administrative Access

Use:

  • Azure RBAC
  • Privileged Identity Management
  • Just-in-time access where supported
  • Separate administrator roles
  • Dedicated subscriptions for sensitive resources
  • Resource-group-level permissions

Monitor Agent and Extension Health

A connected server is not necessarily a fully protected server. Confirm that the required security extensions and Defender for Endpoint components are installed and healthy.

Validate Feature Availability

Always verify whether a feature is supported for:

  • Azure VMs
  • Arc-enabled servers
  • AWS machines
  • GCP machines
  • Windows
  • Linux
  • Plan 1
  • Plan 2

20. Key Exam Takeaways

Remember these points:

  1. Defender for Servers protects supported Windows and Linux servers across Azure, on-premises, AWS, and GCP.
  2. Azure Arc is the primary connection method for non-Azure servers when full Defender for Servers capabilities are required.
  3. The Azure Connected Machine agent establishes the server’s relationship with Azure.
  4. Azure Arc-enabled servers become Azure resources with resource IDs and resource-group placement.
  5. Defender for Endpoint provides core EDR capabilities.
  6. Plan 2 includes additional advanced capabilities, but feature availability varies by environment.
  7. Direct Defender for Endpoint onboarding is not equivalent to full Azure Arc onboarding.
  8. AWS and GCP connectors provide cloud-level visibility, while Arc enables deeper server-level protection.
  9. Azure Policy and Machine Configuration help govern and assess server configuration.
  10. Outbound network connectivity and endpoint allowlisting are essential.
  11. Onboarding credentials must be protected and assigned least-privilege permissions.
  12. A connected Arc server must still be monitored for agent, extension, Defender, and policy health.

Practice Exam Questions

Question 1

An organization has 200 Windows servers running in an on-premises datacenter. The organization wants to manage them through Azure and use Defender for Servers capabilities that require Azure resource representation.

What should the organization do?

A. Install only the Microsoft Defender Antivirus client on each server.
B. Onboard the servers as Azure Arc-enabled servers and enable Defender for Servers.
C. Move all servers into Azure Virtual Machines.
D. Connect the servers only to Microsoft Sentinel.

Answer: B

Explanation: Azure Arc-enabled servers allows on-premises servers to become Azure resources. Defender for Servers can then provide security posture and workload protection capabilities without requiring the servers to be moved into Azure.


Question 2

A company wants to protect AWS EC2 instances with Defender for Servers and obtain the broadest supported set of server protection capabilities.

Which component is generally required for the EC2 instances?

A. Azure Bastion
B. Azure Application Gateway
C. Azure VPN Gateway
D. Azure Arc-enabled servers

Answer: D

Explanation: AWS machines should generally be onboarded as Azure Arc-enabled servers to obtain the full set of supported Defender for Servers capabilities. Azure Arc provides the connection between the AWS machine and Azure.


Question 3

Which component establishes the relationship between a non-Azure server and Azure?

A. Azure Connected Machine agent
B. Microsoft Sentinel connector
C. Azure Firewall
D. Azure Resource Graph query

Answer: A

Explanation: The Azure Connected Machine agent is installed on the non-Azure server and establishes its connection to Azure Arc.


Question 4

An administrator directly onboards an on-premises server to Microsoft Defender for Endpoint. The administrator expects every Defender for Servers Plan 2 capability to become available.

Is this expectation correct?

A. Yes. Direct Defender for Endpoint onboarding always provides every Defender for Servers feature.
B. Yes, but only if the server is running Windows Server.
C. No. Some Defender for Servers capabilities still require Azure Arc onboarding.
D. No. Defender for Endpoint cannot protect on-premises servers.

Answer: C

Explanation: Direct Defender for Endpoint onboarding can provide endpoint protection and EDR, but some Defender for Servers Plan 2 capabilities require Azure Arc-enabled onboarding.


Question 5

An organization wants to evaluate security settings inside the operating system of Arc-enabled servers.

Which capability is most appropriate?

A. Azure Resource Graph only
B. Azure Machine Configuration
C. Azure DNS
D. Azure Front Door

Answer: B

Explanation: Azure Machine Configuration can evaluate and, in supported scenarios, enforce settings inside the operating system of Arc-enabled servers.


Question 6

Which network requirement is most commonly necessary for the Azure Connected Machine agent?

A. Inbound TCP port 3389 from Azure
B. Inbound TCP port 22 from Azure
C. Outbound HTTPS connectivity to required Azure endpoints
D. A public IP address assigned to every server

Answer: C

Explanation: Arc communication is generally outbound and encrypted over HTTPS. The server does not normally require inbound RDP or SSH access from Azure for the Arc connection.


Question 7

An organization connects its GCP project to Defender for Cloud. It wants server-level protection for supported Google Compute Engine instances.

What should it plan to deploy?

A. Azure Arc agent and the required Defender for Servers components
B. Azure Bastion on every GCP VM
C. Azure Application Gateway in the GCP project
D. Azure VPN Gateway on every GCP VM

Answer: A

Explanation: The Azure Arc agent connects supported GCP machines to Azure and allows Defender for Cloud to deploy the extensions and components required for Defender for Servers.


Question 8

Which statement best describes the difference between Defender for Cloud CSPM and Defender for Servers workload protection?

A. CSPM always requires the Microsoft Defender for Endpoint agent.
B. Defender for Servers is only available for Azure VMs.
C. CSPM evaluates security posture, while Defender for Servers provides server workload protection and may require agents or extensions.
D. CSPM and Defender for Servers are identical capabilities with different names.

Answer: C

Explanation: CSPM focuses on security posture and can be agentless in multicloud scenarios. Defender for Servers provides workload protection capabilities that can require Azure Arc, Defender for Endpoint, vulnerability assessment, or other components.


Question 9

A server appears as connected in Azure Arc, but no Defender for Endpoint alerts or vulnerability information are appearing.

What should the administrator check first?

A. Whether Azure Front Door is enabled
B. Whether Defender for Servers is enabled for the correct subscription and the required extensions are healthy
C. Whether the server has an Azure public IP address
D. Whether Azure Bastion is deployed

Answer: B

Explanation: An Arc connection alone does not guarantee that Defender for Servers protection is active. The administrator should verify the Defender for Servers plan, subscription association, Defender for Endpoint provisioning, vulnerability assessment, and extension health.


Question 10

An organization is onboarding highly sensitive Tier 0 servers through Azure Arc. Which approach best follows security best practices?

A. Use a dedicated subscription, minimize persistent administrative access, and review inherited policies and permissions.
B. Grant all administrators the Owner role at the tenant root scope.
C. Allow unrestricted extension deployment by all resource users.
D. Store onboarding credentials in a shared script repository.

Answer: A

Explanation: Highly sensitive servers should be isolated where practical, managed using least privilege, and protected from unnecessary administrative access and uncontrolled extension deployment. Onboarding credentials should also be securely managed.


Go to the SC-500 Exam Prep Hub main page

Identify security risks by using Defender CSPM (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Identify security risks by using Defender CSPM


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Cloud environments are constantly changing. New resources are deployed, permissions are modified, workloads are exposed to the internet, vulnerabilities are discovered, and applications increasingly incorporate AI capabilities. Because of this, security teams need more than point-in-time security checks—they need continuous visibility into their overall security posture and a way to determine which security issues represent the greatest risk.

Microsoft Defender Cloud Security Posture Management (Defender CSPM) is a capability within Microsoft Defender for Cloud that helps organizations identify, understand, prioritize, and remediate security risks across their cloud environments.

For the SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads exam, Defender CSPM is particularly important because it brings together several concepts:

  • Security posture assessment
  • Secure Score
  • Security recommendations
  • Risk-based prioritization
  • Attack path analysis
  • Cloud Security Explorer
  • Cloud Security Graph
  • Agentless scanning
  • Sensitive data discovery
  • Identity and permission analysis
  • Internet exposure
  • Multicloud security posture
  • Security posture for AI and other modern workloads

The objective is not simply to find the largest number of security problems. The goal is to determine which problems represent the greatest likelihood and potential impact of a successful attack.


1. What Is Cloud Security Posture Management?

Cloud Security Posture Management (CSPM) is the practice of continuously assessing cloud resources and configurations to identify security weaknesses, misconfigurations, compliance issues, vulnerabilities, and other risks.

A CSPM solution helps answer questions such as:

  • Which cloud resources are exposed to the internet?
  • Which resources have insecure configurations?
  • Which identities have excessive permissions?
  • Which workloads contain vulnerabilities?
  • Which resources contain sensitive data?
  • Which security recommendations should be remediated first?
  • Can an attacker combine several individual weaknesses into a path toward a critical resource?
  • Are security controls consistently applied across cloud environments?

Defender CSPM provides posture-management capabilities across cloud environments and uses contextual information to help security teams move from a large collection of individual findings toward a more meaningful understanding of organizational risk.

Microsoft describes Defender CSPM as providing visibility into the organization’s security situation while continually assessing resources, subscriptions, and the broader environment.


2. Defender CSPM in Microsoft Defender for Cloud

Microsoft Defender for Cloud provides two important perspectives on cloud security:

Cloud Security Posture Management

CSPM focuses primarily on understanding and improving the security configuration and posture of cloud environments.

Cloud Workload Protection

Workload protection capabilities focus more heavily on protecting specific workload types such as:

  • Servers
  • Containers
  • Storage
  • Databases
  • App services
  • AI services

For the SC-500 exam, remember:

CSPM helps you understand and improve the security posture of your cloud environment.

Defender CSPM extends this capability by adding contextual risk analysis, attack paths, Cloud Security Explorer, agentless scanning, sensitive-data discovery, entitlement insights, and other advanced capabilities.


3. Foundational CSPM vs. Defender CSPM

One important SC-500 concept is understanding the distinction between the foundational posture capabilities and the enhanced Defender CSPM plan.

Foundational CSPM

Foundational CSPM provides basic security posture capabilities, including visibility into security recommendations and the organization’s security posture.

Defender CSPM

The Defender CSPM plan adds more advanced capabilities, including:

  • Enhanced security posture management
  • Governance capabilities
  • Regulatory compliance capabilities
  • Cloud Security Explorer
  • Attack path analysis
  • Agentless machine scanning
  • Agentless Kubernetes discovery
  • Agentless container vulnerability assessment
  • Sensitive data discovery
  • Cloud Infrastructure Entitlement Management (CIEM)
  • Serverless protection
  • Additional contextual risk analysis

Microsoft’s current documentation specifically identifies governance, regulatory compliance, Cloud Security Explorer, attack path analysis, and agentless machine scanning as capabilities available through Defender CSPM.

Exam Tip

If a question asks which capability provides contextual investigation of relationships and potential attack paths, think:

Defender CSPM

rather than basic security posture assessment alone.


4. Understanding Security Posture

Security posture represents the overall security condition of an organization’s environment.

A strong security posture generally means that:

  • Resources are securely configured.
  • Access is appropriately restricted.
  • Vulnerabilities are addressed.
  • Sensitive data is appropriately protected.
  • Internet exposure is minimized.
  • Security policies are consistently applied.
  • High-risk recommendations are prioritized.
  • Attack paths are eliminated.
  • Security controls are continuously monitored.

Defender for Cloud continuously evaluates resources and generates security findings and recommendations.

Instead of treating every finding equally, Defender for Cloud can use contextual information to determine which findings represent greater risk.


5. Microsoft Secure Score

One of the most visible posture-management concepts in Defender for Cloud is Secure Score.

Secure Score provides an aggregated representation of security findings and helps organizations understand their overall security posture.

In general:

A higher Secure Score indicates a stronger security posture and lower identified risk.

The score is based on security findings and recommendations across the environment.

Example

Suppose an organization has 100 security recommendations.

Some might involve:

  • A low-impact configuration issue
  • A publicly exposed storage resource
  • An administrator account with excessive permissions
  • A vulnerable internet-facing virtual machine
  • A database containing sensitive information

Secure Score helps provide an overall posture indicator, but security teams should not assume that improving the score always means they have addressed the most dangerous threat.

This distinction is important.


6. Secure Score Is Not the Same as Risk Prioritization

A common SC-500 trap is assuming that the recommendation that improves Secure Score the most is automatically the recommendation that should be fixed first.

That is not necessarily true.

Defender for Cloud’s risk prioritization uses contextual factors such as:

  • Internet exposure
  • Permissions
  • Data sensitivity
  • Lateral movement potential
  • Exploitability
  • Relationships between resources
  • Attack path context

Current Defender for Cloud documentation explicitly distinguishes risk prioritization from Secure Score: risk prioritization does not affect the Secure Score itself.

Example

Consider two recommendations:

Recommendation A

A development storage account has a minor configuration issue and would significantly improve Secure Score if remediated.

Recommendation B

A vulnerable internet-facing VM has excessive privileges and a network path to a production database containing sensitive data.

Recommendation B should likely receive much higher operational priority even if fixing Recommendation A produces a larger Secure Score improvement.

Exam Principle

Secure Score tells you about overall posture; risk prioritization helps determine what deserves attention first.


7. Security Recommendations

A security recommendation identifies a security issue and provides guidance for addressing it.

A recommendation can contain information such as:

  • Description of the issue
  • Affected resource
  • Severity
  • Risk factors
  • Remediation guidance
  • Related security controls
  • Attack-path context, when applicable

Recommendations can therefore move the security team from:

Detection → Understanding → Remediation

Current Defender for Cloud recommendations can include severity, risk factors, affected resources, remediation guidance, and attack-path context.


8. Security Recommendations vs. Attack Paths

These concepts are related but different.

Security Recommendation

Identifies a specific security weakness.

For example:

A virtual machine should have a more restrictive network security configuration.

Attack Path

Shows how one or more weaknesses could potentially be combined to allow an attacker to reach a valuable target.

For example:

Internet → Exposed VM → Excessive permissions → Storage account → Sensitive data

The individual configuration issues may each appear as separate recommendations.

Attack path analysis provides the additional context that explains why those issues may represent a much greater combined risk.


9. What Is Attack Path Analysis?

Attack path analysis identifies exploitable paths that an attacker could potentially use to move from an external entry point toward a valuable target.

An attack path can include:

  1. An external entry point
  2. A vulnerable or misconfigured resource
  3. An identity or permission relationship
  4. A lateral movement opportunity
  5. A critical resource

Microsoft describes an attack path as a series of steps an attacker could use to breach an environment and reach a critical target.

Example

Imagine the following environment:

Internet
|
v
Public IP
|
v
Vulnerable Virtual Machine
|
v
Overprivileged Managed Identity
|
v
Storage Account
|
v
Sensitive Customer Data

Looking at the VM alone might produce one security recommendation.

Looking at the identity alone might produce another.

Looking at the storage account alone might produce another.

Attack path analysis connects these conditions together.

That context can reveal that the combined risk is substantially more serious than any individual finding suggests.


10. Attack Path Analysis Uses the Cloud Security Graph

Defender for Cloud uses a Cloud Security Graph to understand relationships between resources and security conditions.

The graph can incorporate information such as:

  • Cloud resources
  • Resource relationships
  • Network connections
  • Internet exposure
  • Permissions
  • Identities
  • Vulnerabilities
  • Lateral movement possibilities
  • Sensitive data
  • Other security context

Defender for Cloud uses this contextual graph to identify potential attack paths and prioritize high-risk issues.

Simplified Model

                 Cloud Security Graph
                         |
       +-----------------+-----------------+
       |                 |                 |
   Resources         Identities        Vulnerabilities
       |                 |                 |
       +-----------------+-----------------+
                         |
                   Risk Analysis
                         |
              +----------+----------+
              |                     |
        Attack Paths         Security Explorer

This graph-based approach is one of the most important concepts to understand for the exam.


11. What Makes an Attack Path High Risk?

Attack path analysis considers multiple contextual factors.

Examples include:

Internet exposure

Is the resource reachable from outside the organization’s environment?

Permissions

Does an identity associated with the resource have access to other important resources?

Lateral movement

Can an attacker move from the compromised resource to another resource?

Vulnerability

Does the resource contain a vulnerability that can potentially be exploited?

Data sensitivity

Does the target contain sensitive or business-critical information?

Exploitability

Is the identified weakness realistically exploitable?

The combination of these factors helps Defender for Cloud identify paths that deserve attention.


12. Why Attack Path Analysis Is Different from a Vulnerability List

A traditional vulnerability list might look like:

ResourceFinding
VM01Critical vulnerability
VM02High vulnerability
Storage01Public access
SQL01Excessive permissions

The list does not necessarily tell you how these findings relate to one another.

Attack path analysis adds context:

Attack PathRisk
Internet → VM01 → Identity → SQL01Critical
Internet → VM02Medium
Storage01 → Sensitive dataHigh

This allows security teams to focus on security issues that can contribute to an actual attack scenario.


13. Cloud Security Explorer

Cloud Security Explorer provides a way to proactively investigate security risks by querying the Cloud Security Graph.

Instead of waiting for a predefined recommendation, security teams can use queries to investigate relationships and identify risks based on organizational requirements.

For example, a security team might want to find:

  • Internet-exposed resources with vulnerabilities
  • Resources with excessive permissions
  • Virtual machines that can reach sensitive databases
  • Resources containing sensitive data
  • Kubernetes resources with risky configurations
  • Resources connected to identities with excessive privileges

Cloud Security Explorer uses graph-based queries against contextual security information to help security teams proactively investigate risk.


14. Attack Path Analysis vs. Cloud Security Explorer

These two features are easy to confuse.

CapabilityPrimary Purpose
Attack Path AnalysisIdentify exploitable paths attackers could use
Cloud Security ExplorerProactively investigate and query security relationships
Security RecommendationsIdentify and remediate individual security issues
Secure ScoreProvide an aggregated view of security posture

Easy Way to Remember

Attack Path Analysis

“How could an attacker get from here to there?”

Cloud Security Explorer

“What security relationships and risks exist in my environment?”


15. Agentless Machine Scanning

Defender CSPM supports agentless machine scanning.

Agentless scanning can provide visibility into:

  • Installed software
  • Vulnerabilities
  • Secrets
  • Malware-related findings where supported by the applicable Defender plan

The important advantage is that scanning can occur without installing an agent on the machine and without requiring network access to the machine for the scanning process.

Current documentation states that agentless scanning does not require agents or network access and is designed not to affect machine performance. Running VMs are scanned on a recurring schedule.

Why This Matters

Agentless scanning can be especially useful when organizations need visibility into large numbers of machines without deploying and maintaining additional agents.


16. Agentless Kubernetes Discovery

Defender CSPM also provides agentless discovery capabilities for supported Kubernetes environments.

Agentless Kubernetes discovery can provide visibility into:

  • Kubernetes clusters
  • Cluster configuration
  • Workloads
  • Networking
  • Node pools
  • Kubernetes resources

This information can contribute to posture assessment, security investigation, and attack-path analysis.

Current Defender CSPM capabilities include API-based agentless discovery and contextual risk analysis for Kubernetes resources.


17. Sensitive Data Discovery

Security risk is not determined solely by whether a resource is vulnerable.

A vulnerability involving a system containing sensitive information may be considerably more important than an identical vulnerability involving a low-value development resource.

Defender CSPM provides sensitive data discovery capabilities that can identify managed cloud data resources containing sensitive information.

This information can then be incorporated into security investigations and attack-path analysis.

For example:

Internet Exposure
|
v
Vulnerable Resource
|
v
Identity with Permissions
|
v
Storage Resource
|
v
Sensitive Data

The presence of sensitive data increases the potential business impact of the attack path.

Defender for Cloud can use sensitive-data insights in attack paths and Cloud Security Explorer when the relevant capabilities are enabled.


18. Cloud Infrastructure Entitlement Management

Defender CSPM also provides Cloud Infrastructure Entitlement Management (CIEM) capabilities.

CIEM focuses on understanding identities, permissions, and access rights across cloud environments.

Security teams can use CIEM-related insights to identify situations such as:

  • Excessive permissions
  • Unused permissions
  • Overprivileged identities
  • Risky access relationships

This is particularly important because an attacker who compromises an identity may inherit all the permissions assigned to that identity.

Example

Compromised VM
|
v
Managed Identity
|
+---- Storage Account
|
+---- Key Vault
|
+---- Database

The security risk of the VM is therefore affected by the permissions associated with its identity.

This is another reason why CSPM evaluates relationships, rather than only individual resources.


19. Internet Exposure

Internet exposure is an important risk factor in cloud security.

A resource that is:

  • Internet accessible
  • Vulnerable
  • Overprivileged
  • Connected to sensitive resources

may represent a significantly greater risk than an equivalent resource that is completely isolated.

Defender CSPM incorporates internet exposure into contextual security analysis.

Defender CSPM also integrates external attack surface management capabilities to discover internet-facing cloud resources and identify exploitable paths originating from internet-exposed IP addresses.


20. Risk-Based Security Prioritization

One of the most important principles in Defender CSPM is:

Not every security finding deserves the same priority.

Security teams frequently face thousands of findings.

A simple severity-only approach can overwhelm security teams.

Instead, Defender for Cloud can consider contextual factors such as:

  • Exposure
  • Exploitability
  • Permissions
  • Data sensitivity
  • Lateral movement
  • Resource relationships
  • Attack-path context

This enables organizations to focus first on findings that could realistically contribute to a significant security incident.


21. Example: Prioritizing Two Vulnerabilities

Suppose an organization has two critical vulnerabilities.

VM-A

  • Critical vulnerability
  • No public exposure
  • No sensitive data
  • Limited permissions
  • Isolated network

VM-B

  • Critical vulnerability
  • Internet exposed
  • High-privilege identity
  • Can access production SQL
  • Production SQL contains sensitive data

Although both vulnerabilities are technically critical, VM-B represents the more concerning security scenario.

The reason is not merely the vulnerability severity.

It is the context surrounding the vulnerability.


22. Defender CSPM and AI Workloads

Modern cloud security posture management increasingly includes AI workloads.

Defender CSPM can incorporate security context involving AI resources and AI-related attack paths.

This is important for SC-500 because the certification specifically includes cloud and AI workloads.

Potential AI security concerns include:

  • Internet-exposed AI resources
  • Excessive permissions assigned to AI identities
  • Insecure connections between AI components
  • Sensitive data accessible to AI workloads
  • Vulnerable supporting infrastructure
  • Attack paths involving AI resources

The same fundamental principle applies:

An AI resource should be evaluated in the context of its identities, permissions, data, network exposure, vulnerabilities, and relationships with other resources.


23. Defender CSPM and Multicloud Environments

CSPM is not limited to Azure-only environments.

Defender for Cloud can provide CSPM capabilities across supported multicloud environments, including AWS and Google Cloud Platform.

After supported cloud environments are connected, Defender for Cloud can assess their security posture and surface relevant security information.

This provides a centralized security posture perspective rather than forcing security teams to use completely separate posture-management systems for every cloud provider.


24. Security Posture Management Workflow

A useful way to understand Defender CSPM is to think of it as a continuous cycle:

       Discover
          |
          v
       Assess
          |
          v
       Identify
          |
          v
     Contextualize
          |
          v
      Prioritize
          |
          v
       Remediate
          |
          v
       Reassess
          |
          +------------------+
                             |
                             v
                          Discover

Step 1 — Discover

Identify resources, identities, configurations, vulnerabilities, relationships, and exposure.

Step 2 — Assess

Evaluate resources against security standards and policies.

Step 3 — Identify

Generate security recommendations and other findings.

Step 4 — Contextualize

Use relationships, exposure, permissions, vulnerabilities, and data sensitivity to understand risk.

Step 5 — Prioritize

Focus on the risks that could have the greatest impact.

Step 6 — Remediate

Correct the underlying security weaknesses.

Step 7 — Reassess

Verify that the security posture has improved.


25. A Practical Defender CSPM Investigation

Consider an organization that receives a recommendation indicating that a virtual machine has a serious vulnerability.

A security analyst should not necessarily stop at the recommendation.

The analyst can investigate:

Question 1

Is the VM exposed to the internet?

Question 2

Does the VM have a managed identity?

Question 3

What permissions does that identity have?

Question 4

Can the VM communicate with production resources?

Question 5

Can it reach a database?

Question 6

Does that database contain sensitive information?

Question 7

Is the vulnerability actually exploitable?

Question 8

Does Defender for Cloud identify an attack path involving the VM?

Question 9

Are there additional related recommendations?

Question 10

What remediation would break the attack path most effectively?

This is the mindset the SC-500 exam is testing.


26. Attack Path Remediation

Attack path analysis isn’t simply about identifying problems.

The goal is to break the attack path.

For example:

Internet
|
v
Public VM
|
v
Overprivileged Identity
|
v
Sensitive Storage

There may be several ways to break this path:

Option 1

Remove unnecessary internet exposure.

Option 2

Fix the vulnerability.

Option 3

Reduce identity permissions.

Option 4

Restrict access to the storage account.

Option 5

Apply multiple controls.

The best remediation may not always be the one that addresses the original finding directly. The goal is to eliminate the exploitable path or substantially reduce its risk.


27. Security Explorer Example

Suppose a security team wants to investigate:

“Find internet-exposed resources that have vulnerabilities and can reach sensitive data.”

Cloud Security Explorer can be used to construct graph-based queries that examine these relationships.

Conceptually:

Internet Exposure
|
AND
|
Vulnerable Resource
|
AND
|
Network/Identity Relationship
|
AND
|
Sensitive Data

This is fundamentally different from simply searching a list of vulnerabilities.

The security team is asking the platform to identify relationships and contextual risk.


28. Recommendations, Secure Score, Attack Paths, and Security Explorer

These four concepts should be clearly differentiated for the SC-500 exam.

CapabilityWhat It Answers
Secure ScoreHow strong is our overall security posture?
Security RecommendationsWhat security weaknesses should we address?
Attack Path AnalysisHow could an attacker exploit connected weaknesses to reach a valuable target?
Cloud Security ExplorerWhat security relationships and risks can we discover by querying the security graph?

Memorization Tip

Think:

Score → Recommendations → Paths → Explore

  • Score = posture
  • Recommendations = issues
  • Paths = attacker movement
  • Explorer = investigate relationships

29. Common Defender CSPM Mistakes

Mistake 1: Fixing recommendations solely based on severity

Severity is important, but contextual risk can change remediation priority.


Mistake 2: Assuming Secure Score represents total security risk

Secure Score is an important posture metric, but it should not be treated as a complete representation of business or attack-path risk.


Mistake 3: Looking at vulnerabilities individually

A vulnerability becomes more concerning when it is combined with:

  • Internet exposure
  • Excessive permissions
  • Lateral movement
  • Sensitive data
  • Other exploitable weaknesses

Mistake 4: Ignoring identities

A compromised workload with minimal permissions may have limited impact.

The same workload with excessive privileges may provide an attacker with access to many other resources.


Mistake 5: Ignoring sensitive data

The value of the target matters.

A vulnerability that leads to sensitive customer information should generally receive greater attention than an equivalent vulnerability affecting an isolated test resource.


Mistake 6: Confusing Attack Path Analysis with Cloud Security Explorer

Attack Path Analysis focuses on identifying exploitable attacker paths.

Cloud Security Explorer is designed for proactive graph-based exploration and investigation.


Mistake 7: Assuming CSPM only applies to virtual machines

Modern CSPM extends across many resource types, including:

  • Servers
  • Storage
  • Containers
  • Kubernetes
  • Serverless resources
  • Databases
  • Identities
  • AI workloads
  • Multicloud resources

30. SC-500 Exam-Focused Comparison

ScenarioBest Concept
Determine overall security postureSecure Score
Identify a configuration weaknessSecurity Recommendation
Determine how an attacker can reach a sensitive resourceAttack Path Analysis
Query relationships across cloud resourcesCloud Security Explorer
Scan machines without installing an agentAgentless Machine Scanning
Identify sensitive data that increases breach impactSensitive Data Discovery
Analyze excessive cloud permissionsCIEM
Find internet-facing cloud resourcesExternal Attack Surface Management integration
Prioritize risks based on contextual factorsRisk-based prioritization
Understand resource relationshipsCloud Security Graph

31. Key SC-500 Takeaways

For the exam, remember these principles:

  1. CSPM is about security posture management, not merely vulnerability scanning.
  2. Secure Score provides an aggregated view of security posture.
  3. Security recommendations identify specific security weaknesses and remediation actions.
  4. Risk prioritization uses contextual factors to help determine which findings matter most.
  5. Attack Path Analysis identifies exploitable paths that attackers could use to reach important resources.
  6. The Cloud Security Graph provides contextual relationships between resources, identities, vulnerabilities, exposure, and other security information.
  7. Cloud Security Explorer allows security teams to proactively investigate security relationships using graph-based queries.
  8. Agentless scanning can provide machine visibility without installing an agent.
  9. Sensitive data discovery adds data sensitivity to security-risk analysis.
  10. CIEM helps organizations understand cloud identities, permissions, and entitlement risks.
  11. Internet exposure is an important factor in contextual risk analysis.
  12. Defender CSPM can provide posture capabilities across supported multicloud environments.
  13. CSPM increasingly includes AI workloads and AI-related security risks.
  14. The objective is not to eliminate every finding equally—it is to identify, prioritize, and remediate the risks most likely to result in meaningful compromise.

Practice Exam Questions

Question 1

A security administrator is reviewing thousands of security recommendations in Microsoft Defender for Cloud. The administrator wants to identify the recommendations that could represent the greatest risk of an actual breach.

Which capability should the administrator use?

A. Secure Score

B. Attack path analysis

C. Regulatory compliance dashboard

D. Azure Resource Graph

Answer: B

Explanation

Attack path analysis provides contextual information about exploitable paths through the environment. It considers relationships such as internet exposure, permissions, vulnerabilities, lateral movement, and critical targets.

Secure Score provides an overall posture indicator, but it is not designed to show how an attacker could move through the environment.


Question 2

An organization wants to proactively investigate whether virtual machines with internet exposure can reach storage accounts containing sensitive information.

Which Defender for Cloud capability is most appropriate?

A. Cloud Security Explorer

B. Secure Score

C. Regulatory compliance

D. Microsoft Defender for Endpoint

Answer: A

Explanation

Cloud Security Explorer allows security teams to perform graph-based queries against contextual security information.

The administrator can investigate relationships involving:

  • Internet exposure
  • Virtual machines
  • Network relationships
  • Identities
  • Permissions
  • Sensitive data

Secure Score does not provide this type of relationship-oriented investigation.


Question 3

A company has two security recommendations. Recommendation 1 would produce a larger improvement in Secure Score. Recommendation 2 involves an internet-facing vulnerable server with excessive permissions that can potentially access a sensitive production database.

Which statement is most accurate?

A. Recommendation 1 must always be remediated first because it produces the largest Secure Score improvement.

B. Recommendation 2 should be ignored until Recommendation 1 is remediated.

C. Recommendation 2 may represent greater risk because of its contextual attack-path factors.

D. Both recommendations must always receive exactly the same priority.

Answer: C

Explanation

Secure Score improvement and security-risk prioritization are not the same thing.

The second recommendation has multiple contextual risk factors:

  • Internet exposure
  • Vulnerability
  • Excessive permissions
  • Potential lateral movement
  • Access to sensitive data

Those factors can make the second recommendation substantially more important from a real-world security perspective.


Question 4

Which component provides the contextual relationship information used by Defender for Cloud to understand resources, permissions, vulnerabilities, network connections, and potential attacker movement?

A. Secure Score

B. Azure Policy

C. Cloud Security Graph

D. Microsoft Sentinel

Answer: C

Explanation

The Cloud Security Graph is the contextual graph used by Defender for Cloud to represent relationships across cloud resources and security information.

Defender for Cloud can use this graph for capabilities such as attack path analysis and Cloud Security Explorer.


Question 5

A security engineer wants to obtain software inventory and vulnerability information from Azure virtual machines without installing an agent on each machine.

Which Defender for Cloud capability should the engineer consider?

A. Agentless machine scanning

B. Cloud Security Explorer

C. Secure Score

D. Attack path analysis

Answer: A

Explanation

Agentless machine scanning provides visibility into machine software and vulnerabilities without requiring an agent to be installed on the machine.

Agentless scanning is an important Defender CSPM capability.


Question 6

A security team discovers that a compromised application identity has permissions to access several storage resources. The team wants to understand whether excessive cloud permissions are creating additional security risk.

Which capability is most directly associated with this requirement?

A. Cloud Infrastructure Entitlement Management (CIEM)

B. Secure Score

C. External Attack Surface Management

D. Azure DDoS Protection

Answer: A

Explanation

Cloud Infrastructure Entitlement Management (CIEM) provides visibility into cloud identities, permissions, and access rights.

Understanding excessive permissions is particularly important when evaluating the potential impact of a compromised identity.


Question 7

A security analyst sees a critical vulnerability on a server. The server is not publicly exposed and has no meaningful access to other resources.

Another server has the same vulnerability but is internet-facing and has an identity that can access a production database containing sensitive information.

Why might the second server receive a higher risk priority?

A. Its Secure Score contribution is necessarily higher.

B. Its operating system is necessarily newer.

C. It has fewer security recommendations.

D. Its vulnerability is combined with exposure, permissions, lateral movement, and sensitive-data context.

Answer: D

Explanation

Defender CSPM uses contextual risk factors to help prioritize security issues.

The second server presents a potentially exploitable chain:

Internet → Vulnerable server → Privileged identity → Sensitive database

The context surrounding the vulnerability is therefore much more significant than the vulnerability alone.


Question 8

Which statement best describes the primary purpose of Cloud Security Explorer?

A. Replace all vulnerability scanners in the environment

B. Provide graph-based investigation of security relationships and risks

C. Calculate only the organization’s Secure Score

D. Automatically patch every vulnerable resource

Answer: B

Explanation

Cloud Security Explorer allows security teams to proactively investigate the cloud security graph using graph-based queries.

It can help identify relationships involving resources, identities, vulnerabilities, exposure, permissions, and other security context.

It is an investigation and discovery capability—not an automatic patching engine.


Question 9

An organization wants to determine whether an internet-exposed resource provides an exploitable route to a critical database.

Which Defender for Cloud feature is specifically designed to identify this type of attacker route?

A. Attack path analysis

B. Secure Score

C. Azure Policy

D. Microsoft Defender Vulnerability Management

Answer: A

Explanation

Attack path analysis identifies exploitable paths beginning with potential external entry points and continuing through the environment toward valuable targets.

The feature is specifically designed to help security teams understand how multiple weaknesses could combine to create a realistic attack scenario.


Question 10

Which statement best describes the relationship between Secure Score and risk prioritization in Defender for Cloud?

A. Risk prioritization and Secure Score are identical measurements.

B. Secure Score is based exclusively on attack paths.

C. Risk prioritization can use contextual factors that are not represented simply by the Secure Score.

D. A recommendation with the largest Secure Score impact must always be remediated first.

Answer: C

Explanation

Secure Score provides an aggregated view of security posture, while risk prioritization evaluates contextual factors that can make one issue more dangerous than another.

Factors can include:

  • Internet exposure
  • Permissions
  • Data sensitivity
  • Lateral movement
  • Exploitability
  • Attack-path context

Therefore, improving Secure Score is valuable, but security teams should also consider the actual risk associated with each finding.


Final Exam Reminder

The central idea behind this SC-500 topic is:

Defender CSPM moves security teams from simply finding security problems to understanding which problems create the greatest real-world risk.

If you remember the progression:

Security Findings → Context → Risk → Attack Paths → Prioritization → Remediation

you will have a strong conceptual foundation for questions involving Defender CSPM, Secure Score, security recommendations, Cloud Security Explorer, Cloud Security Graph, attack paths, agentless scanning, sensitive data, and identity/permission risk.


Go to the SC-500 Exam Prep Hub main page

Enable and configure Defender for Cloud workload protection plans (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Enable and configure Defender for Cloud workload protection plans


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Defender for Cloud provides security capabilities for cloud environments from security posture management through active workload protection.

For the SC-500 exam, an important distinction is between:

  • Cloud Security Posture Management (CSPM) — identifies security weaknesses, misconfigurations, exposure, and compliance gaps.
  • Cloud Workload Protection Platform (CWPP) — provides workload-specific threat protection and security capabilities for resources such as servers, containers, databases, storage, applications, APIs, and AI services.

Defender for Cloud’s workload protection plans are enabled according to the types of workloads an organization needs to protect. These plans provide capabilities such as threat detection, vulnerability assessment, runtime protection, malware scanning, and other workload-specific security controls.

For the SC-500 exam, you should understand which Defender plan protects which workload, how to enable the plan, how to configure important plan-specific settings, how to deploy plans at scale, and how to verify coverage.


1. What Is Cloud Workload Protection?

Cloud workload protection focuses on protecting workloads while they are running, rather than simply identifying whether their configuration is secure.

For example:

WorkloadPotential Security ConcernRelevant Defender Capability
Virtual machinesMalware, vulnerabilities, suspicious activityDefender for Servers
KubernetesVulnerable containers, runtime attacksDefender for Containers
Azure StorageMalicious uploads, data threatsDefender for Storage
Azure SQLDatabase attacks and vulnerabilitiesDefender for Databases
App ServiceAttacks against web applicationsDefender for App Service
APIsAPI vulnerabilities and attacksDefender for APIs
Key VaultSuspicious access to secrets and keysDefender for Key Vault
AI servicesThreats against generative AI applicationsDefender for AI Services
Azure resource managementSuspicious resource-management operationsDefender for Resource Manager
DNSDNS-layer threatsDefender for DNS

The important SC-500 concept is that you select protection plans based on the workloads that exist in your environment.

Defender for Cloud currently provides a broad catalog of workload-specific protection plans, including servers, containers, storage, databases, Key Vault, App Service, APIs, AI Services, DNS, and Resource Manager.


2. CSPM vs. CWPP

One of the most important distinctions for the exam is the difference between CSPM and workload protection.

Cloud Security Posture Management

CSPM answers questions such as:

“Is this environment configured securely?”

Examples include:

  • Is a storage account publicly accessible?
  • Is encryption configured?
  • Is a network security control missing?
  • Does a resource violate a security policy?
  • Does the environment have excessive risk?

Defender for Cloud’s foundational CSPM capabilities include recommendations, asset inventory, workbooks, Secure Score, and Microsoft cloud security benchmark capabilities.

Cloud Workload Protection

CWPP answers questions such as:

“Is this workload currently protected against threats?”

Examples include:

  • Is a VM protected against malware and endpoint threats?
  • Is a Kubernetes cluster receiving runtime threat detection?
  • Is malicious content being detected when uploaded to storage?
  • Are suspicious database activities being detected?
  • Are API attacks being detected?
  • Are AI workloads receiving threat protection?

Exam tip:

CSPM focuses primarily on improving security posture.
CWPP focuses primarily on protecting workloads from active threats.

In real environments, the two capabilities complement each other rather than replacing one another.


3. Defender for Cloud Workload Protection Plans

Defender for Cloud contains multiple workload-specific plans.

Some of the important plans for SC-500 include:

Defender for Servers

Protects physical and virtual machines across Azure and supported multicloud environments.

Defender for Servers provides capabilities such as:

  • Threat detection
  • Endpoint protection integration
  • Vulnerability assessment
  • Security recommendations
  • Agentless scanning
  • Additional Plan 2 capabilities

Defender for Servers is available as Plan 1 (P1) and Plan 2 (P2).


Defender for Containers

Protects Kubernetes environments, including supported Azure Kubernetes Service, Amazon EKS, Google GKE, and Azure Arc-enabled Kubernetes environments.

Depending on the environment and configuration, capabilities can include:

  • Vulnerability scanning
  • Runtime threat protection
  • Security posture assessments
  • Agentless scanning
  • Defender sensor
  • Kubernetes API access
  • Registry access

The exact components available depend on the Kubernetes environment and configuration.


Defender for Storage

Defender for Storage provides security monitoring and threat detection for Azure Storage.

The current plan includes capabilities such as:

  • Activity monitoring
  • On-upload malware scanning
  • Sensitive-data threat detection

Malware scanning can also be configured with options such as scanning limits, filtering, scan-result storage, and automated integration through Event Grid or Log Analytics.


Defender for Databases

Defender for Databases protects supported database workloads.

For example, Defender for Azure SQL Databases provides attack detection and threat-response capabilities for Azure SQL databases.

The broader database protection capabilities also include support for other database workloads, depending on the specific Defender plan and supported environment.

For SQL Server running on machines, the SQL Servers on Machines protection is selected within the Defender for Databases plan.


Defender for App Service

Defender for App Service provides protection for applications running on Azure App Service.

It is designed to identify attacks targeting App Service web applications and APIs.


Defender for APIs

Defender for APIs provides security visibility and protection for APIs managed through Azure API Management.

Capabilities include:

  • API discovery
  • Security posture assessment
  • Vulnerability prioritization
  • Threat detection
  • Runtime protection

Defender for APIs is enabled at the subscription level, and the appropriate plan should be selected based on API traffic requirements.

Important exam consideration: enabling Defender for APIs does not automatically mean that every API in existence is protected. The APIs must be onboarded appropriately, and the APIs you want to protect must be published through Azure API Management.


Defender for Key Vault

Defender for Key Vault detects unusual and potentially harmful attempts to access or exploit Key Vault accounts.

This is particularly important because Key Vault can contain highly sensitive:

  • Secrets
  • Encryption keys
  • Certificates

The purpose is not simply to encrypt the vault. Defender for Key Vault adds threat-detection capabilities around access and usage.


Defender for AI Services

AI workloads introduce threats that traditional infrastructure security controls may not completely address.

Defender for AI Services provides threat protection for generative AI applications and can detect suspicious activity involving supported AI services.

For SC-500, remember:

AI workloads are now explicitly part of the Defender for Cloud workload-protection model.

This is especially relevant because the SC-500 certification focuses on cloud and AI workloads, rather than traditional cloud infrastructure alone.


Defender for Resource Manager

Defender for Resource Manager monitors Azure resource-management operations and can detect suspicious activity involving management operations.

This protects an important control plane:

The Azure Resource Manager layer through which resources are created, modified, and managed.

It is different from protecting a VM’s operating system or a storage account’s data plane.


Defender for DNS

Defender for DNS provides DNS-layer threat detection for Azure resources.

This illustrates another important Defender for Cloud concept:

Defender plans are specialized according to the attack surface being protected.


4. Choosing the Appropriate Defender Plan

A common SC-500 scenario is:

“An organization has identified a particular workload and wants to enable the appropriate Defender protection.”

The first step is to identify the workload.

For example:

RequirementAppropriate plan
Protect Azure VMsDefender for Servers
Protect AKS/KubernetesDefender for Containers
Detect malicious files uploaded to StorageDefender for Storage
Protect Azure SQL databasesDefender for Databases
Protect App Service applicationsDefender for App Service
Protect APIs managed through API ManagementDefender for APIs
Detect suspicious Key Vault accessDefender for Key Vault
Protect generative AI servicesDefender for AI Services
Detect suspicious Azure resource-management operationsDefender for Resource Manager
Detect DNS-based threatsDefender for DNS

The exam may deliberately include several plausible answers.

The key is to identify the workload, not simply the type of security problem.


5. Enabling Defender for Cloud

Before configuring individual workload protection plans, Defender for Cloud must be enabled for the relevant environment.

For Azure, Defender for Cloud can be accessed through the Azure portal.

Once the environment is available, the administrator can use:

Microsoft Defender for Cloud → Environment settings

From there, the administrator selects the relevant:

  • Azure subscription
  • AWS account
  • GCP project
  • Other supported environment/connector

The available Defender plans can then be configured for that environment.


6. Environment Settings

The Environment settings area is particularly important for SC-500.

It provides a centralized location for configuring Defender plans for the selected environment.

A typical workflow is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the target environment.
  4. Locate the desired Defender plan.
  5. Turn the plan On.
  6. Configure plan-specific settings.
  7. Save the configuration.
  8. Verify coverage.

For example, to enable Defender for Servers, you select the appropriate environment, turn on the Servers plan, choose the appropriate plan tier, and save the configuration.


7. Defender for Servers Plan 1 vs. Plan 2

Defender for Servers is especially important for the SC-500 exam because it contains two plan levels:

  • Plan 1
  • Plan 2

When enabling Defender for Servers, Plan 2 is selected by default in the current Azure portal workflow, but the administrator can change the selection to Plan 1.

The plans provide different levels of capability.

For example:

CapabilityPlan 1Plan 2
Defender for Endpoint integrationYesYes
Vulnerability assessmentYesYes
Agentless scanning—Yes
File integrity monitoring—Available
Additional advanced capabilitiesLimitedMore extensive

Current configuration guidance indicates that vulnerability assessment is enabled by default when either P1 or P2 is enabled, Defender for Endpoint integration is available with both, and agentless scanning is associated with Plan 2. File integrity monitoring is a Plan 2 capability that is not enabled by default.

Exam strategy

If a question specifically requires a Plan 2-only capability, Plan 1 is not sufficient.

Do not assume:

“Servers enabled = every Defender for Servers capability is enabled.”

Instead, identify the required capability and determine which plan provides it.


8. Configuring Defender for Servers

After enabling Defender for Servers, plan-specific settings can be configured.

Examples include:

Vulnerability assessment

Helps identify vulnerable software and applications on protected machines.

Endpoint protection

Defender for Endpoint integration provides endpoint detection and response capabilities.

Agentless scanning

Agentless scanning can provide additional visibility without requiring a traditional security agent for certain scanning scenarios.

File integrity monitoring

File integrity monitoring can identify changes to important files and registries.

The availability and default state of these capabilities depend on the selected plan.


9. Defender for Storage Configuration

Defender for Storage provides several important configurable capabilities.

The current Defender for Storage plan includes:

  • Activity monitoring
  • Malware scanning
  • Sensitive-data threat detection

Malware scanning can be configured with options such as:

  • Monthly scanning caps
  • Scan filtering
  • Blob index tags for scan results
  • Soft deletion of malicious blobs
  • Event Grid integration
  • Log Analytics integration

Example

Suppose an organization uploads customer documents to Azure Blob Storage.

The security team wants to:

  1. Detect malicious files immediately after upload.
  2. Record scan results.
  3. Automatically initiate downstream processing when malware is discovered.

Defender for Storage can provide the malware scanning capability, while Event Grid can be used to integrate scan results into automated response workflows.


10. Defender for Storage: Important Exam Distinction

Do not confuse:

Activity monitoring

with:

Malware scanning

Activity monitoring provides security analysis of activity involving storage.

Malware scanning specifically detects malicious files, including files uploaded to storage.

Similarly, sensitive-data threat detection addresses suspicious activity involving resources containing sensitive data.

Therefore, if an exam question says:

“Detect malicious files as they are uploaded to Blob Storage.”

The relevant capability is:

Defender for Storage with on-upload malware scanning.


11. Defender for Databases

Defender for Databases protects database workloads against threats and vulnerabilities.

For Azure SQL databases, Defender for Azure SQL Databases can be enabled through the Databases plan.

The administrator:

  1. Opens Defender for Cloud.
  2. Selects Environment settings.
  3. Selects the relevant environment.
  4. Locates Databases.
  5. Selects Select types.
  6. Enables Azure SQL Databases.
  7. Selects Continue.
  8. Saves the configuration.

This illustrates an important Defender for Cloud design:

A single high-level plan may contain multiple workload-specific resource types.

For example, Defender for Databases contains multiple database protection capabilities rather than representing only one specific database engine.


12. SQL Servers on Machines

SQL Server workloads may run on:

  • Azure virtual machines
  • Azure Arc-enabled servers

For SQL Servers on Machines, the protection is configured under the Defender for Databases plan.

The administrator can select the SQL Servers on Machines resource type within the Databases plan.

This is a useful exam distinction.

If a question describes:

“SQL Server installed on an Azure VM”

do not automatically treat it as the same configuration scenario as an Azure SQL Database.

The underlying workload type matters.


13. Defender for Containers

Defender for Containers protects Kubernetes environments.

Depending on the environment, administrators can configure components such as:

  • Agentless scanning
  • Defender sensor
  • Azure Policy
  • Kubernetes API access
  • Registry access

These capabilities support different aspects of container security.

For example:

Defender sensor

is associated with collecting runtime security telemetry used for threat detection.

Registry access

supports vulnerability assessment for container images in connected registries.

Azure Policy

supports Kubernetes security posture assessment and related recommendations.

Kubernetes API access

allows Defender for Cloud to obtain Kubernetes metadata required for inventory, configuration analysis, and related capabilities.


14. Defender for APIs

Defender for APIs provides protection for APIs managed through Azure API Management.

Its capabilities include:

  • Discovery
  • Security posture visibility
  • Vulnerability prioritization
  • Runtime threat detection
  • Response capabilities

One important configuration consideration is selecting the appropriate plan based on API traffic.

The current deployment guidance indicates that subscriptions are opted into Plan 1 by default and that organizations should select a plan appropriate for their API traffic volume to avoid unexpected overages.

Exam scenario

A company has a high-volume API platform.

The question asks what should be considered before selecting the Defender for APIs plan.

The best answer is likely to focus on:

API traffic volume and the plan entitlement associated with that traffic.


15. Defender for AI Services

AI workloads require specialized protection because they introduce risks beyond conventional infrastructure.

Defender for Cloud’s AI threat protection can provide:

  • AI workload discovery
  • Security posture capabilities
  • Runtime threat detection
  • Security alerts
  • Investigation capabilities

Microsoft’s current Defender for Cloud training specifically includes enabling and configuring the AI workloads plan and reviewing AI resource insights, posture, and runtime threats.

This is particularly important for SC-500 because AI security is integrated directly into the certification’s scope.


16. AI Threat Detection and Application Context

AI security can involve applications that sit between an end user and an AI service.

For example:

User → Web application → Azure OpenAI → Model

The AI service may see a request, but security investigators may need to understand:

  • Which user initiated it?
  • Which application generated it?
  • What source IP was involved?

Defender for Cloud’s AI threat protection can use additional security context to improve alert investigation. Microsoft documents the use of fields such as end-user identity, source IP, and application name for supported Azure OpenAI scenarios.

The important SC-500 concept is:

AI workload protection is not limited to infrastructure configuration; it can also provide runtime threat detection and investigation context.


17. Azure-Only vs. Multicloud Defender Plans

Not every Defender for Cloud workload plan applies to every cloud.

Some plans support Azure, AWS, and GCP workloads, while others are Azure-specific.

For example, current support information identifies these as Azure-only plans:

  • Defender for Storage
  • Defender for Key Vault
  • Defender for Resource Manager
  • Defender for DNS
  • Defender for App Service
  • Defender for APIs
  • Defender for AI Services

Defender for Servers and Defender for Containers, by contrast, have significant multicloud support.

Exam tip

If a question says:

“An organization wants to protect an AWS EC2 instance.”

Think about plans that support multicloud workloads, such as:

Defender for Servers

rather than Azure-only plans such as Defender for Storage.


18. Subscription-Level vs. Resource-Level Configuration

Defender for Cloud supports different deployment scopes depending on the plan.

A common approach is to enable a workload protection plan at the subscription level.

This is generally easier to manage and provides broader coverage.

Some scenarios also support resource-level configuration.

For example, Defender for Servers can be configured at different scopes, although Microsoft recommends subscription-level deployment for many scenarios.

However, resource-level configuration can be useful when:

  • Different workloads require different protection levels.
  • Specific resources need to be excluded.
  • An organization is transitioning workloads.
  • Different security requirements exist within the same subscription.

Important exam concept

Do not assume every Defender plan supports the same resource-level configuration options.

Always evaluate the specific plan.


19. Management Group Deployment

Large organizations often have many subscriptions.

Enabling every Defender plan manually on every subscription can be inefficient.

Defender for Cloud can be managed at larger scopes, including management groups, where supported.

This enables organizations to establish consistent protection across a portfolio of subscriptions.

The basic enterprise pattern is:

Management Group

↓

Subscriptions

↓

Workloads

The objective is centralized governance combined with consistent security coverage.


20. Deploying Defender Plans at Scale

Azure Policy can be used to help configure Defender for Cloud plans at scale.

Microsoft provides built-in policy initiatives for configuring Defender plans.

For example, there are built-in policies for:

  • Defender for Servers
  • Defender for Containers
  • Defender for Storage
  • Defender for Databases
  • Defender for APIs
  • Defender for AI Services
  • Defender CSPM
  • Other Defender capabilities

This is especially valuable when an organization wants to enforce security requirements consistently.

Example

An organization has 50 Azure subscriptions and wants Defender for Storage enabled consistently.

Instead of manually configuring each subscription, the organization can use an appropriate Azure Policy assignment to configure the plan at scale.


21. Azure Policy and Defender Plans

An important distinction is:

Azure Policy

can be used to enforce or deploy configurations.

Defender for Cloud

provides the security-management and workload-protection capabilities.

They work together.

For example, a policy can require that Defender for Storage be enabled.

The policy can evaluate the environment and deploy the appropriate configuration where applicable. Microsoft provides a built-in policy specifically for configuring Defender for Storage with its available capabilities.


22. Verifying Protection Coverage

Enabling a Defender plan is not the final step.

Security administrators should verify that the intended resources are actually covered.

Defender for Cloud provides a Coverage workbook that shows which plans are enabled and provides insight into coverage across subscriptions and resources.

A good operational workflow is:

Select plan

↓

Enable plan

↓

Configure plan-specific settings

↓

Deploy required components

↓

Verify coverage

↓

Review alerts/recommendations

↓

Remediate gaps


23. Why Verification Matters

Consider this scenario:

An administrator enables Defender for Servers at the subscription level.

They assume every VM is protected.

However:

  • Some resources may have different configuration.
  • Some resources may be excluded.
  • Required components may not be deployed.
  • Resource-level settings may override broader settings.
  • Multicloud resources may require appropriate onboarding.

Therefore:

Turning a Defender plan on is not the same thing as proving that every intended workload is protected.

The Coverage workbook is designed to help validate the actual deployment state.


24. Monitoring Workload Protection

Defender for Cloud provides workload protection insights and security alerts.

The Workload protections area can show the status of advanced protection for workloads such as:

  • Virtual machines
  • SQL databases
  • Containers
  • Web applications
  • Other supported workload types

Security alerts can provide:

  • Affected resource
  • Threat information
  • Suggested remediation
  • Additional investigation information
  • In some cases, automated response options

This allows security teams to move from:

Protection configuration

to:

Threat detection and response


25. Important Licensing and Cost Considerations

Many workload protection plans are paid capabilities.

Before enabling a plan broadly, an organization should understand:

  • Which workloads will be protected
  • Which features will be enabled
  • Which resources are in scope
  • Whether the plan has multiple tiers
  • Whether optional features incur additional costs
  • Expected usage
  • How long the plan will remain enabled

For example, Defender for Storage includes configurable malware-scanning capabilities, and Defender for APIs has plan selection considerations based on API traffic.

Exam strategy

If a scenario asks for the best security configuration, do not automatically choose the least expensive option.

First satisfy the security requirement.

If the question specifically introduces cost as a constraint, then cost becomes part of the decision.


26. Common SC-500 Workload Protection Scenarios

Scenario 1 — Virtual machines

Requirement: Detect vulnerabilities and protect Azure VMs.

Solution: Defender for Servers.


Scenario 2 — Kubernetes

Requirement: Detect container vulnerabilities and runtime threats in AKS.

Solution: Defender for Containers.


Scenario 3 — Malicious file uploads

Requirement: Detect malicious files uploaded to Blob Storage.

Solution: Defender for Storage with malware scanning.


Scenario 4 — Azure SQL

Requirement: Detect suspicious activity against Azure SQL databases.

Solution: Defender for Databases with Azure SQL Database protection enabled.


Scenario 5 — SQL Server on VM

Requirement: Protect SQL Server running on an Azure VM.

Solution: Configure the SQL Servers on Machines capability within Defender for Databases.


Scenario 6 — API attacks

Requirement: Discover and detect threats against APIs hosted through Azure API Management.

Solution: Defender for APIs.


Scenario 7 — AI threats

Requirement: Detect runtime threats targeting generative AI services.

Solution: Defender for AI Services.


Scenario 8 — Suspicious Azure management activity

Requirement: Detect suspicious Azure resource-management operations.

Solution: Defender for Resource Manager.


27. Common Mistakes to Avoid

Mistake 1: Confusing CSPM with workload protection

CSPM identifies posture weaknesses.

CWPP provides workload-specific protection.


Mistake 2: Enabling the wrong plan

A plan should be selected based on the workload being protected.


Mistake 3: Assuming one Defender plan protects everything

Defender for Cloud uses specialized plans for different workload categories.


Mistake 4: Assuming “On” means every feature is enabled

Some plans contain configurable components and tiers.


Mistake 5: Ignoring plan tiers

Defender for Servers has P1 and P2.

If a scenario requires a Plan 2 capability, enabling P1 is insufficient.


Mistake 6: Forgetting multicloud scope

Some Defender plans support AWS and GCP while others are Azure-only.


Mistake 7: Ignoring API traffic

Defender for APIs plan selection should take API traffic volume into account.


Mistake 8: Forgetting Storage malware scanning

Enabling Defender for Storage and enabling/configuring malware scanning are related but distinct considerations.


Mistake 9: Failing to verify coverage

Always verify that intended workloads are actually protected.


Mistake 10: Treating recommendations as runtime protection

A security recommendation identifies a security weakness.

A workload protection plan provides additional protection against threats.

They complement one another.


28. SC-500 Exam Comparison Table

RequirementThink About
Improve overall cloud security postureCSPM
Improve Secure ScoreCSPM
Identify misconfigurationsCSPM
Protect Azure VMsDefender for Servers
Protect KubernetesDefender for Containers
Detect malicious files in StorageDefender for Storage
Protect Azure SQLDefender for Databases
Protect SQL Server on machinesDefender for Databases → SQL Servers on Machines
Protect App ServiceDefender for App Service
Protect APIsDefender for APIs
Protect Key VaultDefender for Key Vault
Protect generative AI servicesDefender for AI Services
Detect suspicious Azure management activityDefender for Resource Manager
Detect DNS threatsDefender for DNS
Apply configuration consistently at scaleAzure Policy
Verify plan/resource coverageCoverage workbook

29. Recommended Deployment Method

For an enterprise environment, a strong implementation approach is:

Step 1 — Inventory workloads

Identify:

  • VMs
  • Containers
  • Storage
  • Databases
  • APIs
  • App Services
  • Key Vaults
  • AI services
  • Other cloud workloads

Step 2 — Map workloads to Defender plans

Determine which workload protection plan applies to each workload.

Step 3 — Determine scope

Decide whether protection should apply at:

  • Management group
  • Subscription
  • Resource
  • Connected multicloud environment

Step 4 — Select appropriate tiers

For plans with multiple tiers, select the tier that satisfies the security requirement.

Step 5 — Configure plan-specific features

Examples include:

  • Server vulnerability assessment
  • Server agentless scanning
  • Storage malware scanning
  • Storage sensitive-data detection
  • Container runtime protection
  • Container registry scanning
  • API plan selection
  • AI threat protection

Step 6 — Automate deployment

Use Azure Policy where appropriate to establish consistent deployment at scale.

Step 7 — Verify coverage

Use Defender for Cloud’s Coverage workbook.

Step 8 — Monitor

Review:

  • Security alerts
  • Recommendations
  • Coverage
  • Workload protection status

Step 9 — Remediate

Address identified vulnerabilities and configuration gaps.


30. Key Takeaways

For the SC-500 exam, remember these principles:

  1. Defender for Cloud combines CSPM and workload protection capabilities.
  2. CWPP plans are workload-specific.
  3. Choose the Defender plan based on the workload that needs protection.
  4. Defender for Servers has Plan 1 and Plan 2.
  5. Plan 2 provides additional advanced server protection capabilities.
  6. Defender for Storage can provide malware scanning and sensitive-data threat detection.
  7. Defender for Databases protects supported database workloads.
  8. Defender for Containers protects Kubernetes environments.
  9. Defender for APIs protects APIs managed through Azure API Management.
  10. Defender for AI Services provides specialized protection for supported AI workloads.
  11. Not every Defender plan supports AWS and GCP.
  12. Azure Policy can help deploy Defender plans consistently at scale.
  13. Enabling a plan is not the same as verifying coverage.
  14. Use the Coverage workbook to validate deployment coverage.
  15. Always distinguish posture management from active workload protection.

The central exam concept is simple:

Identify the workload → select the appropriate Defender plan → choose the required tier/features → deploy at the appropriate scope → verify coverage → monitor and remediate.


Practice Exam Questions

Question 1

An organization has several Azure virtual machines. The security team wants to detect vulnerabilities, integrate endpoint protection, and provide additional threat protection for the machines.

Which Microsoft Defender for Cloud plan should the organization enable?

A. Defender for Servers

B. Defender for Storage

C. Defender for APIs

D. Defender for Key Vault

Answer: A. Defender for Servers

Explanation: Defender for Servers is the workload protection plan designed for server and machine workloads. It provides capabilities such as vulnerability assessment and Defender for Endpoint integration. Defender for Storage protects storage accounts, Defender for APIs protects APIs, and Defender for Key Vault protects Key Vault resources.


Question 2

A security administrator needs to protect an AKS environment against container vulnerabilities and runtime threats.

Which Defender for Cloud plan should be configured?

A. Defender for App Service

B. Defender for Resource Manager

C. Defender for Servers

D. Defender for Containers

Answer: D. Defender for Containers

Explanation: Defender for Containers is designed to protect Kubernetes environments such as AKS. Depending on the configuration, it can provide vulnerability assessment, runtime threat protection, posture assessment, agentless scanning, registry assessment, and other Kubernetes security capabilities. Defender for Servers is intended primarily for machine workloads.


Question 3

A company uploads documents to Azure Blob Storage. The security team wants Defender for Cloud to identify malicious files when they are uploaded.

Which capability should be configured?

A. Defender for Storage malware scanning

B. Defender for Databases

C. Defender for Key Vault

D. Defender for APIs

Answer: A. Defender for Storage malware scanning

Explanation: Defender for Storage provides on-upload malware scanning for supported storage workloads. The capability is specifically intended to detect malicious files uploaded to storage. Defender for Key Vault, Databases, and APIs address different workload types.


Question 4

An organization enables Defender for Servers and needs a capability that is associated with Plan 2 rather than Plan 1.

Which plan should the organization select?

A. Foundational CSPM

B. Defender for Servers Plan 1

C. Defender CSPM

D. Defender for Servers Plan 2

Answer: D. Defender for Servers Plan 2

Explanation: Defender for Servers has Plan 1 and Plan 2. Plan 2 provides additional advanced capabilities, including agentless scanning. File integrity monitoring is also available as a Plan 2 capability, although it isn’t enabled by default.


Question 5

A company uses Azure API Management and wants to discover APIs, assess their security posture, prioritize API vulnerabilities, and detect active API threats.

Which Defender for Cloud plan should be used?

A. Defender for APIs

B. Defender for App Service

C. Defender for Containers

D. Defender for Resource Manager

Answer: A. Defender for APIs

Explanation: Defender for APIs provides discovery, security posture visibility, vulnerability prioritization, and runtime threat detection for APIs managed through Azure API Management. The APIs must be appropriately onboarded, and plan selection should account for API traffic requirements.


Question 6

An organization wants to apply Microsoft Defender for Cloud workload protection configurations consistently across a large number of Azure subscriptions.

Which service is most appropriate for enforcing configuration at scale?

A. Azure Bastion

B. Azure Policy

C. Azure Monitor

D. Azure DNS

Answer: B. Azure Policy

Explanation: Azure Policy can be used to enforce and deploy security configurations consistently across Azure resources and subscriptions. Microsoft provides built-in policy definitions and initiatives for configuring various Defender for Cloud plans, including Defender for Servers, Storage, Containers, APIs, AI Services, and others.


Question 7

A security engineer wants to verify which subscriptions and resources are actually covered by the Defender for Cloud plans that have been enabled.

Which capability should the engineer use?

A. Secure Score

B. Regulatory Compliance dashboard

C. Coverage workbook

D. Azure Service Health

Answer: C. Coverage workbook

Explanation: The Defender for Cloud Coverage workbook provides visibility into which Defender plans are enabled and the resulting coverage across subscriptions and resources. This is particularly important because simply enabling a plan does not necessarily mean that every intended workload has been successfully protected.


Question 8

A company is deploying a generative AI application and wants specialized Defender for Cloud protection that can identify threats targeting supported AI services.

Which plan should the security team consider?

A. Defender for DNS

B. Defender for Key Vault

C. Defender for Storage

D. Defender for AI Services

Answer: D. Defender for AI Services

Explanation: Defender for AI Services provides specialized threat protection for supported generative AI services and applications. Defender for Cloud’s AI protection capabilities can provide discovery, posture assessment, runtime threat detection, and investigation capabilities for AI workloads.


Question 9

An organization has an Azure SQL Database and wants to enable Defender for Cloud’s attack detection and threat-response capabilities for that database.

Which configuration should the administrator use?

A. Defender for Databases with Azure SQL Databases enabled

B. Defender for Servers Plan 2

C. Defender for Storage

D. Defender for Containers

Answer: A. Defender for Databases with Azure SQL Databases enabled

Explanation: Azure SQL Database protection is configured through the Defender for Databases plan. The administrator selects the Databases plan and enables the Azure SQL Databases resource type. Defender for Servers is intended for machine workloads, while Storage and Containers address different workload categories.


Question 10

An organization has connected its AWS environment to Microsoft Defender for Cloud. The security team wants to protect Windows and Linux EC2 instances against threats.

Which Defender for Cloud plan is the best fit?

A. Defender for Storage

B. Defender for Servers

C. Defender for APIs

D. Defender for AI Services

Answer: B. Defender for Servers

Explanation: Defender for Servers supports multicloud machine workloads, including supported AWS and GCP machines. AWS and GCP machines use the appropriate Defender for Cloud onboarding mechanisms, including Azure Arc for supported server scenarios. Azure-only plans such as Defender for Storage, APIs, and AI Services are not the appropriate choice for protecting EC2 machines.


Final SC-500 Exam Reminder

When you see a Defender for Cloud workload-protection question, first ask:

“What workload am I protecting?”

Then map it to the appropriate plan:

Servers → Defender for Servers

Containers/Kubernetes → Defender for Containers

Storage → Defender for Storage

Databases → Defender for Databases

App Service → Defender for App Service

APIs → Defender for APIs

Key Vault → Defender for Key Vault

AI Services → Defender for AI Services

Resource management → Defender for Resource Manager

DNS → Defender for DNS

Then determine whether the question requires a particular plan tier, feature, deployment scope, or configuration option.

Finally, remember to verify actual coverage rather than assuming that enabling the plan means the deployment is complete.

This topic is important for SC-500 because Microsoft is increasingly treating AI workloads as a first-class security workload, so I would expect questions to test not only the traditional Servers/Storage/Databases/Containers plans but also Defender for AI Services, Defender for APIs, plan-specific configuration, and coverage verification.


Go to the SC-500 Exam Prep Hub main page

Connect hybrid cloud and multicloud environments to Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Connect hybrid cloud and multicloud environments to Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Modern organizations rarely operate entirely within a single cloud provider.

An enterprise might have:

  • Azure virtual machines
  • Amazon EC2 instances
  • Google Compute Engine virtual machines
  • Amazon EKS clusters
  • Google Kubernetes Engine (GKE) clusters
  • On-premises servers
  • SQL Server databases running outside Azure
  • Applications distributed across multiple cloud platforms

Managing security independently in each environment can create visibility gaps and inconsistent security controls.

Microsoft Defender for Cloud helps address this problem by providing a centralized security platform for Azure, AWS, GCP, on-premises, and other supported environments.

For the SC-500 exam, an especially important concept is that Defender for Cloud can extend both:

  • Cloud Security Posture Management (CSPM) capabilities to multicloud environments
  • Cloud Workload Protection Platform (CWPP) capabilities to supported multicloud workloads

These two capabilities use different mechanisms.

CSPM is primarily agentless, while many CWPP scenarios use Azure Arc to connect non-Azure workloads to Azure and enable additional protection capabilities.


1. What Does “Multicloud” Mean?

A multicloud environment uses services from more than one public cloud provider.

For example:

Azure

  • Azure Virtual Machines
  • Azure SQL
  • Azure Storage
  • Azure Kubernetes Service

AWS

  • EC2
  • S3
  • RDS
  • EKS

GCP

  • Compute Engine
  • Cloud Storage
  • Cloud SQL
  • GKE

An organization may intentionally use multiple providers because of:

  • Existing investments
  • Business acquisitions
  • Application requirements
  • Geographic considerations
  • Vendor strategy
  • Specialized cloud services
  • Regulatory requirements
  • Avoidance of excessive vendor dependency

From a security perspective, however, multicloud environments introduce complexity.

Security teams need to answer questions such as:

  • What resources exist?
  • Where are they located?
  • Which resources are exposed?
  • Which resources have vulnerabilities?
  • Which security standards apply?
  • Which workloads are protected?
  • Which accounts or projects have excessive permissions?
  • Where are active threats occurring?

Defender for Cloud can provide a unified view across these environments.


2. What Does “Hybrid Cloud” Mean?

A hybrid environment combines cloud resources with infrastructure outside the public cloud.

A typical example is:

On-premises data center

↓

Azure

↓

AWS

↓

GCP

Defender for Cloud can incorporate on-premises servers by using Azure Arc-enabled servers.

An Azure Arc-enabled server becomes an Azure resource, allowing Azure services and Defender for Cloud capabilities to interact with that server.

For the SC-500 exam, remember:

Azure Arc is the key technology for extending Azure management and many Defender for Cloud workload-protection capabilities to servers outside Azure.


3. The Defender for Cloud Multicloud Model

The multicloud architecture can be viewed conceptually as:

                       Microsoft Defender for Cloud
                                  |
             +--------------------+--------------------+
             |                    |                    |
           Azure                 AWS                  GCP
             |                    |                    |
        Azure resources      AWS resources        GCP resources
             |                    |                    |
             +--------------------+--------------------+
                                  |
                           Unified security
                                  |
              +-----------------+----------------+
              |                                  |
             CSPM                               CWPP
       Posture management                  Workload protection
       Primarily agentless                Often uses Azure Arc

The key idea is that Defender for Cloud doesn’t require an organization to move its workloads into Azure.

Instead, it connects to the other environments and provides security visibility and, where supported, workload protection.


4. CSPM vs. CWPP in Multicloud Environments

This is one of the most important concepts for SC-500.

Cloud Security Posture Management

CSPM focuses on answering:

“Is my environment configured securely?”

Examples include identifying:

  • Misconfigured resources
  • Excessive exposure
  • Weak security configurations
  • Compliance issues
  • Vulnerable configurations
  • Excessive permissions
  • Security recommendations

Defender for Cloud provides CSPM capabilities for AWS and GCP after their environments are connected.

Importantly, multicloud CSPM is agentless. The CSPM assessment does not require installing agents on every AWS or GCP resource.


5. Cloud Workload Protection Platform

CWPP focuses more directly on protecting workloads from threats.

Examples include:

  • Endpoint threat detection
  • Runtime protection
  • Vulnerability assessment
  • Malware detection
  • Container runtime protection
  • Database threat detection

For multicloud environments, many of these capabilities require additional components.

For example, Defender for Servers can use:

  • Azure Arc
  • Microsoft Defender for Endpoint
  • Vulnerability assessment capabilities
  • Agentless scanning

The exact dependencies vary by Defender plan.

Exam distinction

Remember:

CapabilityPrimary purposeMulticloud approach
CSPMIdentify security posture issuesPrimarily agentless
CWPPProtect workloads against threatsOften requires Azure Arc/agents/extensions
Azure ArcConnect/manage supported non-Azure resourcesAzure management plane
Defender plansAdd workload-specific protectionDepends on workload

6. Connecting AWS to Defender for Cloud

AWS accounts can be connected directly to Defender for Cloud through a native AWS connector.

The connection creates a security relationship between Microsoft Defender for Cloud and the AWS environment.

The high-level process is:

  1. Open Microsoft Defender for Cloud.
  2. Navigate to the environment settings.
  3. Select the option to connect an AWS account.
  4. Specify the AWS account and Azure subscription information.
  5. Select the Defender plans to enable.
  6. Configure the required AWS permissions.
  7. Deploy the required AWS resources.
  8. Complete the connector configuration.
  9. Validate connector health.
  10. Review coverage.

Microsoft’s current AWS onboarding process supports configuring the connector through the Azure portal and deploying the required AWS resources using AWS CloudFormation or Terraform, depending on the configuration.


7. AWS Authentication: Federated Authentication

A critical security feature is that Defender for Cloud does not require storing long-lived AWS credentials.

Instead, Defender for Cloud uses federated authentication.

The current AWS architecture uses:

  • Microsoft-managed Microsoft Entra application
  • OpenID Connect (OIDC)
  • AWS IAM roles
  • AWS Security Token Service (STS)
  • Short-lived credentials

The CloudFormation deployment establishes the required trust relationship.

Conceptually:

Microsoft Defender for Cloud
|
| Federated authentication
v
Microsoft Entra identity
|
| OIDC / web identity federation
v
AWS IAM Role
|
| Assume role
v
AWS Security Token Service
|
| Short-lived credentials
v
AWS Resources

The important security principle is:

Defender for Cloud obtains short-lived credentials through federation instead of requiring long-lived AWS access keys to be stored.

SC-500 exam tip

If an answer says:

“Store an AWS access key and secret key in Defender for Cloud.”

that should immediately raise a red flag.

The preferred architecture uses federated trust and temporary credentials.


8. AWS IAM Permissions

The AWS connector requires appropriate permissions to discover and protect AWS resources.

The permissions depend on the Defender plans that are enabled.

For example, the CSPM connector requires permissions to discover AWS resources.

Additional permissions may be required for:

  • Defender for Servers
  • Defender for Containers
  • Other workload protection capabilities
  • Agentless scanning
  • Azure Arc autoprovisioning

Defender for Cloud creates the required roles and permissions in AWS as part of connector configuration.


9. Default Access vs. Least-Privilege Access

When configuring an AWS connector, Defender for Cloud provides options for configuring access.

Two important concepts are:

Default access

Provides the permissions required for the selected Defender capabilities and allows Defender for Cloud to incorporate future capabilities.

Least-privilege access

Grants only the permissions currently required by the selected plans.

The trade-off is important.

If new capabilities require additional permissions later, the connector may need to be updated.

Microsoft documents that changes to Defender plans or plan options can require rerunning the appropriate deployment artifact, such as the CloudFormation template or Terraform configuration.

Exam concept

If a question emphasizes:

“Grant only the minimum permissions required.”

think:

Least-privilege access.

If the question emphasizes:

“Automatically include future Defender capabilities.”

think:

Default access.


10. Connecting GCP to Defender for Cloud

GCP projects and organizations can also be connected to Defender for Cloud.

The high-level workflow is similar to AWS:

  1. Open Defender for Cloud.
  2. Navigate to Environment settings.
  3. Select the GCP connection option.
  4. Select the Azure subscription.
  5. Specify the GCP project or organization.
  6. Configure the required GCP permissions.
  7. Deploy the required GCP configuration.
  8. Complete the connector configuration.
  9. Validate connector health.
  10. Review coverage.

The current GCP connector uses federated authentication, allowing Defender for Cloud to access GCP APIs without storing long-lived credentials.


11. GCP Authentication

The GCP authentication architecture is designed to establish trust between Defender for Cloud and GCP.

The goal is similar to AWS:

Provide Defender for Cloud with the permissions required to inspect and protect resources without relying on permanently stored cloud credentials.

This is an important Zero Trust-oriented principle.

The security solution should have:

  • Appropriate identity
  • Appropriate permissions
  • Appropriate scope
  • No unnecessary long-lived secrets

12. GCP IAM Permissions

The GCP connector creates the required roles and permissions based on the selected Defender plans.

For example, Defender CSPM requires permissions that allow Defender for Cloud to:

  • Discover projects
  • Inspect organizations
  • Inspect folders
  • Review resource configurations
  • Discover resources
  • Analyze IAM-related information
  • Discover supported AI platform resources

Additional permissions may be required for workload protection plans.

Important principle

The permissions required for a GCP connector are not necessarily the same as the permissions required for an AWS connector.

Each cloud provider has its own identity and authorization model.


13. AWS vs. GCP Connector Comparison

CharacteristicAWSGCP
Connected to Defender for CloudYesYes
CSPM supportYesYes
CWPP supportYesYes
AuthenticationFederatedFederated
Long-lived cloud credentials requiredNoNo
Connector creates cloud-side security configurationYesYes
Infrastructure deploymentCloudFormation/TerraformCloud Shell/Terraform
Servers can use Azure ArcYesYes
Containers/Kubernetes supportedEKSGKE
CSPM is primarily agentlessYesYes

The exact permissions and deployment artifacts differ between AWS and GCP.


14. Azure Arc and Multicloud Servers

Azure Arc is particularly important when protecting servers outside Azure.

For example:

AWS EC2
|
| Azure Arc
v
Azure
|
v
Microsoft Defender for Cloud

and:

GCP Compute Engine
|
| Azure Arc
v
Azure
|
v
Microsoft Defender for Cloud

The Azure Arc Connected Machine agent enables the non-Azure server to participate in Azure management.

Microsoft recommends onboarding AWS and GCP machines as Azure Arc-enabled VMs to obtain the full Defender for Servers functionality.


15. Azure Arc Does Not Mean the Workload Moves to Azure

This is an important conceptual distinction.

When an AWS EC2 instance is connected through Azure Arc:

The EC2 instance remains in AWS.

When a GCP Compute Engine VM is connected through Azure Arc:

The VM remains in GCP.

Azure Arc provides a management and identity bridge.

Conceptually:

AWS EC2
|
+---- remains in AWS
|
+---- Azure Arc connection
|
v
Defender for Cloud

The same principle applies to GCP.


16. Defender for Servers on AWS and GCP

Defender for Servers can protect:

  • AWS EC2 instances
  • GCP Compute Engine VMs
  • Azure VMs
  • Azure Arc-enabled servers
  • Supported on-premises machines

When AWS or GCP machines are connected through the multicloud connector, Azure Arc can be automatically deployed as part of the connection process.

The Azure Arc agent is important because it allows Defender for Cloud to:

  • Read host-level security information
  • Deploy required extensions
  • Connect the machine to Azure
  • Extend Defender capabilities to the machine

For AWS, the AWS Systems Manager (SSM) agent is used as part of the Azure Arc autoprovisioning process.

For GCP, the OS Config agent is used for the corresponding process.


17. Defender for Containers in AWS and GCP

Defender for Containers can extend protection to:

  • Amazon EKS
  • Google GKE
  • Other supported Kubernetes environments through Azure Arc-enabled Kubernetes

The multicloud container protection architecture can include:

  • Azure Arc agent
  • Defender sensor
  • Azure Policy for Kubernetes
  • Kubernetes audit logs
  • Agentless scanning

These components have different purposes.

Defender sensor

Provides runtime threat protection.

Azure Policy for Kubernetes

Helps assess and enforce Kubernetes security configuration.

Kubernetes audit logs

Provide activity information that Defender for Cloud can use for suspicious-activity detection and investigation.

Agentless capabilities

Provide visibility into Kubernetes inventory and other security information without requiring the same sensor-based deployment model.


18. EKS and GKE

For the SC-500 exam, remember this mapping:

CloudKubernetes serviceDefender for Containers
AzureAKSYes
AWSEKSYes
GCPGKEYes

This is an easy area for scenario-based questions.

If the question describes:

“A Kubernetes cluster running in AWS”

think:

Amazon EKS → Defender for Containers

If it describes:

“A Kubernetes cluster running in GCP”

think:

GKE → Defender for Containers


19. Defender for SQL in Multicloud Environments

Defender for SQL can provide threat protection for supported SQL workloads running on AWS and GCP.

For multicloud SQL Server scenarios, Azure Arc is important.

The SQL Server can be running on:

  • AWS EC2
  • GCP Compute Engine
  • Other supported machines

The machine is connected to Azure through Azure Arc, and the appropriate Defender for SQL configuration is enabled in the Azure subscription containing the Arc-enabled machine.


20. Multicloud Dependency Model

Different Defender plans have different dependencies.

A simplified view is:

Defender capabilityAzure ArcAgent/extensionAgentless capabilities
CSPMNoNoYes
Defender for ServersYesMDE/other componentsYes
Defender for ContainersYes for sensor-based capabilitiesDefender sensor/PolicyYes
Defender for SQL on MachinesYesSQL-related componentsLimited

The exact dependencies depend on the selected features and workload.

The key exam lesson is:

Do not assume that connecting an AWS or GCP account automatically installs every Defender component required for every workload.

Different plans have different requirements.


21. On-Premises Servers

Hybrid security also includes on-premises environments.

An on-premises server can be connected to Azure using Azure Arc-enabled servers.

Once connected:

  • The server becomes an Azure resource.
  • Azure services can interact with the server.
  • Defender for Cloud can assess and protect the server when the appropriate plans are enabled.

Microsoft recommends Azure Arc onboarding for on-premises servers when full Defender for Servers functionality is desired.


22. Why Azure Arc Is Important

Azure Arc creates a common management model.

Without Arc:

Azure → Azure security model
AWS → AWS security model
GCP → GCP security model
On-premises → Local management

With Arc:

                     Azure
                       |
             Microsoft Defender for Cloud
                       |
       +---------------+---------------+
       |               |               |
    Azure            AWS             GCP
                       |               |
                    Arc               Arc
                       |               |
                    Servers           Servers

This makes it easier to apply centralized security management.


23. Connecting an AWS Account: Conceptual Process

The exact portal experience can change, but the conceptual process is important for the exam.

Step 1 — Prepare Azure

Ensure Defender for Cloud is available in the Azure subscription.

Step 2 — Prepare AWS

Ensure the AWS account can deploy the required IAM roles and resources.

Step 3 — Create the connector

Create the AWS security connector in Defender for Cloud.

Step 4 — Select Defender plans

Select the plans required for the AWS environment.

For example:

  • Defender CSPM
  • Defender for Servers
  • Defender for Containers
  • Defender for SQL

Step 5 — Configure AWS access

Choose the appropriate access model and deploy the required CloudFormation or Terraform configuration.

Step 6 — Complete federation

The AWS-side IAM roles establish the trust relationship.

Step 7 — Validate

Confirm connector health.

Step 8 — Verify coverage

Use Defender for Cloud coverage information to confirm that the expected workloads are being protected.


24. Connecting a GCP Project: Conceptual Process

The process is similar.

Step 1 — Prepare Azure

Ensure Defender for Cloud is available.

Step 2 — Prepare GCP

Ensure the required permissions are available.

Step 3 — Create the GCP connector

Create the connector in Defender for Cloud.

Step 4 — Select Defender plans

Select the appropriate protection capabilities.

Step 5 — Configure GCP access

Deploy the required GCP configuration using the supported deployment method.

Step 6 — Establish federated authentication

The connector establishes the required trust relationship.

Step 7 — Validate connector health

Confirm that Defender for Cloud can communicate with GCP.

Step 8 — Verify coverage

Confirm that the expected GCP resources are visible and protected.


25. Connector Health

Connecting an AWS account or GCP project is not the end of the implementation.

Administrators should verify:

  • Connector status
  • Authentication
  • Permissions
  • Resource discovery
  • Defender plan configuration
  • Azure Arc status where applicable
  • Agent/extension deployment where applicable
  • Security recommendations
  • Security alerts
  • Workload coverage

Both the AWS and GCP connector experiences provide mechanisms to validate connector health and review coverage.


26. Coverage Verification

A very important operational step is determining:

“What is actually protected?”

Defender for Cloud provides coverage information through workbooks, including a Coverage workbook.

This can help administrators understand:

  • Which plans are enabled
  • Which subscriptions are involved
  • Which resources are covered
  • Where protection gaps exist

The GCP connector documentation specifically identifies the Coverage workbook as a way to understand current coverage.

Exam lesson

If the question asks:

“How can an administrator verify whether multicloud resources are covered?”

look for an answer involving:

Defender for Cloud coverage information/workbooks

rather than simply checking whether the connector exists.


27. Security Connector

When AWS or GCP environments are onboarded, Defender for Cloud creates a security connector as an Azure resource.

The connector represents the relationship between the external cloud environment and Defender for Cloud.

It also serves as an important scope for access management.

For example, organizations can assign access to workload owners based on the AWS account or GCP project represented by the security connector.


28. RBAC for Multicloud Security

Azure RBAC controls access to Defender for Cloud resources and security information.

For example, users may need access to:

  • Recommendations
  • Alerts
  • Security posture
  • Connector configuration
  • Workload information

Defender for Cloud includes roles such as:

  • Owner
  • Contributor
  • Reader
  • Security Reader

The Security Reader role provides read-only access to Defender for Cloud security information such as recommendations, alerts, policies, and security states.


29. Resource Group Scope

Multicloud security connectors are Azure resources.

Therefore, Azure RBAC can be used to control access to those connectors.

Permissions assigned at the resource-group level can also be inherited for multicloud recommendations and security alerts associated with the connectors.

This is useful in large organizations where:

  • Different teams own different cloud accounts.
  • Security operations is centralized.
  • Workload owners need visibility into only their environments.

30. Cloud Account vs. Subscription vs. Project

The terminology differs by cloud.

Azure

Subscription

AWS

Account

GCP

Project

A common SC-500 scenario might say:

“Connect an AWS environment.”

Think:

AWS account → Defender for Cloud connector → Azure subscription

Or:

“Connect a GCP environment.”

Think:

GCP project/organization → Defender for Cloud connector → Azure subscription

Understanding this terminology can prevent confusion on the exam.


31. AWS Organizations and GCP Organizations

Large cloud environments may contain many AWS accounts or GCP projects.

Organizations can design their connector strategy around the scale of their environment.

The goal is to avoid creating unnecessary management complexity while maintaining appropriate isolation and access control.

For particularly large AWS environments, Microsoft recommends considering how connectors are distributed across Azure subscriptions to manage portal scale effectively.


32. CloudTrail and Cloud Logging

Multicloud security can also incorporate activity information from the source cloud.

For AWS, Defender for Cloud supports AWS CloudTrail log ingestion in supported scenarios.

For GCP, GCP Cloud Logging ingestion is available in preview for certain enhanced identity and permission insights.

This is important because:

Resource configuration tells you what exists, while activity logs can provide additional context about what happened.


33. Agentless vs. Agent-Based Security

This distinction is extremely important.

Agentless

The security service obtains information without installing an agent on the workload.

Benefits can include:

  • Lower operational overhead
  • Faster deployment
  • Broad visibility
  • No workload agent lifecycle to maintain

Multicloud CSPM is primarily agentless.

Agent-based

An agent or extension runs on or alongside the workload.

This may provide:

  • Runtime telemetry
  • Host-level information
  • Endpoint detection
  • Runtime threat detection
  • Configuration enforcement

For example, Defender for Servers can use the Azure Arc agent and Defender for Endpoint capabilities.


34. Why CSPM Doesn’t Require Azure Arc

Suppose an organization connects an AWS account to Defender for Cloud.

The security team wants only:

“Identify AWS resources with security misconfigurations.”

Azure Arc isn’t required for the core CSPM assessment.

Why?

Because CSPM can assess the AWS environment through the multicloud connector using agentless techniques.

However, if the organization wants deeper workload protection for EC2 machines, Azure Arc may become important.

Exam distinction

Posture assessment:

Connector + agentless CSPM

Full server workload protection:

Connector + Azure Arc + appropriate Defender components


35. Defender for Servers and Azure Arc

For AWS and GCP machines, Azure Arc provides the bridge needed for full Defender for Servers functionality.

The current Microsoft guidance recommends Azure Arc onboarding because it enables the broader Defender for Servers feature set.

For example:

AWS EC2
↓
AWS SSM
↓
Azure Arc
↓
Defender for Cloud
↓
Defender for Servers
↓
Security monitoring/protection

A corresponding GCP model uses the GCP OS Config agent for Azure Arc autoprovisioning.


36. Networking Requirements

Multicloud protection requires appropriate outbound network connectivity.

For example, AWS and GCP machines that are being protected through Azure Arc need access to the endpoints required by the relevant Azure Arc and Defender components.

For GCP Defender for Servers deployments, required outbound HTTPS access includes endpoints such as:

  • osconfig.googleapis.com
  • compute.googleapis.com
  • containeranalysis.googleapis.com
  • agentonboarding.defenderforservers.security.azure.com
  • gbl.his.arc.azure.com

AWS deployments require access to appropriate AWS Systems Manager endpoints and Azure Arc endpoints.

Exam lesson

If an Arc-enabled machine cannot connect to Defender for Cloud, check:

  1. Agent status
  2. IAM permissions
  3. Outbound network connectivity
  4. Required endpoints
  5. Connector health

37. Data Residency Considerations

Multicloud security introduces data residency considerations.

Organizations should understand:

  • Where security data is collected
  • Where it is processed
  • Where it is stored
  • Which agents are involved
  • Which source-cloud logging services are involved

CSPM is primarily agentless, whereas CWPP capabilities can involve agents and extensions.

For Kubernetes, for example, source-cloud logging services such as Amazon CloudWatch or GCP Cloud Logging may be involved in audit-log collection.

Therefore, organizations with strict data residency requirements should evaluate the complete architecture rather than considering only the location of the protected workload.


38. Multicloud Security and Least Privilege

A strong multicloud architecture follows least privilege.

Defender for Cloud should receive only the permissions required for the selected capabilities.

At the same time, administrators should avoid granting so little access that required security functionality cannot operate.

The balance is:

Too many permissions
↓
Unnecessary risk
Too few permissions
↓
Incomplete security visibility/protection
Appropriate permissions
↓
Required security capabilities
+
Least privilege

This is an important security-design principle and an important SC-500 exam concept.


39. Common Multicloud Security Scenario

Consider an organization with:

  • 500 Azure VMs
  • 200 AWS EC2 instances
  • 100 GCP Compute Engine VMs
  • 10 AKS clusters
  • 5 EKS clusters
  • 4 GKE clusters

The organization wants centralized security.

A reasonable architecture is:

Azure

Use Defender for Cloud directly.

AWS

Connect the AWS account and use:

  • Defender CSPM for posture management
  • Defender for Servers for EC2 protection
  • Defender for Containers for EKS

GCP

Connect the GCP project and use:

  • Defender CSPM
  • Defender for Servers
  • Defender for Containers for GKE

On-premises

Use:

  • Azure Arc-enabled servers
  • Appropriate Defender plans

This provides a unified security-management model without moving workloads between clouds.


40. Common Mistakes to Avoid

Mistake 1: Thinking Azure Arc is required for CSPM

It isn’t.

Multicloud CSPM is primarily agentless.


Mistake 2: Thinking connecting AWS automatically protects every EC2 instance

The connector provides the connection and discovery foundation.

The appropriate Defender workload protection plan and required components must also be configured.


Mistake 3: Confusing an AWS account with an Azure subscription

AWS uses accounts.

Azure uses subscriptions.

The AWS account is connected to Defender for Cloud through an Azure subscription.


Mistake 4: Confusing a GCP project with an Azure subscription

GCP uses projects.

Azure uses subscriptions.

The GCP project is connected to Defender for Cloud through an Azure subscription.


Mistake 5: Assuming long-lived AWS credentials are required

Defender for Cloud uses federated authentication and short-lived credentials for AWS.


Mistake 6: Assuming every Defender plan is multicloud

Some Defender plans are designed for Azure-specific workloads.

Always verify plan support for the cloud and workload in question.


Mistake 7: Ignoring Azure Arc

For many CWPP scenarios involving AWS/GCP servers, Azure Arc is an important dependency.


Mistake 8: Forgetting connector permissions

A connector can exist but still have insufficient permissions to perform all configured security functions.


Mistake 9: Forgetting network requirements

Agents and extensions must be able to communicate with the required services.


Mistake 10: Not verifying coverage

A healthy connector does not necessarily mean every intended workload is protected.

Always validate coverage.


41. SC-500 Decision Matrix

ScenarioPrimary consideration
Assess AWS security postureAWS connector + CSPM
Assess GCP security postureGCP connector + CSPM
Protect AWS EC2AWS connector + Defender for Servers
Protect GCP Compute EngineGCP connector + Defender for Servers
Protect AWS EKSDefender for Containers
Protect GCP GKEDefender for Containers
Protect SQL Server on AWS/GCPDefender for SQL + Azure Arc
Connect on-premises serverAzure Arc
Avoid long-lived AWS credentialsFederated authentication
Deploy AWS connectorCloudFormation or Terraform
Deploy GCP connectorCloud Shell or Terraform
Verify connector statusConnector health
Verify resource coverageCoverage workbook
Minimize cloud permissionsLeast-privilege access
Centralize multicloud securityDefender for Cloud
Runtime protection for non-Azure serverCWPP + appropriate agents/Arc

42. A Complete Multicloud Deployment Workflow

A strong enterprise implementation can follow this sequence.

Step 1 — Identify environments

Inventory:

  • Azure subscriptions
  • AWS accounts
  • GCP projects
  • On-premises servers
  • Kubernetes clusters
  • Database workloads

Step 2 — Identify security requirements

Determine whether the organization needs:

  • CSPM
  • CWPP
  • Vulnerability assessment
  • Runtime protection
  • Container security
  • SQL protection
  • Compliance assessment
  • Identity analysis

Step 3 — Establish connectors

Connect:

  • AWS accounts
  • GCP projects
  • Other supported environments

Step 4 — Configure authentication

Use federated authentication rather than long-lived cloud credentials.

Step 5 — Configure permissions

Use the minimum permissions required for the selected plans.

Step 6 — Enable Defender plans

Select appropriate workload protection plans.

Step 7 — Deploy Azure Arc where required

For supported CWPP scenarios, onboard machines or Kubernetes clusters through Azure Arc.

Step 8 — Configure agents and extensions

Deploy required:

  • Defender for Endpoint components
  • Defender sensor
  • Azure Policy for Kubernetes
  • Other required extensions

Step 9 — Verify networking

Confirm required outbound connectivity.

Step 10 — Validate connectors

Check connector health.

Step 11 — Validate coverage

Review the Coverage workbook and resource inventory.

Step 12 — Monitor

Review:

  • Recommendations
  • Alerts
  • Security posture
  • Workload protection
  • Compliance

Step 13 — Remediate

Address security findings and protection gaps.


43. SC-500 Key Concepts to Memorize

The following concepts are especially likely to be useful when answering scenario-based questions.

Concept 1

CSPM = posture management

Concept 2

CWPP = workload protection

Concept 3

CSPM for AWS/GCP = primarily agentless

Concept 4

AWS/GCP server protection = Azure Arc is important

Concept 5

AWS authentication = federated authentication + short-lived credentials

Concept 6

AWS deployment = CloudFormation or Terraform

Concept 7

GCP deployment = Cloud Shell or Terraform

Concept 8

AWS EC2 = Defender for Servers

Concept 9

GCP Compute Engine = Defender for Servers

Concept 10

AWS EKS = Defender for Containers

Concept 11

GCP GKE = Defender for Containers

Concept 12

On-premises servers = Azure Arc

Concept 13

Connector ≠ complete workload protection

Concept 14

Coverage must be verified after onboarding


44. Key Takeaways

Microsoft Defender for Cloud provides a unified security model across Azure, AWS, GCP, and hybrid environments.

The most important SC-500 concepts are:

  1. AWS accounts and GCP projects can be connected directly to Defender for Cloud.
  2. Defender for Cloud provides CSPM capabilities across AWS and GCP.
  3. Multicloud CSPM is primarily agentless.
  4. CWPP provides deeper workload protection.
  5. Azure Arc is important for many non-Azure CWPP scenarios.
  6. AWS authentication uses federated trust and short-lived credentials.
  7. GCP also uses federated authentication for its connector.
  8. AWS connector deployment can use CloudFormation or Terraform.
  9. GCP connector deployment can use Cloud Shell or Terraform.
  10. Defender for Servers can protect supported AWS EC2 and GCP Compute Engine machines.
  11. Defender for Containers can protect supported EKS and GKE environments.
  12. Different Defender plans have different dependencies.
  13. Connector permissions must be sufficient for the enabled plans.
  14. Least-privilege access reduces unnecessary permissions.
  15. Azure Arc does not move a workload into Azure.
  16. Connecting an environment does not automatically mean every workload is protected.
  17. Connector health should be validated.
  18. Coverage should be verified after onboarding.
  19. Networking requirements must be satisfied for agents and extensions.
  20. The goal is unified security management without requiring workloads to migrate to Azure.

The most useful mental model for the exam is:

Connect → Authenticate → Authorize → Assess → Protect → Verify

Or, more specifically:

AWS/GCP connector → federated identity → appropriate permissions → CSPM → Azure Arc/CWPP where required → verify coverage


Practice Exam Questions

Question 1

A company has several AWS accounts and wants Microsoft Defender for Cloud to identify security misconfigurations and assess its AWS environment. The company does not want to install agents on its AWS resources.

What should the security engineer implement?

A. Azure Arc on every AWS resource

B. Defender for Servers Plan 2 on every EC2 instance

C. An AWS connector with Defender CSPM

D. Microsoft Defender for Endpoint on every AWS resource

Answer: C. An AWS connector with Defender CSPM

Explanation: Defender for Cloud provides CSPM capabilities for AWS through the AWS connector, and multicloud CSPM is primarily agentless. Azure Arc and endpoint agents are relevant to deeper workload-protection scenarios, but they aren’t required simply to perform the core CSPM assessment.


Question 2

A security engineer needs to protect EC2 instances in an AWS account using Microsoft Defender for Servers. The organization wants to take advantage of the full Defender for Servers functionality available for its multicloud machines.

Which technology should the engineer use to onboard the machines?

A. Azure Arc-enabled servers

B. Azure Bastion

C. Azure VPN Gateway

D. Microsoft Sentinel agents

Answer: A. Azure Arc-enabled servers

Explanation: Microsoft recommends onboarding AWS and GCP machines as Azure Arc-enabled machines to take full advantage of Defender for Servers. The multicloud connector can automatically onboard the Azure Arc agent as part of the connection process.


Question 3

An organization is connecting an AWS account to Defender for Cloud. The security team has a requirement that Defender for Cloud must not store long-lived AWS access credentials.

Which authentication mechanism should be used?

A. A permanent AWS access key stored in Azure Key Vault

B. Federated authentication using OIDC and short-lived AWS credentials

C. A shared IAM user account with a permanent password

D. An Azure Storage account containing AWS credentials

Answer: B. Federated authentication using OIDC and short-lived AWS credentials

Explanation: Defender for Cloud uses federated authentication when connecting to AWS. The architecture establishes a trust relationship involving Microsoft Entra ID, OIDC, AWS IAM roles, and AWS STS so that Defender for Cloud can obtain short-lived credentials rather than relying on long-lived secrets.


Question 4

A company has deployed several workloads in Google Cloud Platform. The security team wants Defender for Cloud to discover GCP resources and assess their security posture without deploying agents to each resource.

What should the security team configure?

A. Defender for Servers on every GCP VM

B. Azure Arc on every GCP resource

C. Microsoft Defender for Endpoint on every GCP resource

D. A GCP connector with the appropriate CSPM configuration

Answer: D. A GCP connector with the appropriate CSPM configuration

Explanation: Defender for Cloud can perform CSPM for GCP through the GCP connector using primarily agentless techniques. Azure Arc and workload agents become relevant when deeper workload protection is required.


Question 5

An organization has connected an AWS account to Defender for Cloud. The security team wants to protect Amazon EKS clusters against vulnerabilities and runtime threats.

Which Defender for Cloud capability should be enabled?

A. Defender for Containers

B. Defender for Storage

C. Defender for Key Vault

D. Defender for App Service

Answer: A. Defender for Containers

Explanation: Defender for Containers provides protection for supported Kubernetes environments, including Amazon EKS. Multicloud container protection can include Azure Arc, the Defender sensor, Azure Policy for Kubernetes, audit logs, and agentless capabilities depending on the selected configuration.


Question 6

An organization is onboarding a large AWS environment to Defender for Cloud. The security team wants the connector to grant only the permissions currently required by the selected Defender plans.

Which access model should the team select?

A. Default access

B. Owner access

C. Least-privilege access

D. Contributor access

Answer: C. Least-privilege access

Explanation: Least-privilege access grants Defender for Cloud only the permissions required for the currently selected capabilities. This reduces unnecessary permissions. One trade-off is that when new Defender capabilities or permissions are required, the deployment artifact may need to be updated and redeployed.


Question 7

An organization connects a GCP project to Defender for Cloud. It wants to protect GCP Compute Engine virtual machines using Defender for Servers.

Which combination is most appropriate for obtaining the full Defender for Servers functionality?

A. GCP connector only

B. GCP connector plus Azure Arc onboarding

C. Azure Bastion plus VPN Gateway

D. Microsoft Sentinel plus Azure Firewall

Answer: B. GCP connector plus Azure Arc onboarding

Explanation: Connecting the GCP project provides the multicloud integration, while Azure Arc provides the bridge needed for full Defender for Servers functionality on supported GCP machines. Microsoft recommends Azure Arc onboarding for GCP and AWS machines protected by Defender for Servers.


Question 8

A security administrator has successfully connected an AWS account to Defender for Cloud. The connector reports as healthy, but the administrator wants to determine whether the expected AWS resources are actually covered by the enabled Defender plans.

What should the administrator do?

A. Review the Coverage workbook

B. Create a new Azure Policy initiative

C. Enable Azure Bastion

D. Review Azure Service Health

Answer: A. Review the Coverage workbook

Explanation: Connector health confirms that the connection is functioning, but coverage verification determines whether the expected resources are actually protected by the appropriate plans. Defender for Cloud provides coverage workbooks for this purpose.


Question 9

A company has SQL Server databases running on virtual machines in AWS and GCP. The security team wants to use Microsoft Defender for Cloud to provide SQL threat protection for these workloads.

Which approach is appropriate?

A. Enable Defender for Storage on the AWS and GCP accounts

B. Enable Defender for APIs on the Azure subscription

C. Use Defender for SQL with Azure Arc-enabled machines

D. Deploy Azure Firewall to both cloud environments

Answer: C. Use Defender for SQL with Azure Arc-enabled machines

Explanation: Defender for SQL supports SQL workloads running on supported AWS and GCP machines. For multicloud SQL Server scenarios, Azure Arc connects the machines to Azure, allowing Defender for Cloud to provide the required SQL protection capabilities.


Question 10

A company wants to connect its GCP environment to Defender for Cloud. The security team wants to avoid storing long-lived GCP credentials for Defender for Cloud to use when accessing GCP APIs.

Which approach is most appropriate?

A. Create a permanent GCP service-account password

B. Store a GCP private key in an Azure VM

C. Create an AWS IAM role and use it for GCP authentication

D. Use the federated authentication architecture provided by the GCP connector

Answer: D. Use the federated authentication architecture provided by the GCP connector

Explanation: The Defender for Cloud GCP connector uses federated authentication to access GCP APIs without storing long-lived credentials. This provides a more secure cross-cloud trust model while allowing Defender for Cloud to perform the required discovery and security operations.


Final SC-500 Exam Reminder

When you encounter a hybrid or multicloud Defender for Cloud question, work through these questions in order:

1. What cloud is involved?

  • Azure
  • AWS
  • GCP
  • On-premises

2. What is being requested?

  • CSPM?
  • Compliance?
  • Vulnerability assessment?
  • Server protection?
  • Container protection?
  • SQL protection?

3. Is the capability agentless?

If the question is primarily about CSPM, think:

Connector + agentless assessment

4. Does the scenario require workload protection?

If so, think:

Appropriate Defender plan + required components

5. Is Azure Arc required?

For many non-Azure server and Kubernetes CWPP scenarios:

Yes, Azure Arc is an important dependency.

6. How is authentication performed?

For AWS and GCP:

Federated authentication

Avoid answers based on permanently stored cloud credentials.

7. What scope is involved?

Remember:

Azure = Subscription

AWS = Account

GCP = Project

8. How do you know it is working?

Look for:

Connector health + resource inventory + coverage verification

The core SC-500 mental model is:

Connect → Federate → Authorize → Assess → Protect → Verify

That sequence captures much of what Microsoft is testing in this portion of the exam.

This topic is important because the current SC-500 material treats multicloud security as more than simply “connecting AWS and GCP.” The exam can test the distinction between agentless CSPM and Arc-enabled CWPP, the authentication model, cloud-specific permissions, workload-specific Defender plans, and the process of verifying that protection is actually in place.


Go to the SC-500 Exam Prep Hub main page

Enable Defender for AI Service in Cloud Workload Protection in Defender for Cloud (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for AI
      --> Enable Defender for AI Service in Cloud Workload Protection in Defender for Cloud


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Artificial intelligence workloads can introduce security risks that are different from those associated with traditional applications. Examples include unauthorized access to AI services, suspicious model usage, abuse of AI endpoints, anomalous activity, and attacks against applications that consume Azure AI services.

Microsoft Defender for AI Services is a workload protection capability in Microsoft Defender for Cloud designed to detect threats targeting Azure AI services workloads. It complements identity controls, network security, data protection, AI guardrails, and security posture management.

This topic is part of the Secure compute → Implement security for AI area of the SC-500 exam.


What Is Defender for AI Services?

Defender for AI Services provides security monitoring and threat protection for supported Azure AI services workloads. It is part of the broader Cloud Workload Protection Platform capabilities in Microsoft Defender for Cloud.

Its purpose is to help security teams:

  • Detect suspicious activity involving Azure AI services.
  • Identify potential threats targeting AI service resources.
  • Investigate security alerts in the Microsoft Defender portal.
  • Review AI security posture and coverage.
  • Combine AI workload protection with broader Defender for Cloud capabilities.
  • Correlate AI-related security information with other incidents and alerts.

Defender for AI Services is not a replacement for Microsoft Foundry guardrails, Azure AI Content Safety, Microsoft Entra ID, Azure Policy, or network controls. Instead, it adds a security monitoring and threat-detection layer to the AI workload.


AI Workload Security: Posture Versus Runtime Protection

A key exam concept is the difference between security posture management and runtime threat protection.

Cloud Security Posture Management

Cloud Security Posture Management, or CSPM, focuses on identifying and reducing configuration risks before they result in an incident.

Examples include:

  • An AI service that permits unnecessary public network access.
  • Local authentication being enabled when Microsoft Entra authentication should be used.
  • Excessive permissions assigned to an application or identity.
  • Missing security configuration or governance controls.
  • Resources that do not comply with organizational policies.

Cloud Workload Protection

Cloud Workload Protection, or CWP, focuses on detecting threats and suspicious behavior while workloads are operating.

Examples include:

  • Suspicious activity targeting an AI service.
  • Abnormal usage patterns.
  • Potential attempts to exploit an AI workload.
  • Threat indicators associated with an AI service resource.
  • Runtime activity that requires investigation.

Microsoft Defender for Cloud combines discovery, posture management, and runtime protection to provide broader visibility into AI environments.

Exam distinction

If a question asks which capability identifies a misconfiguration, think primarily of CSPM.

If it asks which capability detects a threat or suspicious activity during operation, think primarily of CWP, including Defender for AI Services.


Supported AI Workload Context

The learning material specifically associates this capability with Azure AI services workloads, including services such as:

  • Azure OpenAI-related workloads.
  • Microsoft Foundry and AI service resources.
  • AI model deployments and related service endpoints.
  • Applications that consume Azure AI services.

The exact supported resource types and detections can change as Microsoft expands the service. Therefore, organizations should verify current service coverage and supported regions before designing a production deployment.

Defender for AI Services should be considered part of a layered security architecture rather than a single control that secures every component of an AI solution.


Prerequisites

Before enabling Defender for AI Services, administrators should have:

  • An Azure subscription containing the AI workloads to protect.
  • Microsoft Defender for Cloud enabled for the subscription.
  • Appropriate permissions to configure Defender for Cloud plans.
  • Familiarity with Azure AI services and model deployments.
  • Familiarity with the Azure portal and Microsoft Defender portal.

The associated Microsoft Learn module identifies an Owner or Contributor role on the target subscription as a prerequisite for the configuration exercise. In production environments, organizations should use the least-privileged role that provides the required administrative capability.


Enable Defender for AI Services

The plan is enabled from the Defender for Cloud environment settings.

Step 1: Open Microsoft Defender for Cloud

  1. Sign in to the Azure portal.
  2. Search for and open Microsoft Defender for Cloud.
  3. Select Environment settings.

Step 2: Select the subscription

  1. Select the Azure subscription that contains the AI workloads.
  2. Review the available Defender for Cloud plans.

Defender for Cloud plans can be enabled at the subscription level. Enabling a plan at subscription scope generally applies the protection to applicable resources within that subscription.

Step 3: Enable the AI Services plan

  1. Locate the plan for Defender for AI Services.
  2. Turn the plan on.
  3. Review any available plan-specific configuration options.
  4. Select Save.

The exact portal labels and available configuration options may change as the service evolves. The important exam concept is that Defender for AI Services is enabled as a Defender for Cloud workload protection plan, rather than by installing a traditional agent on each AI service resource.


Configure Plan Components

After enabling the plan, review its available components and configuration settings.

Depending on the current service capabilities, configuration may include:

  • Selecting which AI workloads are covered.
  • Reviewing supported AI service resource types.
  • Enabling or disabling available protection components.
  • Configuring notification and monitoring integrations.
  • Reviewing the subscription’s protection status.
  • Confirming that the required security data is available.

Microsoft continuously adds capabilities to Defender for Cloud plans. Azure Policy includes a built-in initiative named Configure Microsoft Defender threat protection for AI Services to be enabled, which can help ensure that newly created or existing subscriptions remain configured according to organizational requirements.

Important distinction

The Defender for AI Services plan provides the protection capability. Azure Policy can help enforce or audit the desired configuration.

These are different functions:

CapabilityPrimary purpose
Defender for AI ServicesDetect threats targeting AI services workloads
Azure PolicyAudit or enforce resource configuration
Microsoft Defender for Cloud CSPMIdentify security posture weaknesses
Microsoft Foundry guardrailsApply controls to AI inputs, outputs, and model behavior
Microsoft Entra IDAuthenticate and authorize users, applications, and identities
Private Link and network controlsReduce network exposure

Monitor AI Security with the Data and AI Security Dashboard

After the plan is enabled, use the Data and AI security dashboard in Microsoft Defender for Cloud to review AI security information.

The dashboard is intended to provide visibility into areas such as:

  • AI resources discovered in the environment.
  • Security posture information.
  • Protection coverage.
  • Security recommendations.
  • AI-related alerts and findings.
  • Potential risks affecting AI workloads.

The dashboard helps security teams understand whether AI resources are being protected and where additional action may be required.

Recommended monitoring process

  1. Review the AI resource inventory.
  2. Confirm that expected subscriptions and resources are represented.
  3. Review recommendations and unresolved security issues.
  4. Investigate active alerts.
  5. Determine whether the issue is a configuration problem, an identity problem, a network problem, or a runtime threat.
  6. Remediate the issue.
  7. Confirm that the resource returns to the expected protection state.

Investigate AI Threat Protection Alerts

Defender for AI Services can generate security alerts when suspicious activity associated with supported AI workloads is detected.

When investigating an alert, review:

  • The affected subscription.
  • The affected AI service or resource.
  • The alert severity.
  • The detection time.
  • The activity associated with the alert.
  • The identity or application involved, when available.
  • Related resources and incidents.
  • Recommended remediation actions.

AI-related alerts can be investigated through the Microsoft Defender portal. Defender for Cloud alerts can also integrate with Microsoft Defender XDR, allowing security operations teams to correlate cloud alerts with identity, endpoint, email, and other security signals.

Example investigation workflow

A security analyst notices suspicious activity associated with an AI service.

  1. Open the alert in the Defender portal.
  2. Review the affected AI resource.
  3. Examine the evidence and activity timeline.
  4. Identify the application, identity, or network source involved.
  5. Determine whether the activity is expected.
  6. Disable or restrict a compromised identity if necessary.
  7. Rotate exposed credentials.
  8. Review network access and authentication configuration.
  9. Investigate related resources and incidents.
  10. Document the remediation and verify that the threat is no longer present.

Relationship to Other AI Security Controls

Defender for AI Services should be deployed as part of defense in depth.

Microsoft Entra ID

Use Microsoft Entra ID to control who or what can access AI services.

Recommended controls include:

  • Microsoft Entra authentication.
  • Managed identities.
  • Role-based access control.
  • Conditional Access where applicable.
  • Least-privilege permissions.
  • Removal of unnecessary credentials.

Defender for AI Services may detect suspicious activity, but it does not replace proper identity configuration.

Azure AI Content Safety and Foundry Guardrails

Guardrails help control unsafe or undesirable AI inputs and outputs. They address risks such as:

  • Harmful content.
  • Prompt-based abuse.
  • Inappropriate model responses.
  • Content filtering requirements.
  • Certain application-level AI risks.

Runtime threat protection and AI guardrails address different security concerns. A workload can have guardrails configured and still require threat monitoring.

Azure Policy

Azure Policy can audit or enforce requirements such as:

  • AI services should have local authentication disabled.
  • AI services should restrict network access.
  • Defender for AI Services should be enabled.

For example, Microsoft provides policy definitions related to disabling key-based access and restricting network access for Azure AI Services resources.

Network security

Network controls can reduce exposure by using:

  • Private endpoints.
  • Virtual network integration where supported.
  • Network access restrictions.
  • Firewall rules.
  • Private DNS configuration.
  • Restricted administrative access.

Network restrictions reduce the attack surface, while Defender for AI Services helps detect threats against the workload.

Microsoft Defender XDR

Defender XDR can provide a broader incident investigation experience by correlating AI workload alerts with other security signals.


Subscription-Level Enablement and Scale

Defender for Cloud plans are commonly configured at subscription scope. Organizations with many subscriptions should consider centralized governance.

Possible approaches include:

  • Enabling the plan on individual subscriptions.
  • Using management groups to organize subscriptions.
  • Applying Azure Policy initiatives.
  • Auditing plan coverage.
  • Reviewing coverage workbooks.
  • Establishing a standard for newly created subscriptions.

The Defender for Cloud coverage workbook helps administrators understand which plans are enabled across subscriptions and resources.

Why centralized governance matters

Without centralized governance, an organization may have:

  • AI resources deployed in subscriptions without protection.
  • Inconsistent security configurations.
  • Newly created resources that are not covered.
  • Different teams using different security standards.
  • Gaps between development, test, and production environments.

Azure Policy can help maintain consistency, but policy compliance should be verified rather than assumed.


Common Troubleshooting Issues

The plan is not visible

Possible causes include:

  • The wrong subscription or environment was selected.
  • The user lacks sufficient permissions.
  • The capability is not available in the selected region.
  • The service or plan name has changed.
  • The feature is subject to preview or availability limitations.

AI resources are not appearing in the dashboard

Check:

  • Whether the correct subscription is selected.
  • Whether the plan is enabled.
  • Whether the resource type is supported.
  • Whether the resource is in a supported region.
  • Whether sufficient time has passed for discovery and data collection.
  • Whether the resource is excluded by configuration or policy.

Alerts are not appearing

Check:

  • Whether the plan is enabled for the correct subscription.
  • Whether the activity matches a supported detection.
  • Whether the resource is covered.
  • Whether the alert is being viewed in the correct portal.
  • Whether filters are hiding the alert.
  • Whether the issue is a posture recommendation rather than a runtime alert.

A resource is secure but still has recommendations

This may occur because:

  • The recommendation has not refreshed.
  • The resource has another unresolved configuration issue.
  • A policy assignment requires a different setting.
  • The resource is evaluated against a broader security standard.
  • The recommendation applies to a different component of the workload.

Best Practices

Enable protection before production deployment

Do not wait until an AI service is compromised before enabling monitoring and threat protection.

Use least privilege

Assign only the permissions required to configure Defender for Cloud and manage AI resources.

Combine CSPM and CWP

Use CSPM to reduce misconfigurations and CWP to detect suspicious runtime activity.

Restrict network exposure

Use private endpoints and network restrictions where supported and appropriate.

Prefer Microsoft Entra authentication

Avoid unnecessary use of static keys. Use managed identities or Microsoft Entra authentication when supported.

Enforce configuration with Azure Policy

Use policy to audit or enforce requirements such as:

  • Defender for AI Services being enabled.
  • Local authentication being disabled.
  • Network access being restricted.

Monitor the Data and AI dashboard

Review coverage, recommendations, and alerts regularly.

Integrate with incident response

Ensure that AI security alerts are routed to the appropriate security operations team and correlated with other incidents.

Do not assume that one control solves every AI risk

AI security requires multiple layers, including:

  • Identity.
  • Network security.
  • Data protection.
  • Application security.
  • Guardrails.
  • Runtime threat detection.
  • Logging and monitoring.
  • Governance and compliance.

Exam-Focused Comparisons

Exam conceptCorrect interpretation
Defender for AI ServicesRuntime threat protection for supported Azure AI services workloads
AI workloads planDefender for Cloud plan used to protect AI workloads
Data and AI security dashboardView AI security posture, resources, and protection information
CSPMIdentifies configuration and posture weaknesses
CWPDetects threats and suspicious runtime activity
Azure PolicyAudits or enforces Azure resource configuration
Foundry guardrailsControls AI behavior, inputs, and outputs
Microsoft Entra IDProvides authentication and authorization
Defender XDRCorrelates and investigates security signals across workloads
Coverage workbookHelps verify Defender for Cloud plan coverage

Practice Exam Questions

Question 1

An organization uses Azure AI services for a customer-support application. The security team wants to detect suspicious activity targeting the AI service while the application is running. Which capability should the team enable?

A. Azure Policy
B. Microsoft Defender for AI Services
C. Microsoft Entra Privileged Identity Management
D. Azure Resource Manager locks

Answer: B

Explanation: Microsoft Defender for AI Services is designed to detect threats targeting supported Azure AI services workloads. Azure Policy governs configuration, PIM manages privileged access, and resource locks help prevent accidental deletion or modification.


Question 2

Where should an administrator go to enable Defender for AI Services for an Azure subscription?

A. Microsoft Foundry project settings
B. Azure Monitor Workbooks
C. Microsoft Defender portal Incidents page
D. Microsoft Defender for Cloud Environment settings

Answer: D

Explanation: Defender for Cloud workload protection plans are enabled through Microsoft Defender for Cloud → Environment settings, where the administrator selects the appropriate subscription and enables the required plan.


Question 3

A security engineer wants to identify an AI service that has an insecure configuration, such as unnecessary public network access. Which Defender for Cloud capability is most directly relevant?

A. Cloud Security Posture Management
B. Cloud Workload Protection
C. Microsoft Defender XDR incident correlation
D. Azure Bastion

Answer: A

Explanation: CSPM identifies configuration weaknesses and security posture risks. CWP focuses on runtime threats, Defender XDR supports investigation and correlation, and Azure Bastion provides secure administrative access to virtual machines.


Question 4

After enabling Defender for AI Services, which feature should an administrator use to review AI resource insights, security posture, and protection information?

A. Azure Service Health
B. Azure Advisor only
C. Data and AI security dashboard
D. Azure Cost Management

Answer: C

Explanation: The Data and AI security dashboard in Defender for Cloud provides visibility into AI resources, security posture, and related protection information.


Question 5

An organization wants to ensure that Defender for AI Services remains enabled across newly created subscriptions. Which approach is most appropriate?

A. Configure a resource lock on every AI service
B. Create a custom Microsoft Entra authentication method
C. Enable Azure Bastion
D. Use Azure Policy to audit or deploy the required Defender for AI Services configuration

Answer: D

Explanation: Azure Policy can help audit or enforce the desired Defender for Cloud plan configuration across a defined scope. Resource locks, authentication methods, and Bastion do not ensure that the Defender for AI Services plan is enabled.


Question 6

Which statement best describes the relationship between Defender for AI Services and Microsoft Foundry guardrails?

A. Defender for AI Services replaces all Foundry guardrails
B. Defender for AI Services detects workload threats, while guardrails help control AI inputs, outputs, and behavior
C. Foundry guardrails are used only to enable Azure subscriptions
D. Defender for AI Services is required only for virtual machines

Answer: B

Explanation: These controls address different risks. Defender for AI Services provides workload threat protection, while Foundry guardrails help manage AI behavior and content-related risks.


Question 7

A security analyst receives an alert involving suspicious activity against an Azure AI service. Where should the analyst investigate the alert?

A. Microsoft Defender portal
B. Azure Storage Explorer
C. Azure Resource Graph only
D. Microsoft Entra Domain Services

Answer: A

Explanation: Defender for AI Services alerts can be investigated in the Microsoft Defender portal. Defender for Cloud alerts can also integrate with Microsoft Defender XDR for broader correlation and investigation.


Question 8

Which statement about Defender for AI Services is correct?

A. It eliminates the need for identity and network controls
B. It encrypts every prompt and model response automatically
C. It provides runtime threat protection for supported Azure AI services workloads
D. It is an Azure resource lock mechanism

Answer: C

Explanation: Defender for AI Services is a workload protection capability. It does not replace authentication, authorization, encryption, network restrictions, or other defense-in-depth controls.


Question 9

An administrator enables Defender for AI Services but does not see a particular AI resource in the dashboard. What should the administrator check first?

A. Whether the resource is supported, in the correct subscription, and in a supported region
B. Whether the resource has an Azure Bastion host
C. Whether the resource has a resource lock
D. Whether the application uses a virtual machine scale set

Answer: A

Explanation: Missing resource visibility can result from unsupported resource types, incorrect subscription selection, regional availability, or discovery delays. Bastion, resource locks, and VM scale sets are not prerequisites for discovering an AI service resource.


Question 10

Which combination provides the most complete defense-in-depth approach for an Azure AI workload?

A. Resource locks and Azure Cost Management
B. Azure Bastion and storage replication
C. Azure Policy only
D. Microsoft Entra authentication, network restrictions, AI guardrails, Defender for Cloud posture management, and Defender for AI Services runtime protection

Answer: D

Explanation: AI workloads require multiple complementary controls. Identity protects access, network restrictions reduce exposure, guardrails address AI behavior, CSPM identifies configuration weaknesses, and Defender for AI Services detects runtime threats.


Key Takeaways

For the SC-500 exam, remember the following:

  1. Defender for AI Services is a Defender for Cloud workload protection capability.
  2. It focuses on detecting threats targeting supported Azure AI services workloads.
  3. Enable it through Microsoft Defender for Cloud → Environment settings.
  4. Use the Data and AI security dashboard to monitor AI security information.
  5. Investigate alerts in the Microsoft Defender portal.
  6. Use CSPM for configuration and posture risks.
  7. Use CWP for runtime threat detection.
  8. Use Azure Policy to audit or enforce plan configuration.
  9. Defender for AI Services complements—not replaces—identity, network, guardrail, and data security controls.
  10. Treat AI security as a defense-in-depth responsibility rather than a single-product task.

Go to the SC-500 Exam Prep Hub main page

Monitor AI security by using the Data and AI security dashboard in Defender for Cloud (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for AI
      --> Monitor AI security by using the Data and AI security dashboard in Defender for Cloud


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Artificial intelligence workloads introduce security risks that are different from those associated with traditional applications. AI systems may process sensitive data, use external tools, connect to storage and search services, expose model endpoints, and depend on containers, libraries, identities, and infrastructure-as-code configurations.

Microsoft Defender for Cloud provides capabilities for discovering AI workloads, assessing their security posture, detecting threats, and investigating security issues. The Data and AI security dashboard provides a centralized view of data and AI resources, their protection coverage, security recommendations, alerts, attack paths, and internet exposure.

For the SC-500 exam, the key concept is that the dashboard helps security teams answer three questions:

  1. What data and AI resources exist in the environment?
  2. What security risks or protection gaps affect those resources?
  3. What actions should be taken to reduce the risks?

The dashboard combines information from Defender for Cloud capabilities such as Cloud Security Posture Management, sensitive data discovery, Defender for Storage, Defender for Databases, and AI threat protection.


What Is the Data and AI Security Dashboard?

The Data and AI security dashboard is a centralized monitoring experience in Microsoft Defender for Cloud. It provides visibility into an organization’s data and AI estate and helps security teams identify resources that require attention.

The dashboard can display information about:

  • Storage resources
  • Managed databases
  • Hosted databases, including databases hosted on infrastructure
  • AI services and AI workloads
  • Sensitive data
  • Security recommendations
  • Security alerts
  • Attack paths
  • Internet-exposed resources
  • Protection coverage
  • AI threat detection activity

The dashboard is intended to support both proactive and reactive security activities:

  • Proactive security: Identify misconfigurations, exposed resources, missing protection, and potential attack paths.
  • Reactive security: Investigate alerts, identify affected resources, and respond to detected threats.

It is important to understand that the dashboard is not itself a replacement for all security controls. Instead, it provides a consolidated view of information collected by Defender for Cloud and related security services.


Relationship to AI Security Posture Management

Microsoft Defender for Cloud includes AI security posture management, which helps organizations discover AI workloads and identify security risks throughout the AI lifecycle.

AI security posture management can help identify:

  • AI applications and services
  • AI models and model deployments
  • Vulnerable AI-related libraries
  • Infrastructure-as-code misconfigurations
  • Internet-exposed AI endpoints
  • Weak or excessive identity permissions
  • Risks involving data used for grounding or fine-tuning
  • Potential attack paths involving AI resources

Defender for Cloud can discover AI workloads across supported environments and services, including Azure AI services, Azure AI Foundry, Azure Machine Learning, Amazon Bedrock, and Google Vertex AI.

The dashboard provides a practical way to review these findings without having to examine every AI resource independently.

AI security posture management versus AI threat protection

These capabilities address different security questions.

CapabilityPrimary purpose
AI security posture managementIdentify configuration weaknesses, vulnerabilities, exposure, and security gaps
AI threat protectionDetect suspicious or malicious activity targeting AI workloads
Data and AI security dashboardPresent data and AI inventory, posture findings, protection coverage, and threat information in one view

For example:

  • A publicly accessible AI endpoint is primarily a posture concern.
  • A suspicious sequence of prompts targeting an AI service may be a runtime threat concern.
  • The dashboard can help security personnel see both types of information together.

Prerequisites for the Dashboard

The exact information displayed depends on the Defender for Cloud plans and capabilities enabled in the subscription.

For full access to the dashboard’s data and AI capabilities, Microsoft documentation identifies the following requirements:

  • Defender CSPM
  • The Defender CSPM sensitive data discovery extension
  • Defender for Storage
  • Defender for Databases
  • AI workload threat protection
  • Registration of each relevant Azure subscription with the Microsoft.Security resource provider

Access also requires appropriate permissions to read assessments, subassessments, and alerts. The documented minimum privileged role for the dashboard is the Security reader role.

Why plan enablement matters

If a protection plan is not enabled, the dashboard may show incomplete protection coverage or may not provide certain findings.

For example:

  • Without sensitive data discovery, sensitive information findings may be unavailable.
  • Without Defender for Storage, storage threat protection information may be incomplete.
  • Without Defender for Databases, database-related protection information may be unavailable.
  • Without AI threat protection, AI prompt scanning and AI threat alerts may not be displayed.

The dashboard should therefore be interpreted in the context of the plans enabled for the subscription.


Data and AI Security Overview

The Data and AI security overview section provides a high-level view of the organization’s data and AI resources.

Resources may be categorized into areas such as:

  • Storage assets
  • Managed databases
  • Hosted databases
  • AI services

The overview can help identify whether resources are:

  • Fully protected
  • Partially protected
  • Not protected

Protection status depends on the relevant Defender for Cloud plans and extensions that apply to the resource.

The overview may also highlight resources associated with:

  • High-severity recommendations
  • Critical-severity recommendations
  • High-severity alerts
  • Critical-severity alerts
  • High- or critical-severity attack paths

This allows security teams to prioritize the most important issues instead of treating every resource equally.


The Top Issues Section

The Top issues section focuses attention on the resources and findings that require the most immediate action.

It can include:

High- and critical-severity alerts

Alerts indicate that Defender for Cloud or an integrated protection service has detected potentially malicious or suspicious activity.

Examples may include:

  • Suspicious activity involving data resources
  • Threats against AI workloads
  • Malicious or abnormal access patterns
  • Other detected security events

Alerts should be investigated to determine:

  • Which resource is affected
  • What activity was detected
  • When the activity occurred
  • Whether the activity is ongoing
  • What identities or services were involved
  • Whether containment or remediation is required

High- and critical-severity recommendations

Recommendations identify security improvements that should be made to reduce risk.

Examples include recommendations related to:

  • Internet exposure
  • Authentication
  • Identity permissions
  • Data protection
  • Missing security configurations
  • Vulnerable components
  • Protection plan coverage

A recommendation is generally a posture finding, whereas an alert is generally associated with detected activity or a security event.

High- and critical-severity attack paths

Attack path analysis helps identify combinations of weaknesses that could allow an attacker to reach a valuable resource.

An attack path may involve:

  1. An internet-exposed endpoint
  2. A weak identity or excessive permission
  3. A vulnerable workload
  4. Access to sensitive data
  5. A high-value AI or data resource

Attack paths are important because an individual issue may appear moderate when viewed in isolation but become critical when combined with other weaknesses.


The Data Closer Look Section

The Data closer look section provides more detailed information about data resources and their associated risks.

It can include the following areas.

Sensitive data discovery

Sensitive data discovery helps identify data resources that contain sensitive information.

Examples of sensitive information may include:

  • Personal information
  • Financial information
  • Credentials or secrets
  • Regulated information
  • Other information types identified by the organization

The dashboard can provide an overview of:

  • Sensitive information types
  • Sensitivity labels
  • Resources containing sensitive data
  • Resources where sensitive data may be exposed

Security teams can use this information to determine whether sensitive data is:

  • Publicly exposed
  • Accessible by inappropriate identities
  • Used by an AI workload without sufficient controls
  • Stored in a resource lacking appropriate protection

Sensitivity settings can be managed to control which information types and sensitivity labels are relevant to the organization.

Data threat protection

This area provides information about security alerts associated with data resources, including:

  • Storage resources
  • Managed databases

The purpose is to help security teams investigate threats affecting data and determine whether the associated resource requires remediation.

Data queries in Security Explorer

The dashboard can provide investigation queries for data-related risks.

Examples of investigation scenarios include:

  • Data resources containing plaintext secrets
  • Databases accessible by external users
  • Public storage containing sensitive data
  • Resources with potentially unsafe configurations

Security Explorer can be used to investigate relationships between resources, identities, configurations, and risks.

Internet-exposed data resources

The dashboard can identify data resources exposed to the internet.

These may include:

  • Public storage resources
  • Internet-accessible managed databases
  • Hosted databases with external exposure

Internet exposure does not automatically mean that a resource has been compromised. However, it increases the potential attack surface and should be evaluated alongside authentication, authorization, network controls, and data sensitivity.


The AI Closer Look Section

The AI closer look section focuses specifically on AI workloads and their security risks.

It includes several important areas.

AI discovery

AI discovery provides an inventory of AI resources found in the environment.

This visibility helps organizations identify:

  • Which AI services are deployed
  • Where AI workloads are running
  • Which teams or applications use AI
  • Which AI resources require security assessment
  • Whether unauthorized or unexpected AI resources exist

AI discovery is particularly important because organizations may have AI resources deployed by multiple teams across different subscriptions, projects, or cloud providers.

AI threat protection

AI threat protection provides information about detected threats involving AI workloads.

The dashboard can display:

  • The number of prompts scanned
  • Detected alerts
  • Alert severity
  • AI workloads associated with the alerts

Prompt scanning and AI threat detection help identify suspicious activity targeting AI services. However, the number of prompts scanned is a monitoring metric, not a security score by itself.

A high number of scanned prompts may simply indicate that an AI service is heavily used. Security teams should focus on the associated alerts, severity, affected resources, and investigation details.

AI queries in Security Explorer

The dashboard can provide queries for investigating AI-related risks.

Examples include:

  • Sensitive data resources used for grounding
  • Vulnerable containers used by AI workloads
  • AI resources with risky configurations
  • Relationships between AI endpoints and data resources
  • AI workloads with excessive exposure or permissions

These queries help security teams understand how AI resources interact with the rest of the environment.

Internet-exposed resources used for grounding

Grounding allows an AI workload to use external data to improve the relevance or accuracy of its responses.

The dashboard can identify internet-exposed storage and search resources used for grounding.

This is important because an AI application may be secure at the model endpoint while the data used to ground the model is exposed or inadequately protected.

Security teams should evaluate:

  • Whether the grounding data is sensitive
  • Whether the storage or search resource is publicly accessible
  • Whether the AI workload has excessive access
  • Whether authentication and authorization are properly configured
  • Whether the data source is trustworthy
  • Whether the resource is protected by appropriate Defender plans

Monitoring AI Protection Coverage

Protection coverage indicates whether resources are protected by the applicable security plans.

A resource may be:

Fully protected

The relevant posture and threat protection capabilities are enabled and providing coverage.

Partially protected

Some relevant capabilities are enabled, but one or more protections are missing.

Not protected

The applicable protection capabilities are not enabled or do not cover the resource.

Protection coverage should be reviewed regularly because AI environments change quickly. New AI services, model deployments, storage resources, and containers may be introduced without being included in the organization’s original security design.


How to Access and Use the Dashboard

A typical workflow is:

  1. Sign in to the Azure portal.
  2. Open Microsoft Defender for Cloud.
  3. Select Data and AI security dashboard.
  4. Review the Data and AI security overview.
  5. Review the Top issues section.
  6. Examine AI discovery and AI threat protection information.
  7. Investigate relevant recommendations, alerts, or attack paths.
  8. Use Security Explorer queries for deeper analysis.
  9. Remediate configuration issues.
  10. Reassess the dashboard to confirm that risk and protection coverage have improved.

For data-specific investigations, the dashboard can also be used to view resources containing sensitive information and then open the resource’s recommendations and alerts.


Recommended Monitoring Process

A repeatable monitoring process can be organized into five stages.

1. Establish an inventory

Identify all AI services, applications, models, endpoints, data sources, containers, and supporting infrastructure.

2. Review protection coverage

Determine whether each resource is covered by the appropriate Defender for Cloud plans.

3. Prioritize critical findings

Start with:

  • Critical alerts
  • Critical recommendations
  • Critical attack paths
  • Internet-exposed AI endpoints
  • Sensitive data used by AI workloads
  • AI resources with excessive permissions

4. Investigate relationships

Use Security Explorer and attack path analysis to understand how an issue could affect other resources.

5. Remediate and verify

Apply the recommended changes, then return to the dashboard to confirm that the issue has been resolved or that the risk has been reduced.


Common Security Actions After Reviewing the Dashboard

Depending on the findings, remediation may include:

  • Enabling the appropriate Defender for Cloud plan
  • Removing unnecessary public network access
  • Configuring private endpoints
  • Strengthening authentication
  • Applying least-privilege permissions
  • Using managed identities
  • Protecting storage and databases
  • Removing plaintext secrets
  • Updating vulnerable libraries or container images
  • Restricting access to grounding data
  • Investigating suspicious AI prompts or alerts
  • Reviewing attack paths
  • Applying security recommendations through infrastructure as code
  • Monitoring the environment continuously

The dashboard helps identify what should be addressed, but remediation usually occurs in the underlying Azure service, identity platform, network configuration, data platform, or application.


Important Exam Distinctions

Dashboard versus Security Explorer

  • The Data and AI security dashboard provides a summarized monitoring view.
  • Security Explorer provides deeper investigation and relationship analysis.

Recommendation versus alert

  • A recommendation identifies a security improvement or configuration gap.
  • An alert indicates detected suspicious or malicious activity.

Posture management versus threat protection

  • Posture management focuses on reducing weaknesses before they are exploited.
  • Threat protection focuses on detecting threats and suspicious activity.

AI discovery versus AI threat protection

  • AI discovery identifies AI resources and workloads.
  • AI threat protection detects threats targeting those workloads.

Sensitive data discovery versus data threat protection

  • Sensitive data discovery identifies resources containing sensitive information.
  • Data threat protection identifies security threats involving data resources.

Internet exposure versus compromise

An internet-exposed resource is not necessarily compromised. It is a resource with increased attack surface and potentially greater risk. An alert or investigation is needed to determine whether malicious activity occurred.


Key Takeaways

For the SC-500 exam, remember these points:

  • The Data and AI security dashboard provides a centralized view of data and AI security.
  • The dashboard combines inventory, protection coverage, recommendations, alerts, and attack paths.
  • Full functionality depends on the relevant Defender for Cloud plans and extensions.
  • AI discovery helps identify AI resources across the environment.
  • AI threat protection provides visibility into scanned prompts and detected alerts.
  • Sensitive data discovery helps identify resources containing sensitive information.
  • Security Explorer supports deeper investigation of data and AI risks.
  • Attack path analysis helps identify chains of weaknesses that could lead to high-impact compromise.
  • Internet-exposed AI and data resources should be prioritized for review.
  • The dashboard supports monitoring and prioritization; remediation is performed in the underlying services and security controls.

Practice Exam Questions

Question 1

A security team wants a centralized view of its AI resources, protection coverage, recommendations, alerts, and attack paths. Which Microsoft Defender for Cloud capability should the team use?

A. Microsoft Defender Vulnerability Management
B. Azure Resource Graph
C. Data and AI security dashboard
D. Microsoft Sentinel workbook

Correct answer: C

Explanation: The Data and AI security dashboard provides a centralized view of data and AI resources, protection status, recommendations, alerts, and attack paths. Azure Resource Graph can query resources, but it does not provide the same integrated security dashboard experience.


Question 2

An organization wants to identify storage and database resources that contain sensitive information. Which capability should be enabled?

A. Azure Bastion
B. Defender for Servers
C. Sensitive data discovery
D. Microsoft Entra Privileged Identity Management

Correct answer: C

Explanation: Sensitive data discovery identifies resources containing sensitive information types and sensitivity labels. The results can be reviewed through the Data and AI security dashboard.


Question 3

What is the primary purpose of AI security posture management in Defender for Cloud?

A. To identify AI workload risks, vulnerabilities, misconfigurations, and exposure
B. To replace Microsoft Entra authentication for AI applications
C. To train foundation models
D. To provide end-user prompt authoring assistance

Correct answer: A

Explanation: AI security posture management focuses on discovering AI workloads and identifying security weaknesses such as vulnerable components, excessive permissions, misconfigurations, and internet exposure.


Question 4

The AI closer look section reports the number of prompts scanned and displays alerts by severity. What capability is providing this information?

A. Sensitive data discovery
B. AI threat protection
C. Azure Policy
D. Defender for Containers

Correct answer: B

Explanation: AI threat protection provides information about AI-related threat detection, including prompt scanning activity and detected alerts.


Question 5

A security analyst sees a critical recommendation for an AI endpoint that is accessible from the internet. What does this finding primarily represent?

A. Proof that the endpoint has been compromised
B. A completed incident investigation
C. A posture or configuration risk requiring remediation
D. A successful model deployment

Correct answer: C

Explanation: An internet-exposed endpoint is a security posture concern. It increases the attack surface but does not, by itself, prove that a compromise has occurred.


Question 6

Which dashboard section is most directly associated with identifying sensitive information types and sensitivity labels in cloud data resources?

A. Data closer look
B. Top issues
C. AI discovery
D. AI threat protection

Correct answer: A

Explanation: The Data closer look section includes sensitive data discovery information, including sensitive information types and sensitivity labels.


Question 7

A security team wants to investigate whether sensitive data resources are being used for AI grounding. Which capability should the team use?

A. Azure Backup
B. Security Explorer queries
C. Azure Bastion
D. Microsoft Entra authentication methods

Correct answer: B

Explanation: Security Explorer provides queries for investigating relationships and risks involving AI resources, including sensitive data resources used for grounding.


Question 8

Which statement best describes an attack path in Defender for Cloud?

A. A list of all prompts sent to an AI model
B. A backup copy of an affected resource
C. A sequence of weaknesses that could allow an attacker to reach a valuable resource
D. A list of approved Azure Policy definitions

Correct answer: C

Explanation: Attack path analysis identifies connected weaknesses, such as internet exposure, excessive permissions, and vulnerable resources, that could lead to a high-impact compromise.


Question 9

A subscription has Defender CSPM enabled, but sensitive data discovery and Defender for Storage are not enabled. What is the most likely result?

A. The dashboard will automatically protect all storage resources
B. The dashboard may provide incomplete data protection and sensitive data information
C. All storage resources will be removed from the inventory
D. AI threat protection will be disabled automatically

Correct answer: B

Explanation: Dashboard information depends on the relevant plans and extensions. Without sensitive data discovery and Defender for Storage, data-related visibility and protection coverage may be incomplete.


Question 10

Which action is the best first step after identifying a critical AI security alert in the Data and AI security dashboard?

A. Delete every AI resource in the subscription
B. Ignore the alert until the next monthly review
C. Disable all network connectivity
D. Investigate the alert, affected resource, activity, and related recommendations

Correct answer: D

Explanation: A critical alert should be investigated to understand the detected activity, affected resources, identities, timing, and recommended response. Remediation should be based on the investigation rather than automatically deleting or disabling unrelated resources.


Go to the SC-500 Exam Prep Hub main page

Enable and enforce use of just-in-time (JIT) VM access (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Enable and enforce use of just-in-time (JIT) VM access


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Azure virtual machines often require inbound management access through protocols such as:

  • SSH — typically TCP port 22 for Linux VMs
  • RDP — typically TCP port 3389 for Windows VMs
  • WinRM — typically TCP ports 5985 and 5986

Leaving these ports permanently open increases the attack surface of a virtual machine. Attackers can continuously scan exposed management ports and attempt brute-force, credential-stuffing, or exploit-based attacks.

Just-in-time (JIT) VM access in Microsoft Defender for Cloud reduces this exposure by allowing inbound access to selected VM ports only when it is required, from an approved source IP address, and for a limited period.

JIT does not replace authentication, authorization, patching, or network segmentation. Instead, it adds a temporary network-access control layer around administrative access.


What Is Just-in-Time VM Access?

JIT VM access is a Microsoft Defender for Cloud capability that:

  1. Identifies VM management ports that should not remain permanently exposed.
  2. Creates or manages restrictive network rules for those ports.
  3. Requires an authorized user to request temporary access.
  4. Opens the requested ports only for the approved duration.
  5. Restricts access to the requesting IP address or specified address range.
  6. Restores the restrictive network configuration after the access window expires.

For example, an administrator may need to connect to a Linux VM using SSH. Instead of leaving port 22 open continuously, the administrator requests access for 30 minutes from their current public IP address. Defender for Cloud temporarily permits the connection and then closes the access window.

The basic security principle

Open administrative access only when needed, only to the required port, only from the required source, and only for the required duration.


Why JIT VM Access Is Important

1. Reduces the attack surface

Permanent inbound access to RDP or SSH gives attackers more opportunities to discover and target a VM. JIT minimizes the time during which these ports are reachable.

2. Reduces exposure to brute-force attacks

Because management ports remain restricted until access is requested, attackers cannot continuously attempt authentication against those ports during normal operation.

3. Supports least-privilege network access

JIT applies the principle of least privilege to network connectivity:

  • Only selected ports are opened.
  • Only selected source addresses are permitted.
  • Access is available only for a limited time.

4. Improves auditing

JIT access activity can be reviewed to determine:

  • Who requested access
  • Which VM was accessed
  • Which ports were opened
  • Which source IP address was used
  • When access was requested
  • When access expired

5. Helps enforce security standards

Organizations can use Azure Policy to identify or enforce the requirement that supported VMs use JIT access.


JIT VM Access Prerequisites

The principal prerequisite for Azure VM JIT access is:

  • Microsoft Defender for Servers Plan 2 must be enabled on the subscription.

The administrator also needs appropriate permissions to view, configure, or request JIT access.

Supported environments

JIT access supports Azure Resource Manager-based virtual machines. It can also work with supported VMs protected by Azure Firewall on the same virtual network.

Unsupported or restricted scenarios

Important limitations include:

  • Classic deployment-model VMs are not supported.
  • JIT does not support VMs protected by Azure Firewall configurations controlled by Azure Firewall Manager.
  • The Azure Firewall configuration must use the supported rules model.
  • A VM generally needs an appropriate NSG, Azure Firewall configuration, or both.
  • JIT is not a replacement for Azure Bastion, a VPN, or an identity provider.

How JIT Works with Network Security Groups

When JIT is enabled, Defender for Cloud creates or manages restrictive inbound rules for the selected ports.

For example, a VM might normally have the following inbound rule:

PrioritySourceDestination portAction
100Any3389Allow

This permanently exposes RDP to the internet.

With JIT, the selected management port is restricted until an authorized request is made. Defender for Cloud ensures that deny rules exist for the selected ports in the applicable NSG and/or Azure Firewall configuration.

When access is requested and approved, Defender for Cloud temporarily creates an allow rule for:

  • The selected port
  • The requesting source IP address or range
  • The requested duration

After the time window expires, the restrictive configuration is restored.

Important rule-processing consideration

Existing network rules can affect JIT behavior. If another rule already permits traffic to the selected port with a higher priority, that rule may take precedence over the JIT-generated rule.

Therefore, enabling JIT does not automatically correct every conflicting NSG or firewall rule. Administrators should review existing rules and ensure that permanent broad allow rules do not undermine the intended protection.


JIT Access Policy Settings

A JIT policy is configured for a VM and defines which ports can be opened temporarily.

For each protected port, the policy can specify:

  • Port number
  • Protocol
  • Allowed source IP addresses
  • Maximum request access duration

Common ports

PortProtocol or serviceTypical use
22SSHLinux administration
3389RDPWindows administration
5985WinRM over HTTPWindows remote management
5986WinRM over HTTPSSecure Windows remote management

The default recommendations commonly include ports 22, 3389, 5985, and 5986, although the actual ports should be based on the organization’s requirements. Custom ports can also be added.

Example policy

An organization might configure:

SettingValue
Port22
ProtocolTCP
Allowed sourceAdministrator’s public IP range
Maximum duration1 hour

This means the administrator cannot request unlimited access to port 22. The request must remain within the maximum duration defined by the policy.


Enabling JIT Access in the Azure Portal

JIT can be enabled from Microsoft Defender for Cloud or from the Azure virtual machine experience.

From Microsoft Defender for Cloud

  1. Open the Azure portal.
  2. Open Microsoft Defender for Cloud.
  3. Go to Workload protections.
  4. Open Just-in-time VM access.
  5. Select the Not configured virtual machines tab.
  6. Select one or more eligible VMs.
  7. Select Enable JIT on VMs.
  8. Review the recommended ports.
  9. Customize the ports, protocols, source addresses, and maximum duration.
  10. Save the policy.

From the Virtual Machines page

  1. Open Virtual machines in the Azure portal.
  2. Select the target VM.
  3. Open Configuration.
  4. Locate Just-in-time access.
  5. Select Enable just-in-time.
  6. Review or modify the default configuration.
  7. Save the settings.

For Windows VMs, the default RDP port is normally 3389. For Linux VMs, the default SSH port is normally 22. The default maximum access duration is commonly three hours, but this should be reduced when operationally practical.


Configuring JIT Access Securely

The default configuration may be functional but not sufficiently restrictive for a production environment.

Recommended configuration practices

Restrict source IP addresses

Avoid allowing access from Any unless there is a specific business requirement.

Prefer:

  • A corporate public IP range
  • A secured jump-host address
  • A VPN egress address
  • A privileged administrator workstation range

Use the shortest practical duration

If an administrator needs 20 minutes, do not configure a maximum duration of several hours without a reason.

Shorter access windows reduce exposure.

Protect only required ports

Do not enable JIT for unnecessary ports. If a VM is administered only through SSH, there may be no reason to expose RDP or WinRM.

Use custom ports carefully

Changing the port number does not provide meaningful security by itself. Nonstandard ports can reduce casual scanning noise, but they do not replace authentication, authorization, patching, or JIT.

Review existing NSG and firewall rules

Permanent allow rules can undermine the intended JIT protection. Review:

  • NSG inbound rules
  • Azure Firewall rules
  • Load balancer rules
  • Public IP exposure
  • Routing and network virtual appliance rules

Requesting JIT Access

After JIT is enabled, a user must request access before connecting to the VM.

Request process

  1. Open the Just-in-time VM access page.
  2. Select the Configured tab.
  3. Select the target VM.
  4. Select Request access.
  5. Choose the required port or ports.
  6. Specify the source IP address or range.
  7. Specify the requested access duration.
  8. Select Open ports.

The request is evaluated against the user’s permissions and the VM’s JIT policy.

After the request is approved, the user connects using the normal RDP, SSH, or other supported management method.

Requesting access from the VM Connect page

A user can also:

  1. Open the VM in the Azure portal.
  2. Select Connect.
  3. If JIT is enabled, select Request access.
  4. Specify the required access parameters.
  5. Open the ports.
  6. Connect to the VM.

For VMs protected by Azure Firewall, Defender for Cloud may provide the appropriate connection details, including the relevant port mapping.


Does JIT Automatically Approve Every Request?

JIT is not necessarily an approval workflow in the same sense as a formal access-request system.

The user must have the required Azure permissions, and the request must comply with the JIT policy. Depending on the configuration and permissions, an authorized user may be able to open the permitted ports without a separate human approval step.

Organizations requiring managerial or security approval should combine JIT with additional controls, such as:

  • Privileged Identity Management
  • Access reviews
  • Service management approval workflows
  • Conditional Access
  • Privileged access workstations
  • Ticketing and change-management processes

JIT controls temporary network exposure. It does not independently provide a complete privileged-access approval process.


Permissions for JIT Access

Different activities require different permissions.

Viewing JIT information

A user needs appropriate read permissions to view JIT policies and status.

Configuring or editing a JIT policy

A user needs permissions to modify the JIT network access policy and, in some cases, the VM configuration.

Requesting access

A user needs permissions to initiate a JIT access request and read the relevant VM and network configuration.

The principle of least privilege should be applied. A user who only needs to request access should not automatically receive permissions to modify JIT policies or change VM settings.


Enforcing JIT with Azure Policy

Enabling JIT manually on individual VMs does not scale well in a large environment.

Azure Policy can be used to identify VMs that do not comply with the organization’s JIT requirements.

Typical governance approach

  1. Define the organization’s JIT requirement.
  2. Assign an Azure Policy at the subscription or management-group scope.
  3. Evaluate VMs for compliance.
  4. Identify noncompliant VMs.
  5. Remediate or configure JIT where appropriate.
  6. Monitor compliance continuously.

The policy may be used to audit whether JIT is enabled or to support an organizational requirement that eligible VMs use JIT.

Why policy enforcement matters

Without centralized governance, administrators may:

  • Deploy a VM with RDP permanently exposed.
  • Forget to enable JIT.
  • Add a new management port without protecting it.
  • Modify network rules after JIT is configured.
  • Create inconsistent security configurations across subscriptions.

Azure Policy provides a repeatable method for identifying and managing these deviations.


JIT and Azure Bastion

JIT and Azure Bastion address related but different security concerns.

CapabilityJIT VM accessAzure Bastion
Primary purposeTemporarily opens selected management portsProvides managed RDP/SSH connectivity
VM public IP requiredMay be required depending on network designNormally not required
Browser-based connectionNot the primary featureYes
Temporary port accessYesNot the primary feature
Works with existing RDP/SSH clientsYesSupported with appropriate Bastion SKU
Reduces permanently exposed management portsYesYes, by avoiding public VM management exposure
Main controlTime-bound network accessManaged secure connectivity

A strong design may use both:

  • Azure Bastion to provide private administrative connectivity.
  • JIT to restrict management ports when direct network access is required.

JIT and Just-in-Time Privileged Identity Management

JIT VM access should not be confused with Microsoft Entra Privileged Identity Management.

JIT VM access

Controls temporary network access to VM ports.

Privileged Identity Management

Controls temporary privileged role activation.

For example:

  • PIM may temporarily activate the Virtual Machine Administrator Login role.
  • JIT may temporarily open port 3389 from the administrator’s IP address.

Using both controls provides stronger defense in depth because the user must have both:

  1. The appropriate identity and role permissions.
  2. Temporary network connectivity.

JIT and Network Security Groups

JIT does not eliminate the need for NSGs.

NSGs still provide:

  • Subnet-level filtering
  • NIC-level filtering
  • Inbound and outbound traffic control
  • Application-specific network segmentation
  • Persistent baseline security rules

JIT adds temporary management-port control on top of the existing network security design.

Example

An NSG might permanently allow application traffic:

  • TCP 443 from the internet to a web server

But administrative traffic could be controlled through JIT:

  • TCP 3389 closed by default
  • TCP 3389 opened only for an administrator’s IP
  • TCP 3389 automatically restricted after the approved period

JIT and Azure Firewall

JIT can work with supported Azure Firewall configurations.

When Azure Firewall protects a VM, JIT can temporarily modify the relevant firewall access configuration. After the access window expires, the previous restrictive configuration is restored.

Important considerations include:

  • Azure Firewall must use a supported configuration.
  • Azure Firewall Manager-controlled firewall configurations are not supported for JIT.
  • Firewall rules must be reviewed for conflicts.
  • The user may receive a translated or mapped port when connecting through the firewall.

Auditing JIT Activity

JIT activity should be reviewed regularly.

Useful information includes:

  • VM name
  • User who requested access
  • Request time
  • Requested port
  • Source IP address
  • Access duration
  • Whether access was granted
  • Last access time
  • Number of approved requests

This information can help identify:

  • Unexpected administrative activity
  • Excessively long access requests
  • Repeated requests from unusual IP addresses
  • VMs that are accessed more frequently than expected
  • Potential misuse of administrative access

JIT activity should be correlated with other security data, including:

  • Microsoft Entra sign-in logs
  • Azure Activity Log
  • NSG flow logs where available
  • Microsoft Defender for Cloud alerts
  • Microsoft Sentinel incidents
  • Privileged Identity Management activation records

Common JIT Troubleshooting Scenarios

The VM does not appear as eligible

Possible causes include:

  • Defender for Servers Plan 2 is not enabled.
  • The VM uses an unsupported deployment model.
  • The VM lacks a supported NSG or firewall configuration.
  • JIT is disabled by a security policy.
  • The VM is protected by an unsupported Azure Firewall configuration.

The user cannot request access

Check:

  • Azure RBAC permissions
  • VM read permissions
  • JIT request permissions
  • Subscription and resource-group scope
  • Whether the VM is configured for JIT
  • Whether the requested port is included in the policy

The user requested access but cannot connect

Check:

  • The request was successfully opened.
  • The correct source IP was specified.
  • The user is connecting from the same IP address used in the request.
  • The correct port and protocol are being used.
  • The VM is running.
  • The guest operating system firewall allows the traffic.
  • The NSG or Azure Firewall does not contain conflicting rules.
  • The VM service is listening on the expected port.
  • Routing and DNS are functioning correctly.

Access remains available after the expected expiration

Remember that JIT controls network rules. An already established connection may not be interrupted when the access window expires. The expiration prevents new access rather than necessarily terminating an existing session.

A permanent allow rule defeats JIT

Review NSG and firewall priorities. A broad allow rule with a higher priority may continue to permit traffic even when JIT has created a restrictive rule.


Best Practices Summary

  1. Enable Defender for Servers Plan 2 for subscriptions containing eligible VMs.
  2. Enable JIT on all supported administrative VMs.
  3. Protect only required management ports.
  4. Restrict source IP addresses whenever possible.
  5. Use the shortest practical access duration.
  6. Review NSG and Azure Firewall rules for conflicts.
  7. Combine JIT with Azure Bastion where appropriate.
  8. Combine JIT with PIM for privileged role activation.
  9. Use Azure Policy to identify noncompliant VMs.
  10. Audit JIT requests and correlate them with identity and security logs.
  11. Do not treat changing an SSH or RDP port as a substitute for JIT.
  12. Remember that JIT does not replace patching, endpoint protection, strong authentication, or least-privilege RBAC.

Key Exam Takeaways

For the SC-500 exam, remember the following:

  • JIT VM access is provided through Microsoft Defender for Cloud.
  • Microsoft Defender for Servers Plan 2 is a prerequisite for Azure VM JIT access.
  • JIT reduces exposure by restricting inbound management ports.
  • Access is requested for a specific port, source IP address, and time window.
  • Common ports include 22, 3389, 5985, and 5986.
  • JIT policies can include custom ports.
  • JIT works with supported NSG and Azure Firewall configurations.
  • Existing higher-priority allow rules can undermine JIT protection.
  • JIT can be enabled and managed through the Azure portal, PowerShell, or REST API.
  • Azure Policy can be used to enforce or audit JIT adoption.
  • JIT controls temporary network access; it does not replace RBAC, PIM, Bastion, or authentication.
  • Expiration of a JIT window does not necessarily terminate an already established connection.

Practice Exam Questions

Question 1

An organization has several Azure Windows VMs with RDP port 3389 permanently open to the internet. Security administrators want to allow RDP only when an administrator needs access and only for a limited period.

Which solution should they implement?

A. Just-in-time VM access in Microsoft Defender for Cloud
B. Azure Resource Lock
C. Azure Storage firewall rules
D. Microsoft Defender for Storage

Answer: A

Explanation: JIT VM access restricts inbound management ports and temporarily opens them only when access is requested. Resource locks protect resources from deletion or modification, while Storage firewall rules and Defender for Storage do not control RDP access to VMs.


Question 2

What is required before enabling just-in-time access for Azure virtual machines through Microsoft Defender for Cloud?

A. Microsoft Defender for Containers
B. Microsoft Defender for Servers Plan 2
C. Azure Kubernetes Service
D. Microsoft Sentinel automation rules

Answer: B

Explanation: Microsoft Defender for Servers Plan 2 must be enabled on the subscription for Azure VM JIT access.


Question 3

A Linux administrator needs SSH access to a VM for 45 minutes from a corporate public IP address. The JIT policy protects SSH port 22 and allows a maximum request duration of two hours.

Which information should the administrator provide when requesting access?

A. The VM’s operating-system password only
B. The VM’s resource lock and subscription ID
C. Port 22, the corporate source IP address, and a duration of 45 minutes
D. The Azure Storage account and container name

Answer: C

Explanation: A JIT request specifies the port, source IP address or range, and requested access duration. Authentication to the VM is still required separately.


Question 4

An organization wants to ensure that all eligible Azure VMs use JIT access. Administrators should be able to identify VMs that do not comply with the requirement.

Which service should be used?

A. Azure Policy
B. Azure DNS
C. Azure Load Balancer
D. Azure Front Door

Answer: A

Explanation: Azure Policy can audit or enforce organizational requirements and identify VMs that do not comply with JIT-related governance requirements.


Question 5

A VM has JIT enabled for RDP. However, users can still connect to port 3389 even when no JIT request is active.

What should the administrator investigate first?

A. Whether the VM has a managed identity
B. Whether the VM uses a Premium SSD
C. Whether the VM has a resource lock
D. Whether another higher-priority NSG or firewall rule permanently allows RDP

Answer: D

Explanation: Existing higher-priority allow rules can take precedence over JIT-generated restrictions. NSG and Azure Firewall rules should be reviewed for conflicting permanent access.


Question 6

Which statement best describes the relationship between JIT VM access and Azure Bastion?

A. JIT replaces the need for Azure RBAC
B. Azure Bastion is required for every JIT request
C. JIT controls temporary network access, while Bastion provides managed RDP/SSH connectivity
D. Azure Bastion permanently opens RDP and SSH ports on the VM

Answer: C

Explanation: JIT and Bastion provide different controls. JIT manages temporary access to management ports, while Bastion provides secure managed connectivity without requiring a public IP on the target VM in the normal design.


Question 7

A security engineer wants administrators to request JIT access only from approved corporate IP addresses rather than from any internet address.

Which JIT setting should be configured?

A. Allowed source IP addresses
B. VM disk encryption type
C. Azure resource lock level
D. Guest operating system image version

Answer: A

Explanation: The JIT policy allows administrators to define permitted source IP addresses or ranges for each protected port.


Question 8

A user requests JIT access to a VM protected by a supported Azure Firewall configuration. After the request is approved, Defender for Cloud provides a port mapping that differs from the VM’s internal RDP port.

Why might this occur?

A. JIT has changed the VM’s operating system
B. Azure Firewall may use a DNAT port mapping for the connection
C. The VM has been converted into an App Service
D. The VM’s managed identity has expired

Answer: B

Explanation: When Azure Firewall protects the VM, the user may need to connect using the connection details and port mapping associated with the firewall’s DNAT configuration.


Question 9

An administrator requests JIT access for 30 minutes and establishes an SSH session. The 30-minute window expires, but the existing SSH session remains connected.

Is this behavior consistent with JIT?

A. Yes. JIT expiration restricts new access but does not necessarily terminate established connections
B. No. JIT must always forcibly terminate every active session
C. No. JIT only controls outbound traffic
D. Yes, but only when the VM uses Azure Bastion

Answer: A

Explanation: JIT expiration restores the restrictive network configuration. Existing connections may remain active, so organizations should use session controls and operational procedures when immediate termination is required.


Question 10

Which approach provides the strongest defense-in-depth design for administrative access to sensitive Azure VMs?

A. Change the RDP port and leave it permanently open
B. Use JIT alone and disable all identity controls
C. Use JIT, least-privilege RBAC, strong authentication, and Azure Bastion or another secure connectivity method where appropriate
D. Use a resource lock to protect the VM from network attacks

Answer: C

Explanation: JIT should be combined with identity, authorization, authentication, network, and endpoint security controls. Changing ports does not eliminate exposure, and resource locks do not protect network access.


Go to the SC-500 Exam Prep Hub main page