nerdexam
Microsoft

AZ-801 · Question #28

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have 50 Azure virtual machines that run Windows Server. You need to ensure that any security exploits detected on the

The correct answer is A. Vulnerability assessment for machines. To ensure security exploits detected on virtual machines are forwarded to Microsoft Defender for Cloud, you should enable a vulnerability assessment solution on the VMs. This solution, often delivered as an extension, integrates with Defender for Cloud to collect and transmit vul

Secure Windows Server on-premises and hybrid infrastructures

Question

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have 50 Azure virtual machines that run Windows Server. You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud. Which extension should you enable on the virtual machines?

Options

  • AVulnerability assessment for machines
  • BMicrosoft Dependency agent
  • CLog Analytics agent for Azure VMs
  • DGuest Configuration agent

How the community answered

(51 responses)
  • A
    84% (43)
  • B
    8% (4)
  • C
    6% (3)
  • D
    2% (1)

Why each option

To ensure security exploits detected on virtual machines are forwarded to Microsoft Defender for Cloud, you should enable a vulnerability assessment solution on the VMs. This solution, often delivered as an extension, integrates with Defender for Cloud to collect and transmit vulnerability and exploit findings.

AVulnerability assessment for machinesCorrect

Microsoft Defender for Cloud integrates with vulnerability assessment solutions, such as Microsoft Defender for Endpoint's threat and vulnerability management (TVM), to discover, assess, and prioritize vulnerabilities and exploits on virtual machines. Enabling 'Vulnerability assessment for machines' (which might deploy a relevant agent or integrate with existing security tools) is the mechanism that allows Defender for Cloud to collect and display detected security exploits, thereby fulfilling the requirement.

BMicrosoft Dependency agent

The Microsoft Dependency agent is used by Azure Monitor's Service Map feature to discover application components and dependencies on virtual machines, not for forwarding security exploit detections.

CLog Analytics agent for Azure VMs

The Log Analytics agent for Azure VMs primarily collects performance metrics, event logs, and custom logs for Azure Monitor, and while it's a prerequisite for some Defender for Cloud features, it doesn't directly forward security exploit findings itself.

DGuest Configuration agent

The Guest Configuration agent, part of Azure Policy, is used for auditing and configuring operating system settings within virtual machines against predefined baselines, but it does not forward security exploit detections to Defender for Cloud.

Concept tested: Defender for Cloud vulnerability assessment integration

Source: learn.microsoft.com/azure/defender-for-cloud/enable-vulnerability-assessment-defender-vms

Topics

#Azure Defender for Cloud#Vulnerability Assessment#Azure Virtual Machines#Security Monitoring

Community Discussion

No community discussion yet for this question.

Full AZ-801 Practice