AZ-900 · Question #146
Hotspot Question You plan to implement several security services for an Azure environment. You need to identify which Azure services must be used to meet the following security requirements: - Monitor
The question tests knowledge of specific Azure security services: Azure Advanced Threat Protection for sensor-based threat monitoring and Azure AD Identity Protection for conditional MFA enforcement.
Question
Exhibit
Answer Area
- Monitor threats by using sensors:Azure MonitorAzure Security CenterAzure Active Directory (Azure AD) Identity ProtectionAzure Advanced Threat Protection (ATP)
- Enforce Azure MFA based on a condition:Azure MonitorAzure Security CenterAzure Active Directory (Azure AD) Identity ProtectionAzure Advanced Threat Protection (ATP)
Explanation
The question tests knowledge of specific Azure security services: Azure Advanced Threat Protection for sensor-based threat monitoring and Azure AD Identity Protection for conditional MFA enforcement.
Approach. To correctly answer this question, the test-taker must select the appropriate Azure service from each dropdown based on its primary function:
-
For 'Monitor threats by using sensors:': The correct selection is Azure Advanced Threat Protection (ATP) (now part of Microsoft Defender for Identity and Microsoft Defender for Endpoint). Azure ATP (specifically Microsoft Defender for Identity) leverages sensors deployed on domain controllers to monitor traffic and identify suspicious user and entity behavior within the on-premises network and cloud identities. Microsoft Defender for Endpoint also uses endpoint sensors. The phrase 'using sensors' is a key indicator for this service's functionality in detecting advanced threats.
-
For 'Enforce Azure MFA based on a condition:': The correct selection is Azure Active Directory (Azure AD) Identity Protection. This service specializes in detecting identity-based risks (e.g., impossible travel, anonymous IP sign-ins, leaked credentials) and automatically enforces risk-based policies, which can include requiring Azure Multi-Factor Authentication (MFA), blocking access, or forcing a password change, all based on the detected conditions or risk levels. This directly aligns with 'enforce Azure MFA based on a condition'.
Common mistakes.
- common_mistake. Common mistakes stem from misunderstanding the specific capabilities of each Azure security service:
- Azure Monitor: While a powerful monitoring service, it's primarily for collecting, analyzing, and acting on telemetry data (logs, metrics). It doesn't specifically deploy 'sensors' for advanced threat detection in the same way ATP does for identity or endpoint threats. It's a platform for data, not the specific threat detection engine using sensors.
- Azure Security Center (now Microsoft Defender for Cloud): This is a comprehensive platform for security posture management and threat protection across hybrid environments. It integrates with services like ATP and Identity Protection and presents their findings, but it is not the service that directly performs the 'monitoring threats by using sensors' or 'enforces conditional MFA' itself. It's an orchestrator and dashboard for these underlying capabilities.
- Azure Active Directory (Azure AD) Identity Protection (incorrect for 'Monitor threats by using sensors'): Identity Protection focuses on identity risks (user behavior, compromised credentials), not the broader 'threats by using sensors' typically associated with endpoint or domain controller monitoring for advanced persistent threats.
- Azure Advanced Threat Protection (ATP) (incorrect for 'Enforce Azure MFA based on a condition'): ATP (Microsoft Defender for Identity/Endpoint) is focused on detecting advanced attacks on identity systems or endpoints. It does not directly manage or enforce MFA policies based on conditions; that functionality belongs to Azure AD Identity Protection and Conditional Access policies.
Concept tested. The core concept being tested is the understanding of the specialized functions of various Azure security services, specifically their roles in threat detection and identity protection, including sensor-based monitoring and conditional access for Multi-Factor Authentication (MFA). It assesses the ability to differentiate between services like Azure Monitor, Azure Security Center, Azure AD Identity Protection, and Azure Advanced Threat Protection based on specific use cases.
Reference. null
Topics
Community Discussion
No community discussion yet for this question.
