nerdexam
Microsoft

SC-100 · Question #139

You are a security analyst for an organization. Your company recently initiated a cloud adoption strategy and concerns related to threat detection in Azure Container Registry for their Linux images. W

The correct answer is A. Microsoft Defender for Cloud D. Log Analytics Workspace. Option A is correct because once you Enable Microsoft Defender for Containers, Microsoft Defender for Cloud will automatically scan all Linux images pushed to the registry. Option B is incorrect because Twistlock Enterprise Edition is a security suite for protecting container pla

Design security operations, identity, and compliance capabilities

Question

You are a security analyst for an organization. Your company recently initiated a cloud adoption strategy and concerns related to threat detection in Azure Container Registry for their Linux images. Which two Microsoft cloud-native solutions can integrate with Azure Container Registry to automatically scan all Linux images pushed to a registry? (Select TWO)

Options

  • AMicrosoft Defender for Cloud
  • BTwistlock Enterprise Edition
  • CAzure Logic Apps
  • DLog Analytics Workspace

How the community answered

(18 responses)
  • A
    83% (15)
  • B
    6% (1)
  • C
    11% (2)

Explanation

Option A is correct because once you Enable Microsoft Defender for Containers, Microsoft Defender for Cloud will automatically scan all Linux images pushed to the registry. Option B is incorrect because Twistlock Enterprise Edition is a security suite for protecting container platforms like Docker and Kubernetes but is not native to Azure. Option C is incorrect because Azure Logic Apps, Will enable organizations to create workflows by integrating various Azure services, including Azure Container Registry, but it would not provide the security scanning of images pushed to the registry Option D is correct because Defender for Cloud gathers data from your Azure virtual machines (VMs), Virtual machine scale sets, IaaS containers, and non-Azure computers (including on- premises machines) to examine for security vulnerabilities and threats. Data is compiled using the Log Analytics agent, which reads various security-related patterns and event logs from the machine and copies the data to your Log Analytics Workspace for analysis. You need a Log Analytics Workspace to enable Microsoft Defender for the cloud. https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction

Topics

#Container Security#Azure Container Registry#Microsoft Defender for Cloud#Vulnerability Scanning

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice