nerdexam
Microsoft

SC-100 · Question #31

Your company finalizes the adoption of Azure and is implementing Microsoft Defender for Cloud. You receive the following recommendations in Defender for Cloud: - Access to storage accounts with…

The correct answer is D. Azure Policy. Azure Policy is the correct recommendation because it can enforce and automatically remediate the exact network access configurations described in the Defender for Cloud recommendations (firewall rules, VNet rules, private link, disallowing public access). Azure Policy can be…

Design security operations, identity, and compliance capabilities

Question

Your company finalizes the adoption of Azure and is implementing Microsoft Defender for Cloud. You receive the following recommendations in Defender for Cloud:

  • Access to storage accounts with firewall and virtual network

configurations should be restricted

  • Storage accounts should restrict network access using virtual network

rules.

  • Storage account should use a private link connection.
  • Storage account public access should be disallowed.

You need to recommend a service to mitigate identified risks that relate to the recommendations. What should you recommend?

Options

  • AAzure Storage Analytics
  • BAzure Network Watcher
  • CMicrosoft Sentinel
  • DAzure Policy

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    13% (4)
  • D
    78% (25)

Explanation

Azure Policy is the correct recommendation because it can enforce and automatically remediate the exact network access configurations described in the Defender for Cloud recommendations (firewall rules, VNet rules, private link, disallowing public access). Azure Policy can be assigned with 'deny' or 'deployIfNotExists' effects to prevent misconfigured storage accounts from being created and to auto-remediate existing ones. Azure Storage Analytics (A) provides logging and metrics but does not enforce configurations. Azure Network Watcher (B) is a network diagnostics and monitoring tool, not a policy enforcement tool. Microsoft Sentinel (C) is a SIEM/SOAR used for threat detection and response, not configuration enforcement.

Topics

#Azure Policy#Microsoft Defender for Cloud#Storage Account Security#Compliance

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice