nerdexam
Microsoft

SC-100 · Question #325

Drag and Drop Question You have an Azure environment that contains multiple workloads deployed across multiple subscriptions. You need to recommend a solution to assess and improve the security…

The correct answer is Microsoft Defender for Cloud; Microsoft Defender Vulnerability. This question assesses the ability to identify appropriate Azure services and frameworks for improving security posture and evaluating compliance, specifically aligning with the Microsoft Cloud Adoption Framework and Azure Well-Architected Framework.

Design security operations, identity, and compliance capabilities

Question

Drag and Drop Question You have an Azure environment that contains multiple workloads deployed across multiple subscriptions. You need to recommend a solution to assess and improve the security posture of the workloads. The solution must meet the following requirements: - Use the Microsoft Cloud Adoption Framework for Azure to evaluate compliance with cloud governance policies. - Use the Azure Well-Architected Framework to secure individual workloads. What should you include in the recommendation for each requirement? To answer, drag the appropriate recommendations to the correct requirements. Each recommendation may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibits

SC-100 question #325 exhibit 1
SC-100 question #325 exhibit 2

Answer Area

Drag items

Azure AdvisorMicrosoft cloud security benchmark (MCSB)Microsoft Defender for CloudMicrosoft Defender VulnerabilityMicrosoft IntuneMicrosoft Sentinel

Correct arrangement

  • Microsoft Defender for Cloud
  • Microsoft Defender Vulnerability

Explanation

This question assesses the ability to identify appropriate Azure services and frameworks for improving security posture and evaluating compliance, specifically aligning with the Microsoft Cloud Adoption Framework and Azure Well-Architected Framework.

Approach. For the first requirement, 'Use the Microsoft Cloud Adoption Framework for Azure to evaluate compliance with cloud governance policies:', the correct recommendation is 'Microsoft Defender for Cloud'. The Microsoft Cloud Adoption Framework's Governance pillar emphasizes establishing and monitoring policies. Microsoft Defender for Cloud is the primary Azure service that provides security posture management, including regulatory compliance dashboards that assess against benchmarks (like MCSB) and custom policies, directly helping to evaluate compliance with cloud governance policies.

For the second requirement, 'Use the Azure Well-Architected Framework to secure individual workloads:', the correct recommendation is 'Azure Advisor'. The Azure Well-Architected Framework (WAF) includes a Security pillar focused on securing workloads. Azure Advisor provides personalized recommendations across all WAF pillars, including security, to optimize Azure deployments. It actively helps identify and suggest improvements for individual workloads based on best practices aligned with WAF principles.

Common mistakes.

  • common_mistake. 1. Dragging 'Microsoft cloud security benchmark (MCSB)' to the first requirement: While MCSB is fundamental to evaluating compliance, it is a benchmark or a standard, not the active service or tool that performs the evaluation. Microsoft Defender for Cloud is the service that utilizes MCSB to perform compliance assessments.
  1. Dragging 'Microsoft Defender Vulnerability' to the second requirement: This is a specific feature within Microsoft Defender for Cloud used for vulnerability assessment. While it contributes to securing individual workloads, Azure Advisor is a broader service explicitly designed to provide recommendations across all pillars of the Azure Well-Architected Framework, making it a more direct and comprehensive fit for securing workloads according to WAF principles.
  2. Swapping 'Microsoft Defender for Cloud' and 'Azure Advisor': Azure Advisor focuses on WAF recommendations, but it doesn't offer the comprehensive compliance evaluation against governance policies that Defender for Cloud provides. Conversely, while Defender for Cloud secures individual workloads, Advisor is explicitly built to align with WAF recommendations, making it a better fit for that specific requirement.

Concept tested. The underlying technical concept being tested is the understanding of key Azure security and governance services and their alignment with Microsoft's foundational frameworks: the Cloud Adoption Framework (CAF) and the Well-Architected Framework (WAF). Specifically, it assesses knowledge of how Microsoft Defender for Cloud is used for security posture management and compliance, and how Azure Advisor provides recommendations aligned with WAF principles.

Topics

#Cloud Adoption Framework (CAF)#Azure Well-Architected Framework (WAF)#Azure Governance#Security Posture Management

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice