SC-100 · Question #40
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have an Amazon Web Services (AWS) implementation. You plan to extend the Azure security strategy to the AWS…
The correct answer is A. Azure Active Directory (Azure AD) Privileged Identity Management (PIM) B. Azure Active Directory (Azure AD) Conditional Access E. Microsoft Defender for Containers. The correct answers are A (Azure AD PIM), B (Azure AD Conditional Access), and E (Microsoft Defender for Containers). When extending Azure security to AWS without Azure Arc: Azure AD PIM manages and monitors privileged identity access regardless of the underlying cloud…
Question
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have an Amazon Web Services (AWS) implementation. You plan to extend the Azure security strategy to the AWS implementation. The solution will NOT use Azure Arc. Which three services can you use to provide security for the AWS resources? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Options
- AAzure Active Directory (Azure AD) Privileged Identity Management (PIM)
- BAzure Active Directory (Azure AD) Conditional Access
- CMicrosoft Defender for servers
- DAzure Policy
- EMicrosoft Defender for Containers
How the community answered
(56 responses)- A63% (35)
- C21% (12)
- D16% (9)
Explanation
The correct answers are A (Azure AD PIM), B (Azure AD Conditional Access), and E (Microsoft Defender for Containers). When extending Azure security to AWS without Azure Arc: Azure AD PIM manages and monitors privileged identity access regardless of the underlying cloud platform, controlling who has elevated permissions. Azure AD Conditional Access enforces identity-based access policies (MFA, compliant devices) for users accessing AWS resources via federated SSO. Microsoft Defender for Containers has native AWS integration in Microsoft Defender for Cloud that can protect Amazon EKS clusters without requiring Azure Arc. Microsoft Defender for Servers (C) requires Azure Arc to onboard non-Azure machines (VMs) for server-level protection - Arc is explicitly excluded. Azure Policy (D) enforces compliance on Azure and Arc-enabled resources only; it cannot natively govern AWS resources without Arc.
Topics
Community Discussion
No community discussion yet for this question.