SC-200 · Question #275
You have an Azure subscription that uses Microsoft Defender for Cloud. You need to configure Defender for Cloud to mitigate the following risks: - Vulnerabilities within the application source code…
The correct answer is A. Microsoft Defender for Resource Manager E. Microsoft Defender for DevOps. To mitigate risks related to application source code vulnerabilities, exploitation toolkits in templates, malicious IP operations, and exposed secrets, Microsoft Defender for DevOps and Microsoft Defender for Resource Manager are the appropriate services.
Question
You have an Azure subscription that uses Microsoft Defender for Cloud. You need to configure Defender for Cloud to mitigate the following risks:
- Vulnerabilities within the application source code
- Exploitation toolkits in declarative templates
- Operations from malicious IP addresses
- Exposed secrets
Which two Defender for Cloud services should you use? Each correct answer presents part of the solution. NOTE: Each correct answer is worth one point.
Options
- AMicrosoft Defender for Resource Manager
- BMicrosoft Defender for DNS
- CMicrosoft Defender for App Service
- DMicrosoft Defender for Servers
- EMicrosoft Defender for DevOps
How the community answered
(36 responses)- A83% (30)
- B6% (2)
- C3% (1)
- D8% (3)
Why each option
To mitigate risks related to application source code vulnerabilities, exploitation toolkits in templates, malicious IP operations, and exposed secrets, Microsoft Defender for DevOps and Microsoft Defender for Resource Manager are the appropriate services.
Microsoft Defender for Resource Manager protects against management plane attacks targeting Azure resources, including detecting operations from malicious IP addresses and identifying exploitation toolkits in declarative templates during deployment.
Microsoft Defender for DNS provides threat protection for DNS queries, detecting suspicious activity at the DNS layer, which is not directly related to source code vulnerabilities or exploitation toolkits in templates.
Microsoft Defender for App Service protects web applications and APIs running on App Service, focusing on runtime threats rather than source code or template vulnerabilities in the DevOps pipeline.
Microsoft Defender for Servers provides threat protection for virtual machines and physical servers, which is not directly relevant to vulnerabilities in application source code or declarative templates.
Microsoft Defender for DevOps provides security for the DevOps lifecycle, enabling the scanning of application source code for vulnerabilities and identifying exposed secrets within code repositories and build pipelines.
Concept tested: Defender for Cloud capabilities for DevOps and Resource Manager
Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-devops-introduction
Topics
Community Discussion
No community discussion yet for this question.