Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A healthcare organization runs a critical workload on Azure virtual machines. The security team wants to ensure that the VMs are protected against rootkit and kernel-level malware that could persist across reboots. They need a solution that can detect and alert on suspicious kernel driver loads and provide file integrity monitoring. Which Azure service should they implement?

⚠ Common exam trap

The trap here is selecting Azure Sentinel or Network Watcher for endpoint-level kernel monitoring, when only Defender for Servers provides that host-based protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Defender for Servers

Azure Defender for Servers, a component of Microsoft Defender for Cloud, provides endpoint detection and response, file integrity monitoring, and kernel-level threat detection. It can identify suspicious kernel driver loads and rootkit behavior, alerting security teams. Other services like Network Watcher focus on network diagnostics, Sentinel is a SIEM, and the outdated Security Center standard tier is superseded by Defender for Servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Defender for Servers

    Why this is correct

    Azure Defender for Servers (part of Microsoft Defender for Cloud) provides advanced threat protection for VMs, including file integrity monitoring, detection of suspicious kernel driver loads, and behavioral analytics. It can alert on rootkits and other kernel-level anomalies. This service is designed to meet the requirement for detecting and alerting on kernel-level malware and file integrity changes.

  • ✗

    Azure Network Watcher

    Why it's wrong here

    Azure Network Watcher is a network diagnostic and monitoring service that provides tools like IP flow verify, next hop, and connection troubleshoot. It does not inspect kernel-level activity or provide file integrity monitoring. Therefore, it cannot detect rootkits or kernel driver loads, making it unsuitable for this requirement.

  • ✗

    Azure Sentinel

    Why it's wrong here

    Azure Sentinel is a cloud-native SIEM and SOAR solution that collects and analyzes security data from various sources. While it can ingest alerts from Defender for Servers, it does not natively perform kernel-level monitoring or file integrity monitoring on VMs. It requires integration with other tools to achieve that, so it is not the primary service for this need.

  • ✗

    Azure Security Center (standard tier)

    Why it's wrong here

    Azure Security Center has been rebranded as Microsoft Defender for Cloud, and the standard tier includes Defender for Servers. However, the question specifies Azure Security Center (standard tier) as a separate option, which is outdated. The current service that provides these capabilities is Azure Defender for Servers, so this option is not the best answer.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.