CCSP Cloud Platform and Infrastructure Security Practice Question
A healthcare organization runs a critical workload on Azure virtual machines. The security team wants to ensure that the VMs are protected against rootkit and kernel-level malware that could persist across reboots. They need a solution that can detect and alert on suspicious kernel driver loads and provide file integrity monitoring. Which Azure service should they implement?
⚠ Common exam trap
The trap here is selecting Azure Sentinel or Network Watcher for endpoint-level kernel monitoring, when only Defender for Servers provides that host-based protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Defender for Servers
Azure Defender for Servers, a component of Microsoft Defender for Cloud, provides endpoint detection and response, file integrity monitoring, and kernel-level threat detection. It can identify suspicious kernel driver loads and rootkit behavior, alerting security teams. Other services like Network Watcher focus on network diagnostics, Sentinel is a SIEM, and the outdated Security Center standard tier is superseded by Defender for Servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Defender for Servers
Why this is correct
Azure Defender for Servers (part of Microsoft Defender for Cloud) provides advanced threat protection for VMs, including file integrity monitoring, detection of suspicious kernel driver loads, and behavioral analytics. It can alert on rootkits and other kernel-level anomalies. This service is designed to meet the requirement for detecting and alerting on kernel-level malware and file integrity changes.
- ✗
Azure Network Watcher
Why it's wrong here
Azure Network Watcher is a network diagnostic and monitoring service that provides tools like IP flow verify, next hop, and connection troubleshoot. It does not inspect kernel-level activity or provide file integrity monitoring. Therefore, it cannot detect rootkits or kernel driver loads, making it unsuitable for this requirement.
- ✗
Azure Sentinel
Why it's wrong here
Azure Sentinel is a cloud-native SIEM and SOAR solution that collects and analyzes security data from various sources. While it can ingest alerts from Defender for Servers, it does not natively perform kernel-level monitoring or file integrity monitoring on VMs. It requires integration with other tools to achieve that, so it is not the primary service for this need.
- ✗
Azure Security Center (standard tier)
Why it's wrong here
Azure Security Center has been rebranded as Microsoft Defender for Cloud, and the standard tier includes Defender for Servers. However, the question specifies Azure Security Center (standard tier) as a separate option, which is outdated. The current service that provides these capabilities is Azure Defender for Servers, so this option is not the best answer.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.