A company uses Azure virtual machines (IaaS) and on-premises Windows servers. The security team needs a single solution that provides a continuous assessment of security posture, a regulatory compliance dashboard for NIST SP 800-53, and integrated threat detection for hybrid workloads (e.g., brute force attacks on SSH). Which Microsoft security solution should they use?
Defender for Cloud offers unified CSPM and threat protection for hybrid environments, including a regulatory compliance dashboard with built-in standards like NIST SP 800-53.
Why this answer
Microsoft Defender for Cloud is the correct choice because it provides continuous assessment of security posture (via the Secure Score), a regulatory compliance dashboard with built-in standards like NIST SP 800-53, and integrated threat detection for hybrid workloads, including brute force attacks on SSH for Azure VMs and on-premises servers. It unifies these capabilities across IaaS, on-premises, and other cloud environments, making it the single solution the security team needs.
Exam trap
The trap here is that candidates often confuse Microsoft Defender for Cloud (which covers infrastructure security posture and threat detection for workloads) with Microsoft Sentinel (a SIEM), but Sentinel requires manual configuration of data connectors and workbooks to achieve the same compliance dashboard and does not provide continuous posture assessment out of the box.
How to eliminate wrong answers
Option B (Microsoft Defender for Cloud Apps) is wrong because it is a Cloud Access Security Broker (CASB) focused on shadow IT discovery, app permissions, and data protection for SaaS applications, not on infrastructure-level security posture or compliance dashboards for NIST SP 800-53. Option C (Microsoft Defender for Identity) is wrong because it is an identity-based threat detection solution that monitors on-premises Active Directory signals (e.g., Kerberos, NTLM) for attacks like pass-the-hash, not for brute force attacks on SSH or VM-level security posture. Option D (Microsoft Sentinel) is wrong because it is a Security Information and Event Management (SIEM) solution that ingests logs from multiple sources for advanced analytics and incident response, but it does not natively provide a continuous security posture assessment or a built-in regulatory compliance dashboard for NIST SP 800-53 without additional workbooks and configurations.