A cloud team is describing cloud security posture management (CSPM) as delivered by Microsoft Defender for Cloud. Which TWO outcomes does CSPM in Defender for Cloud provide? Select TWO.
- AContinuous assessment of resources against security standards to surface misconfigurations. Correct
- BReal-time intrusion detection and prevention on east-west traffic between Azure subnets.
- CCross-product investigation of correlated email, endpoint, and identity alerts in one queue.
- DPrioritised hardening recommendations that raise the environment's secure score when applied. Correct
- ELong-term log retention and KQL hunting across ingested security data sources.
Why A is correct: CSPM continuously evaluates resources against standards and flags misconfigurations that weaken posture.
Why B is wrong: Signature-based IDPS on traffic is an Azure Firewall Premium feature, not part of posture management.
Why C is wrong: Correlating cross-workload alerts into incidents is Defender XDR, separate from posture assessment.
Why D is correct: CSPM produces recommendations that improve posture, and acting on them increases the secure score.
Why E is wrong: Large-scale log retention and hunting is Microsoft Sentinel, the SIEM, not the CSPM capability of Defender for Cloud.