SC-900 - Microsoft Security Solutions (38% of the exam) - Section 3.2

Describe the security management capabilities of Azure.

Describe Microsoft Defender for Cloud as the service that provides cloud security posture management alongside cloud workload protection for Azure and hybrid environments. Apply its security policies and prioritise recommendations to improve your secure score and harden workloads against known attack patterns.

Microsoft Defender for Cloudcloud security posture managementsecurity policies and recommendationscloud workload protection

Practice question for this objective

Free sampleMicrosoft Security Solutionsmedium

A cloud team is describing cloud security posture management (CSPM) as delivered by Microsoft Defender for Cloud. Which TWO outcomes does CSPM in Defender for Cloud provide? Select TWO.

  • AContinuous assessment of resources against security standards to surface misconfigurations. Correct
  • BReal-time intrusion detection and prevention on east-west traffic between Azure subnets.
  • CCross-product investigation of correlated email, endpoint, and identity alerts in one queue.
  • DPrioritised hardening recommendations that raise the environment's secure score when applied. Correct
  • ELong-term log retention and KQL hunting across ingested security data sources.
Cloud security posture management in Defender for Cloud continuously assesses resources for misconfigurations and issues prioritised recommendations that improve the secure score. CSPM is the assess-and-recommend side of Defender for Cloud: it evaluates resources against standards, reports misconfigurations, and offers fixes that raise secure score. Traffic IDPS, cross-workload incident correlation, and log hunting belong to Firewall, Defender XDR and Sentinel.

Why A is correct: CSPM continuously evaluates resources against standards and flags misconfigurations that weaken posture.

Why B is wrong: Signature-based IDPS on traffic is an Azure Firewall Premium feature, not part of posture management.

Why C is wrong: Correlating cross-workload alerts into incidents is Defender XDR, separate from posture assessment.

Why D is correct: CSPM produces recommendations that improve posture, and acting on them increases the secure score.

Why E is wrong: Large-scale log retention and hunting is Microsoft Sentinel, the SIEM, not the CSPM capability of Defender for Cloud.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Security Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • Microsoft Sentinel, the cloud native platform used to collect and correlate signals for security operations.

    Why it is wrong: Microsoft Sentinel is a security information and event management solution for analytics and response, not the posture and workload protection platform the grounding describes for cloud and on-premises resources.

  • Workload protection replaces the need for a SIEM by retaining raw logs indefinitely.

    Why it is wrong: Indefinite log retention and SIEM functions are Microsoft Sentinel, not what workload protection provides.

  • Cloud Workload Protection Platform, which defends workloads such as virtual machines and databases from threats.

    Why it is wrong: Cloud Workload Protection Platform defends running workloads from threats rather than checking and improving the configuration posture of resources, so it does not match the description.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.