Domain 4 of 4 · Chapter 1 of 3

Manage security posture by using Defender for Cloud

Unlock the complete study guide + 1,040 practice questions across 16 full exams.

Bundled into the existing SC-500 premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • What Defender for Cloud sees, and what each plan adds
  • Finding the risks that matter with Defender CSPM
  • Security standards and the Regulatory compliance dashboard
  • Authoring custom standards and custom recommendations
  • Workload protection plans and their scope
  • Vulnerability management for machines
  • Onboarding AWS, GCP, and hybrid machines
  • Discovering external assets with Defender EASM
  • Exam pattern recognition

What each Defender for Cloud plan adds

CapabilityFoundational CSPM (free)Defender CSPMDefender for Servers Plan 1Defender for Servers Plan 2
Asset inventory, recommendations, secure score, Microsoft Cloud Security BenchmarkYesYesYesYes
Cloud Security Explorer and attack path analysisNoYesNoNo
Risk prioritization on recommendationsNoYesNoNo
KQL-backed custom recommendationsNoYesNoNo
Regulatory compliance standards beyond the benchmarkNoYesNoYes
Agentless vulnerability and secrets scanning of machinesNoYesNoYes
Agentless malware scanning of machinesNoNoNoYes
Agent-based vulnerability scanning via the Defender for Endpoint sensorNoNoYesYes
Endpoint detection and response on serversNoNoYesYes
File integrity monitoring and just-in-time machine accessNoNoNoYes

Decision tree

Need runtime threat alerts for a resource family? Yes Workload plan for that family such as Defender for Storage No Need the Defender for Endpoint sensor on servers? Yes Also agentless vulnerability, secrets, or malware scanning? Yes Defender for Servers Plan 2 No Defender for Servers Plan 1 No Need graph queries, attack paths, risk ranking, or KQL rules? Yes Defender CSPM No Foundational CSPM (free) is enough

Cheat sheet

  • Foundational CSPM supplies the default posture baseline
  • Defender CSPM unlocks graph-based risk analysis
  • Agentless machine scanning exposes secrets without endpoint deployment
  • Subscription Owner permission enables complete Defender CSPM scanning
  • Prioritize CSPM remediation by contextual risk rather than severity alone
  • Assigned security standards drive continuous compliance assessment
  • Compliance standards are assigned to the cloud scope being evaluated
  • KQL-backed custom recommendations require Defender CSPM
  • Custom-standard creation and recommendation authoring use different permissions
  • Use policy-data Reader access and a paid plan to expand compliance standards
  • Attest manual compliance assessments instead of awaiting automated results
  • Workload protection is enabled through resource-specific Defender plans
  • Subscription-level Defender plans cover contained resources
  • Defender for Servers Plan 2 adds advanced machine controls
  • Defender Vulnerability Management combines agent-based and agentless findings
  • Hybrid vulnerability scanning favors fresher agent evidence
  • An AWS management-account connector can expand to member accounts
  • AWS connector access is established through CloudFormation permissions
  • The GCP onboarding script creates workload-identity trust
  • Azure Arc extends server-plan management beyond Azure
  • Authenticate the native AWS connector with federated short-lived credentials
  • EASM expands known seeds into an external asset inventory
  • EASM asset states distinguish ownership from relevance
  • Discovery groups control recurring seed-based discovery
  • A prebuilt EASM inventory should be reviewed before custom discovery
  • Seed EASM discovery with supported external infrastructure entities
  • Use EASM dashboards to prioritize the riskiest external exposures

Unlock with Premium — includes all practice exams and the complete study guide.

References

  1. What is Microsoft Defender for Cloud?
  2. Connect your AWS account to Microsoft Defender for Cloud
  3. Connect your GCP project to Microsoft Defender for Cloud
  4. Cloud security posture management (CSPM) in Defender for Cloud
  5. Build queries with cloud security explorer
  6. Identify and remediate attack paths
  7. Risk prioritization of security recommendations
  8. Enable agentless machine scanning
  9. Assign security standards in Microsoft Defender for Cloud
  10. Improve regulatory compliance with the compliance dashboard
  11. Create custom security standards and recommendations
  12. Select a Defender for Servers plan
  13. Integrated vulnerability assessment in Defender for Cloud
  14. Enable Microsoft Defender Vulnerability Management scanning on machines
  15. What is discovery in Defender External Attack Surface Management?
  16. Understanding Defender EASM dashboards