Module 5: Defender for Cloud

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/72

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:43 AM on 9/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

73 Terms

1
New cards
What is Microsoft Defender for Cloud
Cloud Native Application Protection Platform (CNAPP)
2
New cards
What are the two primary pillars of Microsoft Defender for Cloud
Cloud Security Posture Management and Cloud Workload Protection
3
New cards
What is Cloud Security Posture Management (CSPM)
Identifies and remediates cloud misconfigurations
4
New cards
What is Cloud Workload Protection (CWPP)
Protects workloads from active threats
5
New cards
What is Microsoft Defender CSPM
Provides posture management across cloud environments
6
New cards
What is Defender for Servers
Protects Azure and hybrid servers
7
New cards

What is Defender for Storage

Protects storage accounts from threats

8
New cards
What is Defender for SQL
Protects SQL databases from attacks
9
New cards
What is Defender for Key Vault
Protects Azure Key Vault resources
10
New cards
What is Defender for Containers
Protects Kubernetes and container workloads
11
New cards
What is Defender for Resource Manager
Detects suspicious Azure control-plane activities
12
New cards
What is Defender for DNS
Detects suspicious DNS activity
13
New cards
What is Defender for App Service
Protects Azure App Service applications
14
New cards
What is Secure Score
Measures cloud security posture
15
New cards
What is a Secure Score recommendation
Action that improves Secure Score
16
New cards
What is Secure Score impact
Points gained from completing recommendations
17
New cards
What is a Security Recommendation
Guidance to reduce security risk
18
New cards
What is Regulatory Compliance Dashboard
Tracks compliance against standards and frameworks
19
New cards
What is Azure Policy
Service used to assess and enforce compliance
20
New cards
What is Regulatory Compliance Standard
Framework such as NIST or ISO 27001
21
New cards
What is an Assessment in Regulatory Compliance
Evaluation of a compliance requirement
22
New cards
What is a Compliance Control
Requirement within a compliance framework
23
New cards
What is a Healthy Resource
Resource meeting security requirements
24
New cards
What is an Unhealthy Resource
Resource failing security requirements
25
New cards
What is Attack Path Analysis
Identifies exploitable attack paths
26
New cards
What is Cloud Security Explorer
Visual tool for analyzing cloud risks
27
New cards
What is a Security Alert
Notification of suspicious activity
28
New cards
What is a Security Incident
Collection of related alerts
29
New cards
What is Alert Correlation
Grouping alerts into incidents
30
New cards
What is Microsoft Sentinel integration
Sends alerts and incidents to Sentinel
31
New cards
What are Environment Settings
Configuration settings for Defender plans
32
New cards
What is a Defender Plan
Protection package for a resource type
33
New cards
What is Agentless Scanning
Scans resources without installing agents
34
New cards
What is Malware Scanning
Scans workloads for malicious files
35
New cards
What is Vulnerability Assessment
Evaluates systems for security weaknesses
36
New cards
What is Defender for Containers Vulnerability Assessment
Scans container images for vulnerabilities
37
New cards
What is Defender for Servers Plan 1
Basic server protection
38
New cards
What is Defender for Servers Plan 2
Advanced protection with additional security features
39
New cards
What is Just-In-Time (JIT) VM Access
Temporarily opens management ports when needed
40
New cards
What is Adaptive Application Controls
Creates allowlists for approved applications
41
New cards
What is File Integrity Monitoring
Detects changes to important files
42
New cards
What is a Security Policy
Collection of security requirements
43
New cards
What is Multi-Cloud Support
Protection for Azure, AWS, and GCP resources
44
New cards
What is AWS Connector
Connects AWS resources to Defender for Cloud
45
New cards
What is GCP Connector
Connects Google Cloud resources to Defender for Cloud
46
New cards
What is the Inventory Page
Displays protected resources
47
New cards
What is Resource Health
Security status of a resource
48
New cards
What is a Cloud Workload
Application or service running in the cloud
49
New cards
What is Azure Resource Graph
Query service for Azure resources
50
New cards
What is Exposure Score
Measures exposure to attack paths
51
New cards
What is Risk Prioritization
Ranks risks by severity and exposure
52
New cards
What is Adaptive Network Hardening
Recommends network security rule improvements
53
New cards
What is Internet Exposure
Resource accessible from the internet
54
New cards
What is Lateral Movement Risk
Potential attacker movement between resources
55
New cards
What is Defender for APIs
Protects published APIs from threats
56
New cards
What is API Security Posture
Assessment of API security configuration
57
New cards
What is a Cloud Attack Path
Route attackers may use to reach assets
58
New cards
What is Security Posture
Overall security condition of cloud resources
59
New cards
What is a Hybrid Environment
Combination of cloud and on-premises resources
60
New cards
What is a Remediation Task
Action performed to resolve a recommendation
61
New cards
What is a Recommendation Exemption
Excludes a recommendation from evaluation
62
New cards
What is Continuous Security Assessment
Ongoing evaluation of resources
63
New cards
What is a Cloud Misconfiguration
Incorrect cloud setting that increases risk
64
New cards
What is the main goal of Defender for Cloud
Reduce cloud risk and improve security posture
65
New cards
What is the main difference between CSPM and CWPP
CSPM finds misconfigurations; CWPP protects workloads from threats
66
New cards
Which Defender for Cloud feature is used most for exam questions involving exposed RDP ports
Just-In-Time VM Access
67
New cards
Which service powers compliance assessments in Defender for Cloud
Azure Policy
68
New cards
Which feature recommends NSG rule improvements
Adaptive Network Hardening
69
New cards
What is the purpose of Secure Score
Measure and improve cloud security posture
70
New cards
What is the purpose of Vulnerability Assessment
Identify security weaknesses
71
New cards
What is the purpose of Workflow Automation
Automate security responses
72
New cards
What is the purpose of Exposure Score
Prioritize risks based on exposure
73
New cards
What is the purpose of Recommendation Exemptions
Exclude accepted risks from assessment