What is Defender for Cloud?
Microsoft Defender for Cloud (formerly Azure Security Center) is a unified security management system.
It continuously monitors your Azure resources, provides security recommendations, and detects threats across workloads.
Key Features
-
Secure Score:
-
A numerical score showing how secure your environment is.
-
Higher score = better compliance with best practices.
-
-
Recommendations:
-
Actionable guidance (e.g., “Enable MFA,” “Encrypt disks,” “Apply NSGs”).
-
-
Defender Plans:
-
Free tier: Basic security posture management.
-
Paid tier: Advanced threat protection for VMs, storage, SQL, containers.
-
-
Threat Protection:
-
Detects suspicious activity (e.g., brute force attacks on VMs).
-
-
Integration:
-
Works with Sentinel, Log Analytics, and third-party SIEM tools.
-
Confusion Buster 🚨
-
Defender for Cloud vs Sentinel
-
Defender = security recommendations + protection.
-
Sentinel = SIEM (collect, analyze, respond to threats across environments).
-
-
Defender Free vs Paid
-
Free = security posture + recommendations.
-
Paid = advanced threat protection per resource type.
-
Exam trap: If question says “improve compliance score” → Defender for Cloud. If it says “security analytics across logs from multiple sources” → Sentinel.
Simple Example
A company enables Defender for Cloud:
-
Gets a Secure Score of 65% with recommendations to enable MFA and restrict public IPs.
-
Purchases the Defender for Servers plan to add advanced threat detection.
-
Integrates alerts with Sentinel for centralized monitoring.
Exam Tip
-
“Which Azure service gives security recommendations?” → Defender for Cloud.
-
“Which feature provides a Secure Score?” → Defender for Cloud.
-
“Which service detects brute force login attempts on a VM?” → Defender for Servers (part of Defender for Cloud).
What to Expect in the Exam
-
Direct Q: “Which Azure service provides a Secure Score?” → Defender for Cloud.
-
Scenario: “You need security recommendations to improve compliance posture.” → Defender for Cloud.
-
Trick Q: “Defender for Cloud is a SIEM tool.” (False — that’s Sentinel).