QuestionQ224
Design security solutions for infrastructureYou have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription includes 50 virtual machines. Every virtual machine runs distinct applications on Windows Server 2019.
You need to recommend a solution that ensures only authorized applications can run on the virtual machines. If an unauthorized application tries to run or be installed, it must be automatically blocked until an administrator authorizes it.
Which security control should you recommend?
- A app registrations in Azure Active Directory (Azure AD)
- B OAuth app policies in Microsoft Defender for Cloud Apps
- C Azure Security Benchmark compliance controls in Defender for Cloud
- D application control policies in Microsoft Defender for Endpoint
Community Discussion