QuestionQ51

Design security solutions for infrastructure

Your company completes its adoption of Azure and is implementing Microsoft Defender for Cloud.

You receive the following recommendations from Defender for Cloud:

  • Access to storage accounts with firewall and virtual network configurations should be restricted.
  • Storage accounts should restrict network access using virtual network rules.
  • Storage account should use a private link connection.
  • Storage account public access should be disallowed.

You need to recommend a service to mitigate the identified risks related to these recommendations.

What should you recommend?

  • A Azure Policy
  • B Azure Network Watcher
  • C Azure Storage Analytics
  • D Microsoft Sentinel
Explanation

Azure Policy provides built-in policy definitions that assess and can enforce storage-account configurations such as restricted network access, virtual-network rules, private link, and disallowing public access. These controls directly mitigate the exposure risks identified by the recommendations.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!