QuestionQ22

Secure storage, databases, and networking

You have an Azure subscription named Sub1 that includes a storage account named storage1.

Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled with a monthly limit of 10,000 GB per storage account.

You use a Microsoft Sentinel workspace to monitor security events across all Azure resources.

You need to configure storage1 to use a malware-scanning cap of 2,000 GB each month.

What should you do?

Explanation

Microsoft Defender for Storage allows a storage account to override subscription-level settings. Enabling the override for storage1 permits a storage-account-specific on-upload malware-scanning cap of 2,000 GB, while retaining the 10,000-GB subscription-level cap for other storage accounts. Microsoft Sentinel ingestion controls do not configure Defender for Storage scanning limits.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!