QuestionQ31

Manage and monitor security posture

You have an Azure subscription named Sub1 that contains several virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.

You find that Defender for Cloud does not detect plaintext connection strings or SSH keys stored on the virtual machines.

You need to ensure that secrets are identified on the virtual machines.

What should you do?

Explanation

Agentless machine scanning includes agentless secrets scanning for virtual machines. It scans VM disk snapshots to detect exposed plaintext secrets, including connection strings and SSH private keys, and is available with the Defender CSPM plan.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!