What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).
4.1Posture management with Defender for Cloud
Understand posture evaluation with Microsoft Defender for Cloud (including MCSB) and Microsoft Secure Score, integrated posture across hybrid/multicloud, selecting cloud workload protection (CWPP), and integrating hybrid/multicloud via Azure Arc.
Infrastructure security splits into two questions: "is the configuration safe (posture)?" and "can we detect/defend running threats (workload protection)?" Microsoft Defender for Cloud handles both, not just for Azure but across AWS/GCP/on-prem.
4.1.1CSPM and Secure Score
Cloud security posture management (CSPM) continuously evaluates misconfigurations (public storage, disabled encryption, over-permissions). Defender for Cloud scores the environment against MCSB as the default benchmark and surfaces Secure Score (Defender for Cloud’s infrastructure posture score) to prioritize improvements. Architects make this central to "continuously measure cloud-config risk and reduce it by priority." The Defender CSPM plan adds advanced analysis like attack-path analysis and agentless scanning.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

