Instiq
Chapter 4 · Infrastructure security·v1.0.0·Updated 6/28/2026·~15 min

What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).

4.1Posture management with Defender for Cloud

Key points

Understand posture evaluation with Microsoft Defender for Cloud (including MCSB) and Microsoft Secure Score, integrated posture across hybrid/multicloud, selecting cloud workload protection (CWPP), and integrating hybrid/multicloud via Azure Arc.

Infrastructure security splits into two questions: "is the configuration safe (posture)?" and "can we detect/defend running threats (workload protection)?" Microsoft Defender for Cloud handles both, not just for Azure but across AWS/GCP/on-prem.

4.1.1CSPM and Secure Score

Cloud security posture management (CSPM) continuously evaluates misconfigurations (public storage, disabled encryption, over-permissions). Defender for Cloud scores the environment against MCSB as the default benchmark and surfaces Secure Score (Defender for Cloud’s infrastructure posture score) to prioritize improvements. Architects make this central to "continuously measure cloud-config risk and reduce it by priority." The Defender CSPM plan adds advanced analysis like attack-path analysis and agentless scanning.

4.1.2CWPP and Azure Arc

cloud workload protection (CWPP) detects/defends threats to running workloads (servers, containers, storage, databases) via plans (Defender for Servers/Containers/Storage/Databases). To bring non-Azure servers and other clouds under the same management, onboard them with Azure Arc and apply Defender and Azure Policy to Arc-enabled servers. Architects combine Arc + Defender for Cloud for "manage on-prem and AWS/GCP servers with the same posture/protection as Azure."

Exam point

Cues: "continuously evaluate/prioritize misconfigurations" = CSPM (Secure Score). "detect/defend threats on running workloads" = CWPP (Defender for Servers/Containers/Storage/Databases). "bring on-prem/other-cloud servers under the same management as Azure" = Azure Arc. "regulatory alignment of cloud config" = regulatory compliance dashboard.

Warning

Watch the mix-ups: (1) CSPM (config posture) and CWPP (runtime protection) are different layers—need both. (2) Distinguish Secure Score (Defender for Cloud, infra posture) from Microsoft Secure Score (Defender XDR, identity/M365 posture). (3) Arc is the "multicloud management foundation"—not threat detection itself (detection is via Defender plans).

Diagram of CSPM (config eval against MCSB → Secure Score; Defender CSPM adds attack-path analysis), CWPP (Servers/Containers/Storage/Databases), and Azure Arc integrating on-prem/AWS/GCP.
Unify config and runtime

4.1.3Section summary

  • CSPM = continuously evaluate misconfig against MCSB, prioritize via Secure Score; Defender CSPM adds attack-path analysis
  • CWPP = detect/defend threats on running workloads (Servers/Containers/Storage/Databases)
  • Azure Arc = bring on-prem/AWS/GCP under the same posture/protection/policy management as Azure

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To continuously evaluate cloud misconfigurations (public storage, disabled encryption) and prioritize/visualize improvements, which is best?

Q2. To place on-prem and AWS servers under the same posture/Defender protection/Azure Policy management as Azure, which is best?

Q3. To enable threat detection/defense on running VMs, containers, storage, and databases—what kind of plan is this?

Q4. Which correctly distinguishes Secure Score (Defender for Cloud) from Microsoft Secure Score (Defender XDR)?

Q5. Splitting infrastructure security into "configuration safety" and "runtime threat defense," which product handles both centrally?

Check your understandingPractice questions for Chapter 4: Infrastructure security

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.