What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).
4.2Exposure Management and external attack surface (EASM)
Understand requirements and priorities for a posture-management process using Microsoft Security Exposure Management (attack paths, attack-surface reduction, security insights, initiatives) and Microsoft Defender External Attack Surface Management (Defender EASM).
A configuration score alone does not tell you "where they break in and how far they reach." Architects capture exposure from the attacker’s perspective and design a process that closes the most dangerous paths first.
4.2.1Security Exposure Management and attack paths
Microsoft Security Exposure Management unifies identity, endpoint, cloud, and data information to visualize attack paths (routes from an external entry to critical assets, the "crown jewels"). Through attack-surface reduction, security insights, and initiatives (themed improvement goals), it supports a posture process that prioritizes "choke points on lethal paths" over "isolated misconfigurations." Architects define here the priority for severing routes to critical assets.
4.2.2Defender EASM: discovering the external attack surface
Organizations harbor external assets they do not track (abandoned subdomains, expired certificates, shadow-IT public hosts). Microsoft Defender External Attack Surface Management (Defender EASM) continuously discovers and inventories the organization’s internet-facing assets from the outside in, surfacing unknown exposure. Architects make Defender EASM central to "continuously know/reduce the externally visible attack surface." Exposure Management (attack paths from inside) and EASM (asset discovery from outside) are complementary.
Cues: "visualize and sever routes (attack paths) from entry to critical assets" = Security Exposure Management. "discover/inventory unknown internet-facing assets from outside" = Defender EASM. "evaluate/score isolated misconfigurations" = CSPM (Secure Score, previous section).
Watch the mix-ups: (1) Exposure Management (attack paths = reachability from inside) and EASM (external-asset discovery) are different lenses—complementary. (2) EASM "finds unknown exposure," it does not "fix" vulnerabilities. (3) Prioritize attack paths by "reachability to critical assets," not a single score.
4.2.3Section summary
- Security Exposure Management = visualize attack paths and sever choke points on routes to critical assets
- Defender EASM = discover/inventory unknown internet-facing assets to reduce the external attack surface
- Complementary (reachability from inside + asset discovery from outside); different role from CSPM’s isolated evaluation
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To visualize routes from external entry to crown-jewel assets and close the most lethal paths first, which is best?
Q2. To continuously discover unknown internet-facing assets (abandoned subdomains, expired certs) from the outside, which is best?
Q3. Which correctly states the relationship between Exposure Management and Defender EASM?
Q4. Which is the most appropriate way to prioritize the posture-management process?
Q5. Which correctly describes the role of Defender EASM?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

