What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).
4.2Exposure Management and external attack surface (EASM)
Understand requirements and priorities for a posture-management process using Microsoft Security Exposure Management (attack paths, attack-surface reduction, security insights, initiatives) and Microsoft Defender External Attack Surface Management (Defender EASM).
A configuration score alone does not tell you "where they break in and how far they reach." Architects capture exposure from the attacker’s perspective and design a process that closes the most dangerous paths first.
4.2.1Security Exposure Management and attack paths
Microsoft Security Exposure Management unifies identity, endpoint, cloud, and data information to visualize attack paths (routes from an external entry to critical assets, the "crown jewels"). Through attack-surface reduction, security insights, and initiatives (themed improvement goals), it supports a posture process that prioritizes "choke points on lethal paths" over "isolated misconfigurations." Architects define here the priority for severing routes to critical assets.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

