Instiq
Chapter 4 · Manage and monitor security posture·v1.1.0·Updated 6/11/2026·~15 min

What's changed: Added per-section figures (cert-figure-retrofit). New SC-500 Chapter 4 (Domain 4 "Manage and monitor posture": Defender for Cloud = CSPM(recommendations/Secure Score/attack paths/regulatory compliance)-CWP plans-multicloud(AWS/GCP)-Defender Vulnerability Management-EASM; Microsoft Sentinel = workspaces/roles/content hub/data connectors/Syslog-CEF/Windows events(DCR-WEF)/custom tables/automation rules-playbooks/data retention/Purview Audit in Defender XDR; Microsoft Security Copilot = workspaces/permissions-roles/plugins/Microsoft-Security Store agents)

4.1Managing security posture with Defender for Cloud

Key points

Learn to identify risks with Defender CSPM, evaluate compliance against security frameworks, enable workload protection plans, connect hybrid/multicloud (AWS, GCP), configure Defender Vulnerability Management for Azure VMs, and discover unprotected assets with External Attack Surface Management (EASM).

Posture management has two pillars: "where are the weaknesses now (CSPM)" and "is anything actually under attack (workload protection)." Microsoft Defender for Cloud covers both and extends beyond Azure to AWS/GCP multicloud and hybrid environments.

4.1.1Defender CSPM—identifying and prioritizing risk

Defender CSPM surfaces configuration weaknesses as recommendations and scores overall health as Secure Score. Attack path analysis visualizes connected risk like "internet-exposed → vulnerable VM → over-privileged → sensitive data," prioritizing remediation of the most dangerous paths. The regulatory compliance dashboard also evaluates conformance to frameworks like PCI DSS and ISO 27001.

4.1.2Workload protection plans and multicloud

Cloud Workload Protection (CWP) enables per-resource-type Defender plans (Servers, Storage, Databases, Containers, Key Vault, AI—as seen in Chapters 1–3) to detect runtime threats. Multicloud connectors connect AWS and GCP accounts, extending CSPM and some threat protection to those resources. Defender Vulnerability Management continuously assesses Azure VM vulnerabilities, and EASM (External Attack Surface Management) discovers internet-facing assets the organization did not know about.

GoalFeatureType
Config weaknesses and priorityDefender CSPM (recommendations/Secure Score/attack paths)Posture (proactive)
Runtime threat detectionCloud Workload Protection (CWP) plansThreat protection (runtime)
Framework complianceRegulatory complianceEvaluation/visibility
Protect AWS/GCP tooMulticloud connectorsExtension
Discover unknown exposed assetsEASMExternal attack surface
Warning

Watch the mix-ups: (1) Defender CSPM (config posture = proactive risk identification/attack paths/Secure Score) vs workload protection plans (runtime threat detection)—two pillars, both needed. (2) Defender Vulnerability Management (known vulns = internal assessment of your assets) vs EASM (discover unknown externally visible assets). (3) Defender for Cloud also protects AWS/GCP via multicloud connectors.

Exam point

Map requirement → feature: "visualize connected risk paths and prioritize" = CSPM attack path analysis; "protect AWS/GCP resources with Defender" = multicloud connectors; "discover unknown internet-facing assets" = EASM; "evaluate PCI DSS conformance" = regulatory compliance; "detect runtime threats to VMs" = Defender for Servers (a CWP plan).

Diagram of Defender CSPM identifying/prioritizing risk, workload protection plans, and multicloud coverage.
Posture evaluation and workload protection

4.1.3Section summary

  • Defender for Cloud = CSPM (proactive posture: recommendations/Secure Score/attack paths/regulatory compliance) + CWP (runtime threat detection)
  • Multicloud connectors protect AWS/GCP; Defender Vulnerability Management continuously assesses VMs
  • EASM discovers unknown internet-facing assets

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which Defender CSPM capability visualizes connected risk paths (e.g., internet-exposed → vulnerable VM → over-privileged → sensitive data) to prioritize the most dangerous ones?

Q2. In Defender for Cloud, what do you use to bring AWS and GCP resources into protection?

Q3. Which discovers internet-facing assets the organization is unaware of, from the outside in?

Q4. Which correctly distinguishes Defender CSPM from Cloud Workload Protection (CWP) plans?

Q5. Which continuously assesses known vulnerabilities on Azure VMs?

Q6. Which Defender for Cloud feature evaluates and visualizes conformance to frameworks like PCI DSS and ISO 27001?

Check your understandingPractice questions for Chapter 4: Manage and monitor security posture

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.