What's changed: Added per-section figures (cert-figure-retrofit). New SC-500 Chapter 4 (Domain 4 "Manage and monitor posture": Defender for Cloud = CSPM(recommendations/Secure Score/attack paths/regulatory compliance)-CWP plans-multicloud(AWS/GCP)-Defender Vulnerability Management-EASM; Microsoft Sentinel = workspaces/roles/content hub/data connectors/Syslog-CEF/Windows events(DCR-WEF)/custom tables/automation rules-playbooks/data retention/Purview Audit in Defender XDR; Microsoft Security Copilot = workspaces/permissions-roles/plugins/Microsoft-Security Store agents)
4.1Managing security posture with Defender for Cloud
Learn to identify risks with Defender CSPM, evaluate compliance against security frameworks, enable workload protection plans, connect hybrid/multicloud (AWS, GCP), configure Defender Vulnerability Management for Azure VMs, and discover unprotected assets with External Attack Surface Management (EASM).
Posture management has two pillars: "where are the weaknesses now (CSPM)" and "is anything actually under attack (workload protection)." Microsoft Defender for Cloud covers both and extends beyond Azure to AWS/GCP multicloud and hybrid environments.
4.1.1Defender CSPM—identifying and prioritizing risk
Defender CSPM surfaces configuration weaknesses as recommendations and scores overall health as Secure Score. Attack path analysis visualizes connected risk like "internet-exposed → vulnerable VM → over-privileged → sensitive data," prioritizing remediation of the most dangerous paths. The regulatory compliance dashboard also evaluates conformance to frameworks like PCI DSS and ISO 27001.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

