Q: 1
A customer is deploying Docker images to 10 Azure Kubernetes Service (AKS) resources across four
Azure subscriptions. You are evaluating the security posture of the customer.
You discover that the AKS resources are excluded from the secure score recommendations. You need
to produce accurate recommendations and update the secure score.
Which two actions should you recommend in Microsoft Defender for Cloud? Each correct answer
presents part of the solution. NOTE: Each correct selection is worth one point.
Options
Discussion
A and E tbh, official guide and MS practice tests both cover this sort of secure score scenario for AKS pretty often.
Its A and E. Auto provisioning gets the monitoring agents on all AKS, and Defender plans actually unlock those recommendations for secure score. B isn't needed just for secure score on this workload from what I’ve seen.
Why can't you just enable Defender for Containers and auto provisioning to get AKS resources into secure score? Isn't that what A and E are getting at here?
A and E tbh. You need Defender for Containers enabled and auto-provisioning so AKS gets monitored and actually impacts secure score. That's what I've seen in most of the docs, pretty sure it's not B or D here.
Option A and E make sense here. You have to enable Defender plans for containers (E) so AKS is even monitored, and auto provisioning (A) ensures the agent gets installed on all clusters, which is needed for secure score. B/C/D don't actually trigger the right recommendations for secure score updates. Pretty confident but open to corrections.
Maybe B and D, since setting compliance policies usually affects recommendations and automations can trigger score updates too.
B. not A. Assigning regulatory compliance policies (B) should update the secure score recommendations for AKS. At least that's how I've seen it work before, could be missing an extra step though.
Totally agree, A and E do the job here. Need to enable Defender plans for AKS visibility and set auto provisioning so agents get deployed. Seen similar in some practice sets, pretty sure that's how secure score picks up AKS issues.
I don't think B helps with secure score for AKS, it's A and E. B is a common trap.
Feels like B and D, since workflow automation plus compliance policies should drive secure score recommendations. Not super confident though, maybe missing something.
Be respectful. No spam.