Memory hook: Posture reduces exposure; protection detects abuse.
Must remember
- Defender for Cloud combines supported posture management and workload protection. Connect hybrid/multicloud resources through the appropriate integrations, including Azure Arc where relevant; verify plan/agent requirements.
- Secure Score, exposure management, attack paths and external attack-surface discovery help prioritize risk. Distinguish known inventory from internet-discovered assets and confirm ownership before remediation.
- Harden servers and clients with baselines, patching, endpoint protection and Windows LAPS. Use Intune/other supported management for devices; OT/ICS and IoT need specialized safety and availability constraints.
- Protect containers through trusted images, registry controls, admission/deployment policy, workload identity, runtime monitoring and network segmentation. A secure host does not automatically secure every container permission.
- SaaS, PaaS and IaaS have different shared-responsibility boundaries. Evaluate web, AI service, database and orchestration controls at the service’s actual exposed interfaces.
- Entra Internet Access addresses supported secure web access; Entra Private Access addresses access to private applications. SSE complements network design, firewalls, DDoS protection and private endpoints rather than eliminating all other controls.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Unknown internet-facing assets may belong to the company | External attack-surface discovery followed by ownership validation. |
| Remote users need identity-aware private-app access | Evaluate Entra Private Access with application and device policies. |
Traps
- A posture score is a prioritization aid, not a guarantee of security.
- Aggressive scanning or patching can be unsafe for sensitive OT systems without operational coordination.
Active recall
1. How do CSPM and workload protection differ?
CSPM assesses configuration/exposure; workload protection detects/protects supported running workloads.
2. Why use attack paths?
To prioritize combinations of weaknesses that can reach high-impact assets.
3. What does Windows LAPS reduce?
Risk from reused or unmanaged local administrator passwords.
4. Why secure container identity?
A small compromised container with broad permissions can affect much larger systems.
5. What should an SSE design preserve?
Strong identity/device policy, application access boundaries and visibility into allowed traffic.