Skip to content

Commit ca21df5

Browse files
authored
Merge pull request #54061 from ceperezb/CEPEREZB-sc900-security-management-azure
update module
2 parents 6d6a1d3 + 04595ab commit ca21df5

16 files changed

Lines changed: 405 additions & 239 deletions
Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.introduction
3-
title: Introduction
4-
metadata:
5-
title: Introduction
6-
description: "Introduction"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
durationInMinutes: 1
12-
content: |
13-
[!include[](includes/1-introduction.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.introduction
3+
title: Introduction
4+
metadata:
5+
title: Introduction
6+
description: "Introduction"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 1
12+
content: |
13+
[!include[](includes/1-introduction.md)]
Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-&-explore-azure-security-center
3-
title: Describe Microsoft Defender for Cloud
4-
metadata:
5-
title: Describe Microsoft Defender for Cloud
6-
description: "Describe Microsoft Defender for Cloud"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
durationInMinutes: 3
12-
content: |
13-
[!include[](includes/2-describe-defender-cloud.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-&-explore-azure-security-center
3+
title: Describe Microsoft Defender for Cloud
4+
metadata:
5+
title: Describe Microsoft Defender for Cloud
6+
description: "Describe Microsoft Defender for Cloud"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 5
12+
content: |
13+
[!include[](includes/2-describe-defender-cloud.md)]
Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.baselines-for-azure
3-
title: Describe how security policies and initiatives improve cloud security posture
4-
metadata:
5-
title: Describe how security policies and initiatives improve cloud security posture
6-
description: "Describe how security policies and initiatives improve cloud security posture"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
durationInMinutes: 6
12-
content: |
13-
[!include[](includes/3-baselines-for-azure.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.baselines-for-azure
3+
title: Describe how security policies, standards, and recommendations improve cloud security posture
4+
metadata:
5+
title: Describe how security policies, standards, and recommendations improve cloud security posture
6+
description: "Describe how security policies, standards, and recommendations improve cloud security posture"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 6
12+
content: |
13+
[!include[](includes/3-baselines-for-azure.md)]
Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-cloud-security-posture-management-cspm
3-
title: Describe Cloud security posture management
4-
metadata:
5-
title: Describe Cloud security posture management
6-
description: "Describe Cloud security posture management"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
durationInMinutes: 3
12-
content: |
13-
[!include[](includes/4-describe-cloud-security-posture-management.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-cloud-security-posture-management-cspm
3+
title: Describe Cloud security posture management
4+
metadata:
5+
title: Describe Cloud security posture management
6+
description: "Describe Cloud security posture management"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 5
12+
content: |
13+
[!include[](includes/4-describe-cloud-security-posture-management.md)]
Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-benefit-use-cases-defender
3-
title: Describe the enhanced security of Microsoft Defender for Cloud
4-
metadata:
5-
title: Describe the enhanced security of Microsoft Defender for Cloud
6-
description: "Describe the enhanced security of Microsoft Defender for Cloud"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
durationInMinutes: 5
12-
content: |
13-
[!include[](includes/5a-describe-enhanced-security-defender-cloud.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-benefit-use-cases-defender
3+
title: Describe the enhanced security of Microsoft Defender for Cloud
4+
metadata:
5+
title: Describe the enhanced security of Microsoft Defender for Cloud
6+
description: "Describe the enhanced security of Microsoft Defender for Cloud"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 5
12+
content: |
13+
[!include[](includes/5a-describe-enhanced-security-defender-cloud.md)]
Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-dev-ops-security-management
3-
title: Describe DevOps security management
4-
metadata:
5-
title: Describe DevOps security management
6-
description: "Describe DevOps security management"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
durationInMinutes: 3
12-
content: |
13-
[!include[](includes/6-describe-dev-ops-security-management.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.describe-dev-ops-security-management
3+
title: Describe DevOps security management
4+
metadata:
5+
title: Describe DevOps security management
6+
description: "Describe DevOps security management"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 4
12+
content: |
13+
[!include[](includes/6-describe-dev-ops-security-management.md)]
Lines changed: 72 additions & 61 deletions
Original file line numberDiff line numberDiff line change
@@ -1,61 +1,72 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.knowledge-check
3-
title: Module assessment
4-
metadata:
5-
title: Module assessment
6-
description: "Knowledge check"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
module_assessment: true
12-
durationInMinutes: 2
13-
content: |
14-
[!include[](includes/7-knowledge-check.md)]
15-
quiz:
16-
title: "Check your knowledge"
17-
questions:
18-
- content: "Microsoft Defender for Cloud covers three pillars of cloud security. Which pillar provides visibility to help you understand your current security situation and provides hardening recommendations?"
19-
choices:
20-
- content: "Cloud security posture management (CSPM)"
21-
isCorrect: true
22-
explanation: "Correct. The CSPM pillar of Microsoft Defender for Cloud provides visibility and to help you understand your current security situation and provides hardening recommendations."
23-
- content: "Cloud workload protection (CWP)"
24-
isCorrect: false
25-
explanation: "Incorrect. Although CWP is an important pillar of cloud security for Microsoft Defender for Cloud, it's focused on detecting and resolving threats for resources, workload, and services. It works with the CSPM pillar."
26-
- content: "Microsoft Cloud security benchmark"
27-
isCorrect: false
28-
explanation: "Incorrect. The Microsoft cloud security benchmark (MCSB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure and your multicloud environment."
29-
- content: "An organization wants to add vulnerability scanning for its Azure resources to view, investigate, and remediate the findings directly within Microsoft Defender for Cloud. What functionality of Microsoft Defender for Cloud would they need to consider?"
30-
choices:
31-
- content: "Secure score and recommendations functionality that are part of the CSPM pillar of Microsoft Defender for Cloud."
32-
isCorrect: false
33-
explanation: "Incorrect. Secure score and recommendations functionality doesn't include vulnerability scanning."
34-
- content: "The enhanced functionality that is provided through the Microsoft Defender plans and is part of the CWP pillar of Microsoft Defender for Cloud."
35-
isCorrect: true
36-
explanation: "Correct. Microsoft Defender plans provide enhanced security features for your workloads, including vulnerability scanning."
37-
- content: "Security Benchmarks"
38-
isCorrect: false
39-
explanation: "Incorrect. The Microsoft cloud security benchmark (MCSB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure, it doesn't provide vulnerability scanning."
40-
- content: "Which framework does Microsoft Defender for Cloud apply as a default initiative for security and compliance and provides best practices and recommendations to help improve the security of workloads, data, and services on Azure and your multicloud environment?"
41-
choices:
42-
- content: "Microsoft Cloud security benchmark"
43-
isCorrect: true
44-
explanation: "Correct. The Microsoft cloud security benchmark that is automatically assigned to every subscription in Microsoft Defender for Cloud."
45-
- content: "The Center for Internet Security (CIS) framework"
46-
isCorrect: false
47-
explanation: "Incorrect. Although the MCSB builds on the controls from the Center for Internet Security (CIS) and the National Institute of Standards and Technology (NIST) with a focus on cloud-centric security, it's the MCSB that is automatically applied as a default initiative."
48-
- content: "The National Institute of Standards and Technology (NIST) framework"
49-
isCorrect: false
50-
explanation: "Incorrect. Although the MCSB builds on the controls from the Center for Internet Security (CIS) and the National Institute of Standards and Technology (NIST) with a focus on cloud-centric security, it's the MCSB that is automatically applied as a default initiative."
51-
- content: "Which capability allows you to manage your connected DevOps environments and provides your security teams with visibility to discovered issues within those environments?"
52-
choices:
53-
- content: "The Defender for DevOps console"
54-
isCorrect: true
55-
explanation: "Correct. The Defender for DevOps console allows you to manage your connected DevOps environments and provides your security teams with a high level overview of discovered issues that may exist within them."
56-
- content: "Secure score"
57-
isCorrect: false
58-
explanation: "Incorrect. Although secure score in Microsoft Defender for Cloud provides single score so that you can tell, at a glance, your current security situation, it does not provide specific visibility to your DevOps environments. ."
59-
- content: "The Microsoft cloud security benchmark (MCSB)"
60-
isCorrect: false
61-
explanation: "Incorrect. The Microsoft cloud security benchmark (MCSB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure and your multicloud environment."
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.knowledge-check
3+
title: Module assessment
4+
metadata:
5+
title: Module assessment
6+
description: "Knowledge check"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
module_assessment: true
12+
durationInMinutes: 2
13+
content: |
14+
[!include[](includes/7-knowledge-check.md)]
15+
quiz:
16+
title: "Check your knowledge"
17+
questions:
18+
- content: "Microsoft Defender for Cloud covers three pillars of cloud security. Which pillar provides visibility to help you understand your current security situation and provides hardening recommendations?"
19+
choices:
20+
- content: "Cloud security posture management (CSPM)"
21+
isCorrect: true
22+
explanation: "Correct. The CSPM pillar of Microsoft Defender for Cloud provides visibility and to help you understand your current security situation and provides hardening recommendations."
23+
- content: "Cloud workload protection (CWP)"
24+
isCorrect: false
25+
explanation: "Incorrect. Although CWP is an important pillar of cloud security for Microsoft Defender for Cloud, it's focused on detecting and resolving threats for resources, workload, and services. It works with the CSPM pillar."
26+
- content: "Microsoft Cloud security benchmark"
27+
isCorrect: false
28+
explanation: "Incorrect. The Microsoft cloud security benchmark (MCSB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure and your multicloud environment."
29+
- content: "An organization wants to add vulnerability scanning for its Azure resources to view, investigate, and remediate the findings directly within Microsoft Defender for Cloud. What functionality of Microsoft Defender for Cloud would they need to consider?"
30+
choices:
31+
- content: "Secure score and recommendations functionality that are part of the CSPM pillar of Microsoft Defender for Cloud."
32+
isCorrect: false
33+
explanation: "Incorrect. Secure score and recommendations functionality doesn't include vulnerability scanning."
34+
- content: "The enhanced functionality that is provided through the Microsoft Defender plans and is part of the cloud workload protection platform (CWPP) pillar of Microsoft Defender for Cloud."
35+
isCorrect: true
36+
explanation: "Correct. Microsoft Defender plans provide enhanced security features for your workloads, including vulnerability scanning."
37+
- content: "Security Benchmarks"
38+
isCorrect: false
39+
explanation: "Incorrect. The Microsoft cloud security benchmark (MCSB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure, it doesn't provide vulnerability scanning."
40+
- content: "Which framework does Microsoft Defender for Cloud apply as a default initiative for security and compliance and provides best practices and recommendations to help improve the security of workloads, data, and services on Azure and your multicloud environment?"
41+
choices:
42+
- content: "Microsoft Cloud security benchmark"
43+
isCorrect: true
44+
explanation: "Correct. The Microsoft cloud security benchmark that is automatically assigned to every subscription in Microsoft Defender for Cloud."
45+
- content: "The Center for Internet Security (CIS) framework"
46+
isCorrect: false
47+
explanation: "Incorrect. Although the MCSB builds on the controls from the Center for Internet Security (CIS) and the National Institute of Standards and Technology (NIST) with a focus on cloud-centric security, it's the MCSB that is automatically applied as a default initiative."
48+
- content: "The National Institute of Standards and Technology (NIST) framework"
49+
isCorrect: false
50+
explanation: "Incorrect. Although the MCSB builds on the controls from the Center for Internet Security (CIS) and the National Institute of Standards and Technology (NIST) with a focus on cloud-centric security, it's the MCSB that is automatically applied as a default initiative."
51+
- content: "Which capability allows you to manage your connected DevOps environments and provides your security teams with visibility to discovered issues within those environments?"
52+
choices:
53+
- content: "The Defender for DevOps console"
54+
isCorrect: true
55+
explanation: "Correct. The Defender for DevOps console allows you to manage your connected DevOps environments and provides your security teams with a high level overview of discovered issues that may exist within them."
56+
- content: "Secure score"
57+
isCorrect: false
58+
explanation: "Incorrect. Although secure score in Microsoft Defender for Cloud provides single score so that you can tell, at a glance, your current security situation, it doesn't provide specific visibility to your DevOps environments."
59+
- content: "The Microsoft cloud security benchmark (MCSB)"
60+
isCorrect: false
61+
explanation: "Incorrect. The Microsoft cloud security benchmark (MCSB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure and your multicloud environment."
62+
- content: "An organization wants to understand what generative AI applications and models are running in their cloud environment and whether they're securely configured. Which capability in Microsoft Defender for Cloud addresses this need?"
63+
choices:
64+
- content: "AI security posture management (AI SPM)"
65+
isCorrect: true
66+
explanation: "Correct. AI SPM maintains an AI Bill of Materials (AI BOM) that catalogs your organization's generative AI workloads and assesses their security posture, surfacing recommendations and attack path analysis specific to AI."
67+
- content: "AI threat protection"
68+
isCorrect: false
69+
explanation: "Incorrect. AI threat protection detects active threats targeting generative AI workloads in real time, such as prompt injection attacks and data leakage. Discovering and assessing the security posture of AI workloads is the role of AI security posture management (AI SPM)."
70+
- content: "Cloud security explorer"
71+
isCorrect: false
72+
explanation: "Incorrect. The cloud security explorer lets security teams run graph-based queries to investigate security risks across cloud resources. It is not specifically focused on discovering and assessing the security posture of AI workloads."
Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.describe-security-management-capabilities-of-azure.summary-resources
3-
title: Summary and resources
4-
metadata:
5-
title: Summary and resources
6-
description: "Summary and resources"
7-
ms.date: 08/05/2024
8-
author: wwlpublish
9-
ms.author: ceperezb
10-
ms.topic: unit
11-
durationInMinutes: 1
12-
content: |
13-
[!include[](includes/8-summary-resources.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.describe-security-management-capabilities-of-azure.summary-resources
3+
title: Summary and resources
4+
metadata:
5+
title: Summary and resources
6+
description: "Summary and resources"
7+
ms.date: 03/31/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 1
12+
content: |
13+
[!include[](includes/8-summary-resources.md)]

0 commit comments

Comments
 (0)