Protego field desk
Infrastructure Security Architecture / 25-30% of exam

L10.Multicloud Posture, Exposure Management & Azure Arc

Course outlineLesson 10 of 18

Design a posture-management process that connects Defender for Cloud, Secure Score, Azure Arc, EASM, attack paths, and remediation ownership across hybrid and multicloud estates.

Build one asset and exposure view

Posture management begins with inventory and ownership. Microsoft Defender for Cloud evaluates supported Azure, hybrid, and multicloud resources against security recommendations and the Microsoft Cloud Security Benchmark. Azure Arc extends Azure management capabilities to supported resources outside Azure.

Distinguish the measures

Secure Score summarizes improvement actions and posture signals. It helps prioritize and track progress, but it is not a risk model by itself. Defender External Attack Surface Management discovers internet-visible assets from an outside-in perspective. Internal inventory and external discovery should be reconciled.

Prioritize attack paths

Exposure Management combines attack paths, insights, initiatives, and attack-surface-reduction information. Prioritize findings that connect exposed entry points to critical assets or privileged control. Assign remediation to the team that can safely change the asset.

Design the operating loop

  1. Discover and normalize assets.
  2. Assign business owner and criticality.
  3. Evaluate posture and exposure.
  4. Prioritize by reachable impact.
  5. Remediate or approve a time-bound exception.
  6. Verify the finding is closed and the control remains healthy.
Exam signal: A dashboard is not a posture process. Choose designs with ownership, prioritization, remediation, verification, and governance.

Exam Focus Points
  • Defender for Cloud assesses supported hybrid and multicloud posture
  • Azure Arc extends management to supported resources outside Azure
  • EASM supplies an outside-in view of internet-visible assets
  • Attack paths prioritize reachable impact, but remediation still needs an owner and verification
Knowledge Check

1. Which capability is designed to discover an organization's internet-visible assets from an outside-in perspective?