Cyber Intelligence
Security Posture Management and Microsoft Sentinel · 20-25% of exam

L15. Managing Security Posture with Defender CSPM, Compliance & External Attack Surface Management

Video generating

Check back soon for the video lesson on Managing Security Posture with Defender CSPM, Compliance & External Attack Surface Management

Course outlineLesson 15 of 18
SC-500 Exam Prep: course overview

Defender CSPM answers what could go wrong inside your known environment, and Defender EASM answers the scarier question: what parts of your attack surface did you not even know existed.

Identifying Security Risks with Defender CSPM

Defender Cloud Security Posture Management (Defender CSPM) is the premium posture-management plan that goes beyond basic Secure Score recommendations:
  • Cloud security graph: models resources, their configurations, and their relationships (identities, network paths, data stores) as a connected graph rather than a flat resource list
  • Attack path analysis: uses that graph to identify actual exploitable chains, for example, an internet-exposed VM with a vulnerability, that has a managed identity, that has Contributor rights on a subscription containing a database with sensitive data, surfacing the *combination* of individually low-severity issues that together form a real attack path
  • Agentless scanning: for VMs, containers, and secrets (as covered in Lesson 3 and Lesson 13), providing coverage without deploying an agent everywhere

Evaluating Compliance Against Security Frameworks

As covered in Lesson 4, Defender for Cloud's regulatory compliance dashboard measures your environment against assigned standards continuously, not just at audit time, with every control traceable back to specific underlying recommendations and resources.

Enabling Workload Protection Plans

Defender for Cloud's protections are organized into per-resource-type workload protection plans that must be individually enabled: Defender for Servers, Storage, SQL/Databases, Key Vault, Containers, DNS, APIs, and others each turn on independently, so coverage should be reviewed resource-type by resource-type rather than assuming "Defender for Cloud is on" means everything is protected.

Multicloud and Hybrid Connectivity

Defender for Cloud connects to AWS and GCP through native cloud connectors, using each provider's own security services (like AWS Security Hub or GCP Security Command Center findings) alongside Azure-native signals, giving one unified posture view across all three clouds instead of three separate consoles. Auto-provisioning can automatically deploy the required agents/extensions to newly discovered resources in connected accounts as they appear, so coverage doesn't lag behind resource sprawl.

Configuring Defender Vulnerability Management

Microsoft Defender Vulnerability Management settings for Azure VMs provide continuous, agent-based (via Defender for Endpoint) discovery of software inventory, missing patches, and misconfigurations, going deeper than the periodic snapshot-based agentless vulnerability findings by continuously tracking a VM's exposed vulnerabilities as its installed software changes over time.

Discovering Unprotected Assets with Defender EASM

Microsoft Defender External Attack Surface Management (EASM) takes an explicitly outside-in view: it discovers internet-facing assets belonging to your organization the way an attacker doing reconnaissance would, including shadow IT never registered with central IT, forgotten subdomains, expired certificates on still-resolving hostnames, and third-party/subsidiary infrastructure connected to your brand. This is a fundamentally different discovery model from CSPM (which analyzes resources already known to be in your Azure/AWS/GCP subscriptions): EASM's entire value is surfacing what you didn't know was there in the first place. Exam tip: A scenario about "combining multiple individually low-risk findings into one exploitable chain" is Defender CSPM attack path analysis; a scenario about "discovering an internet-facing asset nobody in IT knew existed" is Defender EASM, since EASM operates entirely outside the boundary of what's already inventoried in your cloud subscriptions.

Exam Focus Points
  • Defender CSPM's cloud security graph models resource relationships to surface attack path analysis, chains of individually low-severity issues that combine into a real exploitable path
  • Workload protection plans (Servers, Storage, SQL, Key Vault, Containers, etc.) are each enabled independently; "Defender for Cloud is on" does not imply every resource type is protected
  • Defender for Cloud connects to AWS and GCP via native connectors, with auto-provisioning extending coverage to newly discovered resources automatically
  • Defender Vulnerability Management provides continuous, agent-based tracking of software inventory and missing patches, deeper than periodic agentless scans
  • Defender EASM discovers internet-facing assets from an outside-in, attacker's-eye view, including shadow IT never registered with central IT, a fundamentally different model from CSPM's analysis of already-known resources
Knowledge Check

1. A security team discovers a subdomain running an old, forgotten web application that nobody in IT knew was still online. Which capability is specifically designed to surface this kind of unknown, unregistered asset?

2. An internet-exposed VM has a vulnerability, carries a managed identity with Contributor rights on a subscription, and that subscription contains a database with sensitive data. Individually each finding is low severity. Which Defender CSPM capability identifies this as a combined exploitable chain?

3. A team assumes that because Defender for Cloud is enabled on their subscription, all their storage accounts and SQL databases are automatically protected. Why might this assumption be wrong?

Recommended: Pluralsight

This free course covers the theory. Pluralsight adds structured Cloud and AI Security Engineer learning paths, hands-on Azure and Defender for Cloud labs, and timed practice exams to make it stick before exam day.

Start SC-500 prep free10-day free trial · card required, cancel anytime before it renews