This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of enabling and configuring workload protection plans in Microsoft Defender for Cloud.
Your organization deploys Azure OpenAI Service and Azure AI Model Inference service to power a customer-facing assistant. Which Defender for Cloud plan provides real-time threat protection against prompt injection and jailbreak attacks targeting these AI applications?
Defender Cloud Security Posture Management (CSPM)
Defender for AI Services
Defender for App Service
Defender for Resource Manager
You enable Defender for Storage on a subscription containing five Azure Blob Storage accounts. Which statement correctly describes the protection layers and their costs?
Activity monitoring starts automatically for all storage accounts when the plan is enabled; malware scanning is a configurable add-on charged per gigabyte of data scanned.
Activity monitoring requires you to enable diagnostic logs on each storage account before threat detection begins.
Malware scanning is included at no extra cost as part of the base Defender for Storage plan.
Sensitive data threat detection requires a separate Defender CSPM plan to be enabled on the subscription.
Contoso Financial Services needs to enable just-in-time (JIT) VM access and file integrity monitoring on a group of production servers to meet their internal security policy. Which Defender for Servers plan provides both of these features?
Plan 1 (P1)
Plan 2 (P2)
Either Plan 1 or Plan 2—both plans include just-in-time VM access and file integrity monitoring.
Foundational CSPM—these features are part of posture management and don't require a CWPP plan.
After enabling Defender plans across 14 subscriptions in a management group, your CISO asks for a consolidated report showing exactly which protection plans are active for each subscription. Which Defender for Cloud capability provides this view?
Regulatory compliance dashboard
Cloud Security Explorer
Coverage workbook
Microsoft Defender XDR incidents dashboard
You want to protect a specific virtual machine with Defender for Servers Plan 2 without enabling Plan 2 for the entire subscription. Which statement accurately describes this option?
Plan 2 can be enabled at the resource level for individual virtual machines in the Azure portal.
Plan 2 must be enabled at the subscription level; you can then disable it for specific resources to exclude them from protection.
Plan 2 can be enabled at the resource level using the Azure REST API, even if it can't be enabled through the portal.
Both Plan 1 and Plan 2 support full enable and disable operations at the individual resource level.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?