This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of connecting hybrid and multicloud environments to Microsoft Defender for Cloud.
When you connect an AWS account to Microsoft Defender for Cloud, how does Defender for Cloud authenticate to AWS APIs?
It stores AWS access keys and secret keys in Azure Key Vault and uses them to call AWS APIs.
It uses the customer's Microsoft Entra service principal to call AWS APIs directly.
It creates IAM roles with a federated trust relationship through OIDC and authenticates using short-lived credentials from AWS Security Token Service.
It requires a dedicated IAM user with programmatic access enabled on the AWS account.
You connect an AWS account to Defender for Cloud with both Defender CSPM and Defender for Servers enabled. Which coverage becomes active within hours of connector creation, and which requires Azure Arc deployed on EC2 instances before it provides protection?
Both Defender CSPM and Defender for Servers become active immediately after the connector is created—no Arc agent is needed for either.
Defender for Servers activates immediately; Defender CSPM requires Arc agents on EC2 instances before posture recommendations appear.
Defender CSPM activates within hours of connector creation through agentless API calls; Defender for Servers runtime protection requires Azure Arc deployed on each EC2 instance.
Both Defender CSPM and Defender for Servers require Azure Arc on EC2 instances before any coverage becomes active.
When Defender for Cloud connects to a GCP project, what authentication mechanism does it use, and what does this mean for credential storage in Azure?
It downloads a GCP service account JSON key and stores it in Azure Key Vault for use in API calls.
It uses workload identity federation and service account impersonation—no private keys or long-lived credentials are stored in Azure.
It uses the customer's Microsoft Entra service principal to call GCP APIs directly, with no GCP-side resources required.
It creates a dedicated GCP IAM user with API key authentication and stores the key in the connector configuration.
After creating an AWS connector, you check Environment Settings and see 'Has issues' in the Connectivity status column. What does this status indicate, and how do you begin resolving it?
The connector is still establishing its initial connection. Wait 24 hours and the status change to Healthy automatically.
The connector detected configuration or permission problems. Select the status value to open the Environment details page, which lists specific issues and often provides remediation scripts.
The AWS account reached its API call quota. Contact AWS Support to increase the API call limit before the connector can function.
The CloudFormation stack deployed incorrectly. You must delete the connector and restart the onboarding process from the beginning.
A security engineer needs full Defender for Servers Plan 2 coverage on on-premises Windows servers, including just-in-time VM access, file integrity monitoring, and agentless scanning. What is required to enable these capabilities?
Install the Microsoft Monitoring Agent (MMA) on each server and connect it to a Log Analytics workspace linked to the Defender for Cloud subscription.
Enable Defender for Servers Plan 1 on the Azure subscription. Plan 1 includes all advanced protection features for on-premises machines without requiring any agent.
Deploy the Azure Connected Machine agent on each server to Arc-enable it, then enable Defender for Servers Plan 2 on the Azure subscription.
Create a native cloud connector for the on-premises environment in Defender for Cloud Environment Settings, the same way you would for AWS or GCP.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?