certslothcertsloth
SC-500/Topic 09

Azure / Associate

Defender, Key Vault and Preventive Controls

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Posture finds exposure; workload protection detects threats; prevention still needs correctly scoped policy.

Must remember

  • Distinguish app registrations (application definitions) from enterprise applications/service principals (tenant instances). OAuth delegated/application permissions and consent have different implications. Review grants, publisher trust, owners and overprivileged roles; use PIM and Conditional Access where appropriate.
  • Key Vault separates keys, secrets and certificates. Configure its authorisation model, network access, soft delete/purge protection and lifecycle deliberately. Rotation needs compatible clients and recovery planning. Defender for Key Vault and CSPM secret discovery provide different detection capabilities.
  • Defender for Cloud CSPM assesses posture and attack paths; workload protection plans cover supported services. Enable the required plans and connectors rather than assuming every workload is protected by default. Regulatory-compliance views organise evidence, not automatic legal certification.
  • For servers, use supported trusted-launch/secure-boot/vTPM/integrity features, encryption, JIT access and Bastion. Arc brings supported hybrid/multicloud resources into management; Defender for Servers supports vulnerability/EDR and agentless capabilities according to plan/configuration. Machine Configuration evaluates/enforces supported guest baselines.
  • Protect containers with image/runtime assessment, registry restrictions, workload identity, Kubernetes RBAC/network controls and secure configuration. Secure Functions, Logic Apps and App Service using identities, authentication and network restrictions. API Management policies and WAF protect different application boundaries.
  • Secure storage and SQL with identity/data permissions, firewalls/private endpoints, encryption, auditing and appropriate Defender plans. Network Manager/security admin rules, Firewall, Virtual WAN controls and Entra Private Access serve distinct access/inspection needs; verify effective rules and routes.
  • EASM discovers externally visible assets/exposure; vulnerability management identifies supported weaknesses. Connect AWS/GCP environments through supported Defender connectors with scoped permissions. Remediation should prioritise exploitable paths and business impact, then verify the fix.

Choose under exam pressure

Requirement Choice and reason
Find risky combinations of permissions and exposure CSPM/attack-path analysis with workload context.
Limit administrative port exposure JIT and controlled access such as Bastion.
Detect unexpected public assets External Attack Surface Management.

Traps

  • Enabling one Defender plan does not enable all protection.
  • Compliance score is not proof of complete security.
  • A secret rotation can break clients if retrieval/cache behaviour is ignored.

Active recall

1. What differs between an app registration and a service principal?

The application definition versus its identity instance in a tenant.

2. Why review OAuth consent?

An application can receive significant delegated or application access independent of a user's ordinary resource workflow.

3. What does Arc add?

Supported management/governance integration for resources outside native Azure deployment.

4. Why combine posture and runtime evidence?

Exposure shows potential paths; runtime evidence shows observed behaviour and threats.

5. What should follow remediation?

Re-evaluation of effective access/configuration and confirmation that the application still operates safely.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.