certslothcertsloth
SC-100/Topic 04

Microsoft / Expert

Infrastructure, exposure and network security

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Posture reduces exposure; protection detects abuse.

Must remember

  • Defender for Cloud combines supported posture management and workload protection. Connect hybrid/multicloud resources through the appropriate integrations, including Azure Arc where relevant; verify plan/agent requirements.
  • Secure Score, exposure management, attack paths and external attack-surface discovery help prioritize risk. Distinguish known inventory from internet-discovered assets and confirm ownership before remediation.
  • Harden servers and clients with baselines, patching, endpoint protection and Windows LAPS. Use Intune/other supported management for devices; OT/ICS and IoT need specialized safety and availability constraints.
  • Protect containers through trusted images, registry controls, admission/deployment policy, workload identity, runtime monitoring and network segmentation. A secure host does not automatically secure every container permission.
  • SaaS, PaaS and IaaS have different shared-responsibility boundaries. Evaluate web, AI service, database and orchestration controls at the service’s actual exposed interfaces.
  • Entra Internet Access addresses supported secure web access; Entra Private Access addresses access to private applications. SSE complements network design, firewalls, DDoS protection and private endpoints rather than eliminating all other controls.

Choose under exam pressure

Requirement Choice and reason
Unknown internet-facing assets may belong to the company External attack-surface discovery followed by ownership validation.
Remote users need identity-aware private-app access Evaluate Entra Private Access with application and device policies.

Traps

  • A posture score is a prioritization aid, not a guarantee of security.
  • Aggressive scanning or patching can be unsafe for sensitive OT systems without operational coordination.

Active recall

1. How do CSPM and workload protection differ?

CSPM assesses configuration/exposure; workload protection detects/protects supported running workloads.

2. Why use attack paths?

To prioritize combinations of weaknesses that can reach high-impact assets.

3. What does Windows LAPS reduce?

Risk from reused or unmanaged local administrator passwords.

4. Why secure container identity?

A small compromised container with broad permissions can affect much larger systems.

5. What should an SSE design preserve?

Strong identity/device policy, application access boundaries and visibility into allowed traffic.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.