AZ-500 Question 230
Select 2Your organization hosts workloads in both AWS and GCP and wants to unify threat protection and security posture management across these environments using Microsoft Defender for Cloud. Which TWO actions should you perform to ensure comprehensive security monitoring and recommendations for these multi-cloud resources?
- A
Configure AWS Config and GCP Cloud Logging to send security data directly to Microsoft Defender for Cloud without any additional steps.
- B
Enable and configure the AWS and GCP connectors in Microsoft Defender for Cloud, specifying the required roles and enabling AWS Security Hub or GCP Security Command Center as appropriate.
- C
Deploy only an agent-based approach on each virtual machine in AWS and GCP, bypassing the native cloud integrations in Microsoft Defender for Cloud.
- D
Use Azure Arc to onboard non-Azure servers running in AWS or GCP, then configure Microsoft Defender for Cloud to provide advanced threat detection and management across these workloads.
Show answer and explanation
Correct answers: B, D
Explanation
To fully integrate AWS and GCP resources with Microsoft Defender for Cloud, you must configure the built-in connectors for posture management and threat detection. Additionally, for VM-based workloads in these clouds, Azure Arc agents help unify server monitoring. Together, these steps enable Microsoft Defender for Cloud to provide a consolidated view of security recommendations, threat alerts, and compliance posture across hybrid and multi-cloud environments. For more details, refer to the official documentation: https://learn.microsoft.com/azure/defender-for-cloud/connect-multicloud
- A. Incorrect.
Option 1 is incorrect because simply configuring AWS Config and GCP Cloud Logging to forward data does not fully integrate AWS and GCP environments with Microsoft Defender for Cloud. Native connectors or Azure Arc must be used to establish the necessary security visibility and recommendations.
- B. Correct.
Option 2 is correct. The recommended method for monitoring multiple clouds in Microsoft Defender for Cloud is using the built-in connectors. By enabling and configuring the AWS connector (with AWS Security Hub) and the GCP connector (integrating with GCP Security Command Center), you establish the required permissions and data flows for continuous security assessment and threat detection.
- C. Incorrect.
Option 3 is incorrect because relying solely on agent-based deployments ignores the full posture management capabilities provided by the native multi-cloud connectors. Although agents can provide some insights, they do not replace or replicate the broader posture management that the connectors offer.
- D. Correct.
Option 4 is correct. For server workloads, Azure Arc is used to onboard non-Azure servers (for example, EC2 instances in AWS or VMs in GCP) into Microsoft Defender for Cloud. This approach provides integrated threat protection, security monitoring, and centralized management for these servers in conjunction with the native AWS/GCP connectors.