AZ-700 exam dumps

AZ-700 practice question 78 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 78

Single answer

You are a cloud administrator for an organization that recently enabled Microsoft Defender for Cloud across multiple subscriptions. Your team wants to identify all Azure network resources (such as virtual networks and subnets) from a single pane of glass. Which action should you take in Microsoft Defender for Cloud to list and examine these network resources using Security Explorer?

  1. A

    Enable Microsoft Defender for Cloud on every subscription and filter by 'Network' in Security Explorer.

  2. B

    Use Azure Resource Graph queries to discover network resources and import the CSV results into Security Explorer.

  3. C

    Configure custom detections in Microsoft Defender for Cloud to directly scan all subnets in each VNET.

  4. D

    Create an Azure Policy for network resources in each subscription and rely on Compliance blade data.

Show answer and explanation

Correct answer: A

Explanation

Microsoft Defender for Cloud� Security Explorer consolidates resource visibility across enabled subscriptions, allowing you to filter and inspect specific resource types�such as network resources�for security and compliance. By enabling Microsoft Defender for Cloud on each subscription, you ensure Security Explorer can accurately list all network assets. For more information, see Microsoft Defender for Cloud documentation on Security Explorer: https://learn.microsoft.com/azure/defender-for-cloud/security-explorer.

  • A. Correct.

    Option 1 is correct. When Microsoft Defender for Cloud is enabled on each subscription, the Security Explorer will automatically discover resources within those subscriptions. You can then filter by the 'Network' category within Security Explorer to list all relevant network items (e.g., virtual networks, subnets). This leverages Defender for Cloud� built-in inventory features to provide a consolidated view.

  • B. Incorrect.

    Option 2 is incorrect. While Azure Resource Graph queries can help you discover and list Azure resources (including network resources), these results are not automatically imported into Security Explorer. You would still need to rely on Defender for Cloud� native resource discovery to have them appear within the Security Explorer interface.

  • C. Incorrect.

    Option 3 is incorrect. Custom detections typically refer to defining security alerts or anomaly detections, not enumerating all network resources. Although Defender for Cloud offers various detection capabilities, they do not serve as a tool for listing all subnets in every virtual network in real time.

  • D. Incorrect.

    Option 4 is incorrect. Azure Policy helps enforce or assess compliance against defined standards, but it does not directly feed data into Security Explorer. While compliance data can highlight misconfigurations, it does not provide the consolidated resource listings that Security Explorer offers.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam