Defender for Cloud Protected Resources
You have an Azure subscription that contains the resources shown in the following table. You plan to implement Microsoft Defender for Cloud. Which resources can be protected by using Defender for Cloud? - 
Community Votes
100% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Defender for Cloud provides a unified security posture management and threat protection layer across various Azure resource types, not just compute or storage.
This question tests knowledge of which Azure resources are supported by Microsoft Defender for Cloud. The correct answer is E because Defender covers VMs, Storage, Key Vaults, and Virtual Networks.
Many learners select options that exclude VNet1, mistakenly believing Defender only protects data planes (Storage/Key Vault) or compute (VM), ignoring network-level protections like Just-in-Time access and advanced threat protection for virtual networks.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Cloud is a comprehensive solution that secures cloud workloads across hybrid environments. It supports a wide range of Azure resources including Virtual Machines (VM1), Storage Accounts (storage1), Key Vaults (Vault1), and Virtual Networks (VNet1). Specifically, Defender for Cloud offers features like Just-in-Time (JIT) VM access, vulnerability assessment for VMs and SQL, continuous export, and workload protectors for storage and key vaults. Additionally, it monitors network traffic and configurations within VNets to detect threats. Therefore, all listed resources can be protected.Why the Other Options Are Wrong
Options A, B, C, and D are incorrect because they arbitrarily exclude certain resource types. For instance, excluding VNet1 (as in option D) ignores the fact that Defender for Cloud includes network security monitoring and JIT access which relies on VNet configuration. Excluding VM1 (as in option C) ignores the core compute protection capabilities. Since Defender for Cloud is designed to be a centralized security hub for the entire subscription, limiting its scope to only specific resource types contradicts its fundamental architecture.Community Comment Notes
The community consensus strongly favors option E. As user obaemf noted, referencing official Microsoft documentation, network resources are indeed protected. Another user, rv_sharma24, confirmed that "Network Resources are protected," aligning with the understanding that VNet1 is included. The high vote count for E indicates broad agreement among learners that Defender's coverage is extensive.Official Reference
Exam Strategy
When studying Defender for Cloud, remember that it acts as a central security hub. Don't limit your thinking to just 'antivirus' or 'firewall'; think about posture management, threat detection, and compliance across ALL resource types connected to the subscription.
Frequently Asked Questions
Does Defender for Cloud protect Virtual Networks?
Yes, Defender for Cloud monitors network traffic and configurations within Azure Virtual Networks to detect anomalies and threats.
Can I use Defender for Cloud with Azure Key Vault?
Yes, Defender for Cloud provides threat protection for Key Vaults, detecting unusual access patterns and potential vulnerabilities.