After creating a Microsoft Defender EASM instance, the next step is to import your organization's seeds to begin asset discovery

Manage security posture by using Microsoft Defender for Cloud
Answer Correct answer: D — Import seeds from your organization after creating the Defender EASM instance to start external attack-surface discovery.

You have an Azure subscription. You plan to deploy Microsoft Defender External Attack Surface Management (Defender EASM) to identify and monitor externally facing assets. You create a new Defender EASM instance named EASM1. What should you do next?

  1. Create a custom attack surface.
  2. Add a Log Analytics workspace.
  3. Add a discovery group.
  4. Import seeds from an organization. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

EASM discovery is seed-driven: you provide known assets (seeds) and the service expands to discover connected entities. Creating a discovery group or custom attack surface comes after seeds are established.

Defender External Attack Surface Management (EASM) discovers externally facing assets by recursively scanning known 'seed' assets. After you create the EASM instance, you import seeds (your organization's known domains, IPs, etc.) so discovery can expand outward.

Some think you first create a discovery group or custom attack surface, but the documented next step after provisioning the instance is to import seeds from your organization to kick off discovery.

Community Discussion (6 comments)

husam421 👍 6 Selected: D
Given answer is correct https://learn.microsoft.com/en-us/azure/external-attack-surface-management/what-is-discovery
Viggy1212 👍 1 Selected: D
To create a comprehensive mapping of your organization’s attack surface, the system first intakes known assets (known as "seeds") that are recursively scanned to discover more entities through their connections to a seed. From, https://learn.microsoft.com/en-us/azure/external-attack-surface-management/what-is-discovery
Koekjesdoos_111 👍 1 Selected: C
It's D, first you create a Discovery group and then u add the seed
pentium75 👍 1
Wouldn't I need to create a custom attack surface (A) and add a discovery group (C) BEFORE I can import seeds (D)?
Jimmy500 👍 1
Correct!
leleontop 👍 1
Correct. See: https://jeffreyappel.nl/how-to-use-microsoft-defender-easm-external-attack-surface-management/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Defender EASM builds its inventory by ingesting known assets called 'seeds' and then recursively scanning their connections to discover more entities. The official onboarding flow is: create the EASM instance, then import seeds from your organization so discovery can begin. (Option D)

Why the Other Options Are Wrong

  • Option A (Create a custom attack surface) is a later configuration step, not the immediate next action after instance creation.
  • Option B (Add a Log Analytics workspace) is not required to start EASM discovery; EASM has its own data store.
  • Option C (Add a discovery group) organizes seeds but you still must import the seeds themselves; importing seeds is the action that initiates discovery.

Community Comment Notes

Top comment cited the Microsoft 'what-is-discovery' article: 'the system first intakes known assets (known as seeds) that are recursively scanned,' confirming D with 88 community votes.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide