Selecting Defender for Resource Manager and Defender for DevOps to mitigate source-code, template, malicious-IP, and secret risks

Topic 5
Answer Correct answer: A, E — Defender for DevOps scans source code and IaC templates; Defender for Resource Manager detects malicious-IP operations and exposed secrets.

You have an Azure subscription that uses Microsoft Defender for Cloud. You need to configure Defender for Cloud to mitigate the following risks: • Vulnerabilities within the application source code • Exploitation toolkits in declarative templates • Operations from malicious IP addresses • Exposed secrets Which two Defender for Cloud services should you use? Each correct answer presents part of the solution. NOTE: Each correct answer is worth one point.

  1. Microsoft Defender for Resource Manager Correct Answer
  2. Microsoft Defender for DNS
  3. Microsoft Defender for App Service
  4. Microsoft Defender for Servers
  5. Microsoft Defender for DevOps Correct Answer

Community Votes

AE
80%
BE
20%

80% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Defender for DevOps scans application source code and infrastructure-as-code (declarative) templates, while Defender for Resource Manager detects suspicious operations from malicious IP addresses and exposed secrets in deployments, together covering all four stated risks.

To mitigate source-code vulnerabilities, exploitation toolkits in declarative templates, malicious-IP operations, and exposed secrets in Defender for Cloud, use Defender for DevOps (code and IaC scanning) and Defender for Resource Manager (malicious-IP operations and exposed secrets).

Picking Defender for DNS or Defender for App Service — DNS monitors DNS traffic and App Service protects web apps, neither of which scans source code, IaC templates, or detects exposed secrets and malicious-IP Resource Manager operations.

Community Discussion (6 comments)

Shaddy43 👍 20
Correct Answer A, E A: Microsoft Defender for Resource Manager handles (exploitation toolkits, operations from Malicious IP, Exposed secrets) https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-resource-manager-introduction E: Microsoft Defender for DevOps handle (vulnerabilities within application source code) https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-devops-introduction
renrenren 👍 8 Selected: AE
I think correct. https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-resource-manager-introduction#what-are-the-benefits-of-microsoft-defender-for-resource-manager https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-devops-introduction
g_man_rap 👍 2 Selected: BE
Correct Answers: E. Microsoft Defender for DevOps: This service directly mitigates vulnerabilities within the application source code, exploitation toolkits in declarative templates, and exposed secrets. B. Microsoft Defender for DNS: This service helps mitigate operations from malicious IP addresses by monitoring DNS traffic for signs of malicious activity.
laddu001 👍 1
Microsoft Defender for App Service: This service helps protect your web applications by monitoring for common web app attacks and identifying emerging threats. Microsoft Defender for Servers: It helps defend against vulnerabilities, malware, and other threats targeting servers in your environment.
ServerBrain 👍 1 Selected: AC
To mitigate the specified risks using Microsoft Defender for Cloud, you should use the following services: Microsoft Defender for Resource Manager (Azure Defender): This service provides protection against vulnerabilities within the application source code and exploitation toolkits in declarative templates. It helps secure your Azure resources by identifying and remediating security issues. Azure Defender integrates with Azure Security Center and provides advanced threat protection for Azure resources Microsoft Defender for App Service: This service helps protect your web applications hosted on Azure App Service. It can detect and block malicious traffic, including operations from malicious IP addresses. By securing your App Service, you reduce the risk of exposure to attacks and unauthorized access
oricgoldfinger 👍 1 Selected: CE
To mitigate the risks you’ve mentioned, you should use: C. Microsoft Defender for App Service: This service provides protection against vulnerabilities within the application source code and operations from malicious IP addresses. It also helps in identifying and mitigating exposed secrets. E. Microsoft Defender for DevOps: This service helps in scanning your declarative templates for exploitation toolkits and other potential vulnerabilities. It also helps in identifying and mitigating exposed secrets in your DevOps pipeline. So, the correct answers are C and E. Each of these services addresses different aspects of your security needs and together they provide a comprehensive solution. Remember, security is a multi-layered approach and often requires multiple services working together to provide the best protection.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for DevOps secures application source code and infrastructure-as-code templates, addressing the source-code vulnerabilities and exploitation toolkits in declarative templates. Microsoft Defender for Resource Manager detects suspicious Resource Manager operations originating from malicious IP addresses and flags exposed secrets, covering the remaining two risks.

Why the Other Options Are Wrong

Defender for DNS (B) monitors DNS traffic for malicious activity but does not scan code or templates or detect exposed secrets. Defender for App Service (C) protects web applications against attacks. Defender for Servers (D) protects server workloads. None of these covers source-code/IaC scanning or Resource Manager malicious-IP and secret exposure.

Community Comment Notes

Shaddy43 (20 likes) and renrenren both cite the official docs (https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-resource-manager-introduction and defender-for-devops-introduction) confirming AE as the answer. g_man_rap argues BE, but Defender for DNS does not scan source code or declarative templates, which is the core of the first two risks.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide