Selecting Defender for Resource Manager and Defender for DevOps to mitigate source-code, template, malicious-IP, and secret risks
You have an Azure subscription that uses Microsoft Defender for Cloud. You need to configure Defender for Cloud to mitigate the following risks: • Vulnerabilities within the application source code • Exploitation toolkits in declarative templates • Operations from malicious IP addresses • Exposed secrets Which two Defender for Cloud services should you use? Each correct answer presents part of the solution. NOTE: Each correct answer is worth one point.
Community Votes
80% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Defender for DevOps scans application source code and infrastructure-as-code (declarative) templates, while Defender for Resource Manager detects suspicious operations from malicious IP addresses and exposed secrets in deployments, together covering all four stated risks.
To mitigate source-code vulnerabilities, exploitation toolkits in declarative templates, malicious-IP operations, and exposed secrets in Defender for Cloud, use Defender for DevOps (code and IaC scanning) and Defender for Resource Manager (malicious-IP operations and exposed secrets).
Picking Defender for DNS or Defender for App Service — DNS monitors DNS traffic and App Service protects web apps, neither of which scans source code, IaC templates, or detects exposed secrets and malicious-IP Resource Manager operations.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for DevOps secures application source code and infrastructure-as-code templates, addressing the source-code vulnerabilities and exploitation toolkits in declarative templates. Microsoft Defender for Resource Manager detects suspicious Resource Manager operations originating from malicious IP addresses and flags exposed secrets, covering the remaining two risks.Why the Other Options Are Wrong
Defender for DNS (B) monitors DNS traffic for malicious activity but does not scan code or templates or detect exposed secrets. Defender for App Service (C) protects web applications against attacks. Defender for Servers (D) protects server workloads. None of these covers source-code/IaC scanning or Resource Manager malicious-IP and secret exposure.Community Comment Notes
Shaddy43 (20 likes) and renrenren both cite the official docs (https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-resource-manager-introduction and defender-for-devops-introduction) confirming AE as the answer. g_man_rap argues BE, but Defender for DNS does not scan source code or declarative templates, which is the core of the first two risks.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →