Several VMs behind NSGs allow broad inbound access from the Internet. You want to minimize exposed ports using Defender for Cloud intelligence and apply the tightened rules directly to the NSGs. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: From Defender for Cloud, open Adaptive network hardening, review the recommended NSG inbound rules per VM/subnet, and apply the hardening recommendations to update the NSGs..
Why this is the answer
Adaptive network hardening in Defender for Cloud analyzes network traffic patterns and security intelligence to provide recommendations for tightening Network Security Group (NSG) rules. This feature directly addresses the goal of minimizing exposed ports by suggesting specific, more restrictive inbound rules based on actual usage, and allows you to apply these recommendations directly to the NSGs. Replacing NSGs with Azure Firewall is a valid security enhancement but doesn't directly use Defender for Cloud's intelligence to tighten existing NSG rules. Azure DDoS Standard protects against DDoS attacks, not against broad inbound access from the internet. Adding an NSG rule for RFC1918 sources would block all internet access, which is likely too restrictive for VMs that need some internet exposure. Creating an Azure Policy to deny broad NSG rules is a governance measure, not a direct way to apply intelligent hardening recommendations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed