Which Azure solution should you use to map external infrastructure and perform vulnerability scanning for ASNs, hostnames, IP addresses, and SSL certificates?
Choose an answer
Tap an option to check your answer.
Correct answer: Microsoft Defender External Attack Surface Management (Defender EASM).
Why this is the answer
Microsoft Defender External Attack Surface Management (Defender EASM) is the correct choice because it specializes in discovering and mapping an organization's external attack surface. It actively scans for internet-facing assets like ASNs, hostnames, IP addresses, and SSL certificates, identifying unknown or unmanaged resources and potential vulnerabilities. This helps organizations understand their exposure from an attacker's perspective. Microsoft Defender for Cloud provides cloud security posture management and workload protection for Azure, multi-cloud, and hybrid environments, but its primary focus isn't external asset discovery of this nature. Microsoft Defender for Identity monitors identity-related threats and anomalous user behavior. Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices. Neither of these solutions is designed for comprehensive external infrastructure mapping and vulnerability scanning across ASNs, hostnames, and IP addresses.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed