
Answer-first summary for fast verification
Answer: Microsoft Defender for Cloud
The best solution is Microsoft Defender for Cloud. It provides a secure score scoped to the landing zone, helps minimize data exfiltration, and meets the business requirement to minimize additional on-premises infrastructure and operational costs. Defender for Cloud offers advanced threat protection and security management capabilities that align well with the security needs of the landing zones. Given the requirement to have a secure score and centralize security operations with tools like Microsoft Sentinel, Defender for Cloud is the most appropriate solution.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
Litware, Inc. is a financial services company operating out of main offices in New York and San Francisco, with 30 branch offices and remote employees dispersed throughout the United States. The organization plans to establish a management group hierarchy for each Azure AD tenant, develop a landing zone strategy, and implement Azure AD Application Proxy to securely access internal applications. Litware's existing infrastructure includes an Azure AD tenant that synchronizes with an AD DS forest, multiple AD DS forests, various Azure AD tenants, and hundreds of Azure subscriptions. Key objectives include reducing on-premises infrastructure and operational costs, centralizing cross-tenant subscription management, enforcing compliance with Azure Policy, and using Microsoft Sentinel for security operations. The company also aims to detect brute force attacks, implement leaked credential detection, and delegate user and group management within Azure AD. The landing zone strategy must ensure routing all internet-bound traffic through Azure Firewall, securing communication between virtual machines and web apps over the Microsoft backbone network, minimizing data exfiltration, and delivering a secure score specific to the landing zone. Given these requirements, what configuration should be applied to secure each landing zone?
A
an ExpressRoute gateway
B
Microsoft Defender for Cloud
C
an Azure Private DNS zone
D
Azure DDoS Protection Standard
No comments yet.