Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
03Microsoft Defender for Cloud6 modules · 48 units · 4 hr 17 min · Cloud security posture, multicloud onboarding, workload protection, alerts, and response0/48 units complete
Learning path 03 · Microsoft Defender for Cloud

6 modules · 48 units · 4 hr 17 min · Cloud security posture, multicloud onboarding, workload protection, alerts, and response

0%

Study focus

Cloud posture and coverage

Connect Azure and hybrid resources, extend multicloud coverage, and manage cloud security posture.

Workload threat response

Enable workload protections, investigate alerts, and remediate risks across cloud resources.

6 modules · 48 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

05

Module 5

Explain cloud workload protections in Microsoft Defender for Cloud

Focus: workload-specific protection plans, telemetry sources, detection coverage, and investigation context.
0/13
01 / 13Introduction

Cloud workload protection applies threat detection tuned to the service being protected. Each Defender plan uses workload-native signals, Microsoft threat intelligence, and behavioral analytics to detect different attack paths.

Official moduleWorkload protection objectives
02 / 13Understand Microsoft Defender for Servers
PlanCore coverage
Plan 1MDE automatic onboarding, endpoint detection and response, security alerts, and vulnerability assessment.
Plan 2Plan 1 plus agentless discovery, vulnerability and malware scanning, secrets discovery, security baselines, OS-update assessment, file integrity monitoring, just-in-time VM access, network map, and additional detections.

Coverage can extend to Azure VMs, Azure Arc-enabled servers, and supported multicloud machines.

Official lessonDefender for Servers plans
03 / 13Understand Microsoft Defender for App Service

Defender for App Service provides Azure-native, agentless protection for supported App Service workloads. It analyzes platform and application signals, inbound requests, and management operations to detect web attacks, suspicious access, and post-exploitation behavior.

Official lessonApp Service runtime protection
04 / 13Understand Microsoft Defender for Storage

Defender for Storage protects Azure Blob Storage, Azure Files, and Data Lake Storage against suspicious access, data exfiltration, permission changes, and malicious uploads. Malware reputation based on file hashes is not the same as inspecting file contents; configure current malware-scanning capabilities when content scanning is required.

Official lessonStorage threat detection
05 / 13Understand Microsoft Defender for SQL

Defender for SQL combines vulnerability assessment with advanced threat protection for Azure SQL Database, Managed Instance, Synapse SQL, and SQL servers on machines. Detections include SQL injection, anomalous access, brute force, privilege abuse, and suspicious query behavior.

Official lessonSQL assessment and threat protection
06 / 13Understand Microsoft Defender for open-source databases

Defender for open-source relational databases monitors supported PostgreSQL, MySQL, and related database services for unusual access, anomalous queries, brute-force attempts, suspicious applications, and potentially compromised credentials.

Official lessonOpen-source database detections
07 / 13Understand Microsoft Defender for Key Vault

Defender for Key Vault detects unusual or potentially harmful attempts to access keys, secrets, and certificates. Alerts include context such as user principal, source IP, operation, and object ID. A familiar identity or application does not automatically make anomalous access benign.

Official lessonKey Vault anomaly detection
08 / 13Understand Microsoft Defender for Resource Manager

Defender for Resource Manager analyzes Azure control-plane operations made through the portal, API, CLI, or automation. It can identify suspicious source IPs, antimalware disabling, malicious VM extensions, tools such as PowerZure or MicroBurst, and lateral movement from control plane to data plane.

Investigate the alert together with the Azure Activity Log, identity sign-in data, affected resource configuration, and any subsequent data-plane actions.

Official lessonControl-plane threat detection
09 / 13Understand Microsoft Defender for DNS

DNS telemetry reveals attempted communication even when payload traffic is encrypted. Defender for DNS identifies tunneling, command-and-control infrastructure, malicious or phishing domains, cryptomining destinations, and suspicious resolvers.

Official lessonDNS-based detections
10 / 13Understand Microsoft Defender for Containers

Defender for Containers covers supported AKS, EKS, and Arc-enabled Kubernetes environments. It combines cluster hardening recommendations, image vulnerability assessment, Kubernetes policy, node and control-plane signals, audit logs, and runtime detections.

  • Find vulnerable images in registries and identify where they are running.
  • Assess cluster configuration and admission-policy compliance.
  • Detect suspicious commands, privilege escalation, exposed dashboards, and anomalous API activity.
Official lessonContainer posture and runtime protection
11 / 13Understand Microsoft Defender additional protections

Additional coverage can include network-layer analytics based on flow data, Defender for Cosmos DB, Web Application Firewall alerts, DDoS Protection alerts, and Defender for Cloud Apps integration. These signals enrich investigations across identity, application, network, and data layers.

Official lessonNetwork, data, WAF, and DDoS protections
12 / 13Module assessment

Match each workload to its telemetry and detections: server endpoint signals, App Service platform logs, storage operations, database queries, Key Vault object access, ARM control-plane operations, DNS queries, or Kubernetes audit/runtime data.

Official assessmentWorkload protection knowledge check
13 / 13Summary and resources

Select workload plans according to deployed services, risk, and required detection depth. Investigate alerts with the service-native logs and entity context appropriate to that workload.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Cloud