あなたはある組織のセキュリティアナリストです。会社では最近、クラウド導入戦略を開始し、Azure Container Registry における Linux イメージの脅威検出に関する懸念が生じています。 Azure Container Registry と統合して、レジストリにプッシュされたすべての Linux イメージを自動的にスキャンできる Microsoft クラウド ネイティブ ソリューションはどれですか (2 つ選択)。
正解:A,D
Option A is correct because once you Enable Microsoft Defender for Containers, Microsoft Defender for Cloud will automatically scan all Linux images pushed to the registry. Option B is incorrect because Twistlock Enterprise Edition is a security suite for protecting container platforms like Docker and Kubernetes but is not native to Azure. Option C is incorrect because Azure Logic Apps, Will enable organizations to create workflows by integrating various Azure services, including Azure Container Registry, but it would not provide the security scanning of images pushed to the registry Option D is correct because Defender for Cloud gathers data from your Azure virtual machines (VMs), Virtual machine scale sets, IaaS containers, and non-Azure computers (including on- premises machines) to examine for security vulnerabilities and threats. Data is compiled using the Log Analytics agent, which reads various security-related patterns and event logs from the machine and copies the data to your Log Analytics Workspace for analysis. You need a Log Analytics Workspace to enable Microsoft Defender for the cloud. Reference: https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction