Shadow lock-lab DNS and a forgotten public IP never appear in Defender for Cloud Inventory. Which capability should the Azure security engineer use to discover what the Internet can already see?
Select an answer to reveal the explanation.
Short Explanation
Inventory only knows what you already parked in the cloud. EASM walks the public Internet from your org, domain, or IP seeds and lights up the shadow DNS and forgotten public IP nobody owned.
Full Explanation
Microsoft Defender External Attack Surface Management discovers Internet-facing assets from organization, domain, or IP seeds—including shadow DNS and forgotten public IPs that Defender for Cloud Inventory does not list because they are not known cloud resources. Sentinel UEBA and Bastion address different problems and do not replace EASM discovery.