The first Microsoft Defender External Attack Surface Management run for the canal authority is noisy with candidate assets. What should the Azure security engineer configure next at security-engineer depth?
Select an answer to reveal the explanation.
Short Explanation
First EASM sweep always looks like a junk drawer. Plant the official seeds—domains, WHOIS, IP blocks—then separate confirmed assets from the maybe pile so ops is not chasing ghosts.
Full Explanation
EASM setup requires configuring discovery seeds (domains, WHOIS, IP blocks recognized as authoritative for the organization) and then triaging discovered inventory into confirmed versus candidate assets. Turning EASM off, skipping seeds for Security Copilot chat, or forcing Azure Policy compliance on unconfirmed hosts does not implement EASM at associate security-engineer depth.