Microsoft Defender External Attack Surface Management flags an expired TLS certificate on a public marketing site for the lock authority. How should the Azure security engineer classify that finding?
Select an answer to reveal the explanation.
Short Explanation
Expired cert on the public brochure site is Internet surface dirt—not a guest OS CVE on some Azure VM. Fix the external hygiene; don’t pretend EASM just invented a Servers Vulnerability Management ticket.
Full Explanation
EASM findings describe the organization’s external attack surface, such as expired TLS on a public marketing site. They are not automatically Microsoft Defender Vulnerability Management findings on Azure virtual machines, nor disk-encryption or storage malware-scan issues. Treat EASM as external-surface hygiene distinct from CWPP vulnerability management on known cloud workloads.