Unusual anonymous enumeration and a hash-reputation hit appear on lock-photo blobs. What should the Azure security engineer enable so those storage threat alerts fire?
Select an answer to reveal the explanation.
Short Explanation
Weird anonymous poking and bad-hash blobs need Defender for Storage watching the account. Rotating keys or redesigning SAS is access hygiene—it does not light up those threat alerts by itself.
Full Explanation
Microsoft Defender for Storage provides threat detection for storage accounts, including alerts such as unusual anonymous enumeration and hash-reputation matches on blobs. Access-key rotation and SAS design are Domain 3 access controls and do not replace enabling the Storage plan. Sentinel can receive alerts later but is not a substitute for enabling Defender for Storage on the accounts.