Uploads to a public lock-photo container must be scanned for malware on ingest. What should the Azure security engineer configure first?
Select an answer to reveal the explanation.
Short Explanation
Public photo drops need the Storage malware-scan add-on on ingest—not a random AV VM chewing blob mounts. Flip the Defender for Storage malware scanning option on the accounts that take uploads.
Full Explanation
Malware scanning is an official add-on capability on Microsoft Defender for Storage and should be enabled for accounts that accept uploads requiring on-ingest scanning. A third-party antivirus VM or only Defender for Servers antimalware on other machines is not the first AZ-500 answer for storage ingest scanning. Disabling public access may reduce exposure but does not configure the Storage malware-scan add-on.