On the same Microsoft Defender for Cloud blade, the lock-lab team sees a “secure transfer required” recommendation and a “crypto-mining on VM” alert. How should the Azure security engineer treat them?
Select an answer to reveal the explanation.
Short Explanation
One is a smoke alarm, one is a house-inspection note. Jump on the crypto-mining alert like a live threat, and fix “secure transfer required” as posture work—don’t mix those lanes up.
Full Explanation
In Microsoft Defender for Cloud, recommendations express configuration posture, while alerts indicate detected threats or suspicious activity. Crypto-mining on a VM is an active threat that requires immediate alert response; enabling secure transfer is a posture remediation. Treating both as the same class of work, or prioritizing a recommendation over an active High alert, confuses monitoring response with Secure Score hygiene.