An organization is deploying an AI workload on Azure and wants to use Microsoft Defender for Cloud's AI security posture management capabilities. The security team needs to identify misconfigurations in their Azure OpenAI deployments. Which Defender for Cloud feature surfaces AI-specific security recommendations?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Defender CSPM (Cloud Security Posture Management) includes AI security posture management capabilities that discover AI resources across the estate and surface specific security recommendations for Azure OpenAI Service, such as disabling public network access, enabling customer-managed keys, and using private endpoints. B is wrong because Defender for DevOps focuses on security in CI/CD pipelines and code repositories, not runtime AI resource posture.
Full explanation below image
Full Explanation
A is correct because Defender CSPM (Cloud Security Posture Management) includes AI security posture management capabilities that discover AI resources across the estate and surface specific security recommendations for Azure OpenAI Service, such as disabling public network access, enabling customer-managed keys, and using private endpoints. B is wrong because Defender for DevOps focuses on security in CI/CD pipelines and code repositories, not runtime AI resource posture. C is wrong because the Cloud Security Benchmark is a set of standards, not a posture management engine that surfaces per-resource recommendations. D is wrong because the regulatory compliance dashboard maps controls to standards, but it does not discover AI-specific misconfigurations.