A security team using Microsoft Defender for Cloud receives an alert indicating 'Credential theft from Azure OpenAI resource via metadata service.' This alert suggests an attacker on a compute resource is attempting to steal the managed identity token to call Azure OpenAI. Which Defender for Cloud plan generates this AI workload security alert?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Defender for AI Services is the Defender for Cloud plan that monitors Azure AI resources—including Azure OpenAI Service—for threats. It generates security alerts specific to AI workloads, including suspicious token usage patterns that may indicate credential theft or misuse of managed identity tokens to authenticate to Azure OpenAI.
Full explanation below image
Full Explanation
B is correct because Microsoft Defender for AI Services is the Defender for Cloud plan that monitors Azure AI resources—including Azure OpenAI Service—for threats. It generates security alerts specific to AI workloads, including suspicious token usage patterns that may indicate credential theft or misuse of managed identity tokens to authenticate to Azure OpenAI. A is wrong because Defender for Servers monitors server workloads for endpoint-level threats (malware, privilege escalation); it does not generate AI service-specific alerts. C is wrong because Defender for Key Vault monitors suspicious access to Azure Key Vault, not Azure OpenAI credential theft via the metadata service. D is wrong because Defender for Resource Manager detects anomalous operations on the Azure management plane, not data-plane AI service credential theft.