A security engineer is configuring Microsoft Defender for Cloud to protect an Azure OpenAI resource. They want to receive alerts when the OpenAI endpoint is accessed from a Tor exit node or anonymous proxy. Which Microsoft Defender plan must be enabled?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Defender for AI (preview) provides threat protection specifically for Azure AI services including Azure OpenAI, and generates alerts for suspicious access patterns including connections from anonymizing networks like Tor. A is incorrect because Defender for App Service protects web applications hosted on App Service, not Azure AI services.
Full explanation below image
Full Explanation
B is correct because Microsoft Defender for AI (preview) provides threat protection specifically for Azure AI services including Azure OpenAI, and generates alerts for suspicious access patterns including connections from anonymizing networks like Tor. A is incorrect because Defender for App Service protects web applications hosted on App Service, not Azure AI services. C is incorrect because Defender for Key Vault monitors for suspicious key vault access, not AI endpoint access. D is incorrect because Defender for DNS monitors DNS query anomalies, not AI service access patterns.