A security engineer configures Microsoft Defender for Cloud Defender for AI plan. After enabling it, alerts appear for 'Jailbreak attempt detected on Azure OpenAI endpoint.' Which underlying technology enables this detection?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because Microsoft Defender for AI's jailbreak detection capability is powered by Azure AI Content Safety Prompt Shield, which analyzes prompts in real-time for jailbreak patterns. Defender for AI integrates with this detection pipeline to surface jailbreak attempts as security alerts in Defender for Cloud.
Full explanation below image
Full Explanation
C is correct because Microsoft Defender for AI's jailbreak detection capability is powered by Azure AI Content Safety Prompt Shield, which analyzes prompts in real-time for jailbreak patterns. Defender for AI integrates with this detection pipeline to surface jailbreak attempts as security alerts in Defender for Cloud. A is incorrect because Azure OpenAI's built-in content filtering blocks harmful content in responses but the Defender for Cloud alert specifically leverages Prompt Shield integration. B is incorrect because Defender for AI for Azure OpenAI does not require an agent on compute nodes; it monitors API-level interactions through the service plane. D is incorrect because Sentinel anomaly detection rules are in the SIEM layer and are not the underlying detection mechanism for Defender for Cloud alerts.