A company wants to enforce that all Azure VMs in a subscription must use managed disks and must not have public IP addresses. Which Azure service should the cybersecurity architect use to implement these requirements at scale?
-
A
Azure Security Center Recommendations
-
B
Azure Policy with Deny effects
-
C
Azure Blueprints Locks
-
D
Microsoft Defender for Cloud Alerts