A security architect must design a solution to detect when Azure resource configurations drift from a secure baseline and automatically remediate. Which combination of services achieves this?
-
A
Microsoft Defender for Cloud recommendations combined with Azure Policy DeployIfNotExists effects for automated remediation
-
B
Azure Monitor alerts on configuration changes and manual remediation tickets in ServiceNow
-
C
Microsoft Sentinel analytics rules querying Azure Activity logs with playbook-triggered remediation
-
D
Azure Blueprints with locked policy assignments and manual drift reviews monthly