Summary
In this chapter, you explored Azure Security Center and Azure Defender. Azure Security Center is an infrastructure security monitoring platform. It provides both monitoring of security configuration as well as monitoring of any potential ongoing threats. To monitor workloads in a Kubernetes cluster, Azure Security Center makes use of Azure Policy for AKS.
To start, you enabled Azure Policy for AKS. You then enabled Azure Security Center and Azure Defender on your subscription.
You then created five harmful workloads on your cluster. Some of those caused configuration recommendations in Azure Security Center. Some others even caused security alerts to be triggered in Azure Defender. You explored four security alerts and followed the mitigation steps recommended to resolve these alerts.