5.1.1. Defender CSPM and Compliance Framework Evaluation
💡 First Principle: A resource's security posture isn't a single number — it's the accumulation of many individual recommendations, each with a different severity and a different contribution to your overall exposure, and Defender CSPM's job is to find, prioritize, and track all of them continuously.
Defender CSPM identifies security risks through continuous assessment — misconfigurations, missing controls, and risky combinations (like an internet-facing VM with a known vulnerability and excessive permissions, which CSPM's attack path analysis can specifically surface as a compounding risk rather than three separate low-priority findings). Compliance framework evaluation (introduced conceptually in 2.3.2) is powered by the same underlying engine — CSPM findings map to specific controls within whichever regulatory standards you've assigned, driving both secure score and framework-specific compliance percentages.
⚠️ Exam Trap: CSPM's attack path analysis is specifically about combinations of findings that compound risk — a scenario emphasizing "these three individually low-severity issues create a critical exposure when combined" is pointing at attack path analysis, not just a list of individual recommendations.
Reflection Question: Why might three individually low-severity CSPM findings on the same resource deserve more urgent attention together than any one of them would on its own?