More Info:

Ensure that monitoring of DDoS protection at the Azure virtual network level is enabled.

Risk Level

High

Address

Security, Operational Maturity

Compliance Standards

CBP

Triage and Remediation

Remediation

Sure, here are the step-by-step instructions to remediate the misconfiguration “Enable DDoS Protection Standard Monitoring for Public Virtual Networks” in Azure using the Azure console:

  1. Login to the Azure Portal (https://portal.azure.com/)
  2. Select the subscription and resource group that contains the virtual network you want to protect.
  3. In the Azure portal, search for “DDoS protection plans” in the search bar.
  4. Select “DDoS protection plans” from the search results.
  5. Click on ”+ Add” to create a new DDoS protection plan.
  6. In the “Basics” tab, enter a name for the plan and select the subscription and resource group that contains the virtual network you want to protect.
  7. In the “Settings” tab, select “Standard” as the DDoS protection plan tier.
  8. In the “Review + create” tab, review the settings and click on “Create” to create the DDoS protection plan.
  9. Once the DDoS protection plan is created, go to the virtual network that you want to protect.
  10. In the virtual network’s “Settings” menu, select “DDoS protection”.
  11. Under “DDoS protection plan”, select the DDoS protection plan that you created in step 5.
  12. Click on “Save” to save the changes.

That’s it! You have now enabled DDoS Protection Standard Monitoring for Public Virtual Networks in Azure.