To ensure that the configuration of the Docker host meets best practices and to be alerted if vulnerabilities are detected, you should use Microsoft Defender for Containers [2] [5]. This solution is suitable for protecting Docker hosts and verifying their compliance with the CIS Docker benchmark [2]. Since VM1 in your Azure subscription hosts a Docker container running App1, using Microsoft Defender for Containers will help you monitor and secure the environment effectively [1].