CV0-004 Operations and Support Practice Question
A cloud administrator manages workloads in Microsoft Azure. The security team requires that all virtual machines apply operating system updates automatically during a defined window without the administrator logging in to each machine. Which Azure feature should the administrator use to meet this requirement?
⚠ Common exam trap
It's easy for candidates to confuse posture assessment or configuration enforcement services, which only report or enforce settings, with the service that actually schedules and installs operating system updates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Update Manager, with a maintenance configuration that schedules update assessments and installations on the target virtual machines.
Azure Update Manager is the service purpose-built for assessing and installing operating system updates on Azure virtual machines and Arc-connected servers. A maintenance configuration defines the schedule and window, and the service performs assessment and installation automatically, which is exactly what the security team requires without per-machine administrator logon.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud, with the regulatory compliance dashboard enabled for the subscription.
Why it's wrong here
Defender for Cloud continuously assesses security posture and can flag missing updates as recommendations, but it does not install operating system patches on a schedule. The compliance dashboard reports status; it takes no remediation action on the machines, so the automatic installation requirement would remain unmet.
- ✓
Azure Update Manager, with a maintenance configuration that schedules update assessments and installations on the target virtual machines.
Why this is correct
Azure Update Manager provides agentless assessment and scheduled patching for Azure and Arc-enabled machines. By assigning a maintenance configuration, the administrator defines the recurrence and maintenance window, and the service installs approved updates automatically, satisfying the requirement without interactive logon to each VM.
- ✗
Azure Policy, with a built-in initiative that audits whether the Guest Configuration extension is installed.
Why it's wrong here
Azure Policy evaluates and can deploy configuration through remediation tasks, but its guest configuration policies report on settings and can enforce presence of the extension. They do not provide recurring update installation windows, so machines would still need another mechanism to apply patches on schedule.
- ✗
Azure Automation State Configuration, with a DSC configuration that declares the Windows Update service as running.
Why it's wrong here
DSC ensures a declared configuration state, such as a service being started, but it does not orchestrate patch approval, assessment, or installation inside a maintenance window. Declaring the update service running does not cause updates to download or install, so this does not fulfill the patching requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.