MS-900 Describe cloud concepts Practice Question
Exhibit
{
"properties": {
"microsoftDefenderForCloud": {
"enabled": true
}
}
}Refer to the exhibit. An administrator is configuring a new Azure subscription with this ARM template snippet for Microsoft Defender for Cloud. What will be the immediate result?
⚠ Common exam trap
Many exam-takers confuse 'enabling Microsoft Defender for Cloud' with automatically activating premium features like Defender for Endpoint or the highest security tier, when in reality the default is only foundational CSPM with recommendations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The subscription will be monitored for security issues and receive recommendations
The ARM template snippet enables Microsoft Defender for Cloud at the subscription level. By default, this activates the foundational Cloud Security Posture Management (CSPM) capabilities, which continuously assess the subscription's resources against security baselines and generate actionable security recommendations. This does not automatically onboard VMs to Defender for Endpoint or apply the highest security tier; it simply enables monitoring and recommendations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All virtual machines will be automatically onboarded to Microsoft Defender for Endpoint
Why it's wrong here
Enabling Microsoft Defender for Cloud through the template does not automatically install or onboard Microsoft Defender for Endpoint on every virtual machine. That integration requires separately enabling the Defender for Servers plan and configuring auto-provisioning for the endpoint protection agent; without those additional steps, VMs remain unevaluated by Defender for Endpoint even though Defender for Cloud can still assess their security posture.
- ✓
The subscription will be monitored for security issues and receive recommendations
Why this is correct
When Microsoft Defender for Cloud is enabled on the subscription, it continuously assesses the environment against built-in security benchmarks and policy initiatives. The service surfaces misconfigurations, computes a secure score, and provides prioritized, actionable recommendations; this monitoring and guidance happen automatically after enabling Defender for Cloud, with no need for manual security policy creation to get basic CSPM value.
- ✗
The subscription will be protected by the highest security tier
Why it's wrong here
The template only ensures that Microsoft Defender for Cloud is turned on, which provisions the foundational free tier of cloud security posture management, not automatically the highest security tier. Activating higher tiers such as Defender for Servers Plan 1 or Plan 2 requires an administrator to explicitly enable those paid enhanced security features; the free tier alone does not include endpoint detection and response, vulnerability management, or just-in-time access controls.
- ✗
No changes will occur until a security policy is manually created
Why it's wrong here
Deploying the template assigns the built-in Azure Policy initiatives that define Defender for Cloud's security policies, so security assessments and recommendations begin immediately after enabling it. Resources are continuously evaluated against those automatically applied policies, and findings appear in the Defender for Cloud dashboard; therefore, changes do occur without requiring an administrator to manually create or assign a custom security policy.
Go deeper
Related to this question
Learn chapter
Attack Simulator in Microsoft Defender
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise security solution designed to protect devices from cyber threats using behavioral analysis, machine learning, and automated investigation.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.