mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Deploying Microsoft Defender for Cloud to protect…
A company is deploying Microsoft Defender for Cloud to protect a multi-cloud environment that includes Azure and AWS. The security team wants to prioritize the highest-risk recommendations. Which feature should they use to identify and focus on the most critical security issues?
⚠ Common exam trap
Many candidates confuse 'enhanced security features' (which enable advanced detections) with 'prioritization features' (which rank recommendations by risk), leading them to select Option C instead of recognizing that Secure Score is the dedicated prioritization mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Secure Score and its recommendations
Secure Score in Microsoft Defender for Cloud aggregates all security recommendations and assigns a score based on their relative risk and impact. By focusing on recommendations that most improve the Secure Score, the security team can systematically prioritize the highest-risk issues across both Azure and AWS resources. This directly aligns with the goal of identifying and focusing on the most critical security issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Secure Score and its recommendations
Why this is correct
Secure Score quantifies organizational security posture as a percentage by scoring controls across workloads. Each recommendation is mapped to a control and shows the potential score increase if remediated, directly enabling risk-based prioritization. Defender for Cloud's recommendations page defaults to sorting by Secure Score impact, so this is the primary mechanism for deciding what to remediate first.
- ✗
Regulatory Compliance dashboard
Why it's wrong here
The Regulatory Compliance dashboard assesses environments against standards such as CIS, NIST SP 800-53, and Azure CIS, displaying pass/fail status per control. While it identifies which compliance requirements are unmet, it does not rank risks or suggest which fixes will most reduce attack surface. It answers 'Are we compliant?' not 'What should we fix first?', making it unsuitable as a prioritization tool.
- ✗
Enable Defender for Cloud's enhanced security features
Why it's wrong here
Enabling enhanced security features (e.g., Defender for Servers, Defender for SQL) activates additional telemetry and threat detection capabilities, giving broader visibility and more alerts and findings. However, this action only expands the data feeding into recommendations; it does not analyze, score, or sequence remediation steps. Prioritization still requires Secure Score and the recommendations workload, so this option is a prerequisite for more findings, not the decision mechanism.
- ✗
Review attack path analysis
Why it's wrong here
Attack path analysis uses a graph-based model to simulate how vulnerabilities and misconfigurations could be chained into a breach, pinpointing exploitable paths from an attacker's perspective. This is a targeted, context-aware diagnostic—useful for validating specific exposures or incident response—but it does not produce an organization-wide, prioritized list of remediations. It's a secondary tool for deep investigation rather than a primary recommendation ranking engine.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.