Courseiva

SC-100 Design security solutions for infrastructure Practice Question

A company is designing a secure baseline for Azure VMs using Azure Policy and Microsoft Defender for Cloud. Which TWO recommendations should you include to ensure VMs are protected against common threats?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the Log Analytics agent on all VMs

Enabling just-in-time (JIT) VM access reduces attack surface by blocking inbound traffic to management ports. Deploying the Log Analytics agent is required for Defender for Cloud to collect security data. The other options are either not security baselines or not VM-specific.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Azure Backup for all VMs

    Why it's wrong here

    Azure Backup focuses on creating restore points for virtual machines to support disaster recovery and business continuity. While having backups can aid in recovering from a ransomware attack, the service itself does not actively detect, prevent, or respond to security threats. A security baseline for threat protection requires telemetry, hardening, and access control, not merely backup copies. Therefore, it is not a primary recommendation for a security baseline.

  • ✓

    Deploy the Log Analytics agent on all VMs

    Why this is correct

    Deploying the Log Analytics agent (or its current replacement, the Azure Monitor Agent) is a foundational requirement for Microsoft Defender for Cloud to ingest operating system security events, audit logs, and vulnerability telemetry. Without this agent, Defender for Cloud cannot assess OS-level hardening or detect malicious activity, making the security baseline ineffective. This agent enables continuous monitoring, threat detection, and integration with Microsoft Sentinel, so it directly supports the threat protection baseline.

  • ✓

    Enable just-in-time (JIT) VM access

    Why this is correct

    Just-in-time (JIT) VM access is a network security control that temporarily opens management ports (SSH/RDP) only when authorized requests are validated, and automatically closes them when the session ends. This minimizes the attack surface by eliminating persistent internet-facing ingress points, a core recommendation in the Azure Security Benchmark. JIT is part of the Defender for Cloud security baseline because it directly addresses exposure of management interfaces, reducing the risk of brute-force and unauthorized access.

  • ✗

    Enable Azure Site Recovery

    Why it's wrong here

    Azure Site Recovery replicates virtual machines to a secondary region to enable failover during a disaster, providing resilience for business continuity. It does not collect security telemetry, evaluate security posture, or harden the VM's configuration. Disaster recovery is about maintaining availability, not protecting against identity-based attacks or malware. Thus, enabling Site Recovery is not a valid component of a security baseline focused on threat protection.

  • ✗

    Use Azure Disk Encryption with Azure Key Vault

    Why it's wrong here

    Azure Disk Encryption protects data at rest by using BitLocker or DM-Crypt, with encryption keys safeguarded in Azure Key Vault, addressing confidentiality and compliance requirements. While it is a valuable security control, it does not detect threats, monitor for misconfigurations, or prevent unauthorized access to the VM. Rather than preventing attacks, it mitigates the impact of a lost or stolen disk. Consequently, disk encryption is not a primary recommendation for a threat protection baseline, which emphasizes detection and access reduction.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.