Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

A company is implementing Microsoft Defender for Cloud to protect their Azure environment. Which TWO of the following are security best practices that should be enabled? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse 'security best practices that should be enabled' with 'all available security products,' leading them to select options like Defender for Office 365 or Sentinel, which are valuable but not mandatory foundational practices for Azure environment protection in the context of Defender for Cloud.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Security Posture Management (CSPM)

Option A, Cloud Security Posture Management (CSPM), is correct because Defender for Cloud's foundational CSPM continuously assesses Azure resources against security benchmarks like Microsoft Cloud Security Benchmark, surfaces secure score recommendations, and detects misconfigurations and external attack surface risks — the core best practice for hardening an Azure environment. Option B, Microsoft Defender for Cloud workload protection, is correct because enabling the Defender plans (e.g., Defender for Servers, Storage, SQL, Containers, App Service, Key Vault) adds threat detection, vulnerability assessment, and advanced protection for running workloads, which is the recommended complement to CSPM. Option C, Microsoft Defender for Office 365, is not part of Defender for Cloud's Azure protection scope; it protects Exchange Online, SharePoint, Teams, and email against phishing and malware. Option D, Microsoft Defender for Endpoint onboarding, is a separate endpoint security product (though Defender for Servers can auto-provision it), not a Defender for Cloud best-practice toggle itself. Option E, Microsoft Sentinel integration, is an optional SIEM/SOAR data-connector scenario for centralized detection and response, not a required Defender for Cloud security best practice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Security Posture Management (CSPM)

    Why this is correct

    Cloud Security Posture Management (CSPM) is a foundational capability of Microsoft Defender for Cloud that continually scans resource configurations across Azure, AWS, and GCP, comparing them against standards like the Azure Security Benchmark. It generates a Secure Score, highlights misconfigurations, and offers step-by-step remediation, enabling security teams to prevent vulnerabilities before exploitation. Because it directly targets the cloud control plane and configuration drift, CSPM is the best practice for continuous security assessment.

  • ✓

    Microsoft Defender for Cloud workload protection

    Why this is correct

    Microsoft Defender for Cloud workload protection encompasses the enhanced security plans that deliver threat detection and response for running workloads—including VMs, containers, SQL databases, and serverless functions—by using built-in sensors, agent-based logs, and cloud-native signals. Unlike CSPM's configuration scanning, workload protection focuses on post-deployment attack detection, such as suspicious process execution, file integrity changes, and privilege escalation attempts. It is a core Defender for Cloud feature but addresses runtime threats rather than posture assessment.

  • ✗

    Microsoft Defender for Office 365

    Why it's wrong here

    Microsoft Defender for Office 365 is a separate security product that guards email and collaboration platforms—Exchange Online, SharePoint, Teams, and OneDrive—against phishing, malware, and data leakage, not against vulnerabilities in cloud infrastructure. Deploying it is appropriate for messaging hygiene, but it does not scan Azure virtual machines, storage accounts, or subscriptions for misconfigurations. Therefore, it is unrelated to implementing a cloud security posture within Defender for Cloud.

  • ✗

    Microsoft Defender for Endpoint onboarding

    Why it's wrong here

    Onboarding endpoints to Microsoft Defender for Endpoint secures user devices such as Windows, macOS, Linux, and mobile platforms against malware and advanced threats, which is a device-management concern rather than a cloud-resource protection capability. Defender for Cloud can ingest signals from Defender for Endpoint for server coverage, but the onboarding process itself is outside Defender for Cloud and does not evaluate cloud workloads. Since this question is about cloud security posture, endpoint onboarding is not a relevant best practice within Defender for Cloud.

  • ✗

    Microsoft Sentinel integration

    Why it's wrong here

    Microsoft Sentinel integration involves connecting alert and log data from Defender for Cloud into Sentinel, a cloud-native SIEM and SOAR, for centralized monitoring, correlation, and automated incident response. While this is a strong operational practice, Sentinel is an external analytics platform that consumes Defender for Cloud data, not a capability that performs posture assessment itself. As a result, integration is better understood as an outcome of using Defender for Cloud, not as a best practice for enabling its security features.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.