SC-100 Design security solutions for infrastructure Practice Question
A company plans to use Microsoft Defender for Cloud to secure a multi-cloud environment including Azure, AWS, and GCP. What is the first step to enable multi-cloud visibility?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect AWS and GCP accounts using the cloud connectors in Defender for Cloud
Connect AWS and GCP accounts using the cloud connectors in Defender for Cloud. Defender for Cloud's native multi-cloud support requires onboarding non-Azure environments through the AWS and GCP connectors, which establish the necessary trust and inventory so that resources, recommendations, and alerts from those clouds become visible in the portal. Only after this connection can Defender plans, compliance policies, or agent-based extensions be applied to those resources. Option A is premature because enabling subscription-level Defender plans only affects Azure resources, not AWS or GCP. Option C is a later configuration step that depends on data already being collected, and Option D is not the onboarding mechanism for multi-cloud visibility, since Azure Arc is used for connecting specific servers rather than enabling cloud-wide AWS/GCP visibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable all Defender plans for subscription
Why it's wrong here
Enabling all Defender plans across the subscription is a post-onboarding configuration that dictates which advanced security features, such as threat detection for servers or databases, are active on resources that have already been discovered. It does not create any connection to AWS or GCP workloads, so if no cloud connector exists, the plans have nothing to operate on. Additionally, 'all plans' may be unnecessary or costly—you selectively enable only the plans that match your workload types after the multi-cloud assets are connected.
- ✓
Connect AWS and GCP accounts using the cloud connectors in Defender for Cloud
Why this is correct
The Defender for Cloud multi-cloud connectors establish the onboarding bridge between Azure and AWS or GCP, synchronizing security configurations, threat indicators, and resource inventory into the unified Azure dashboard. This connector-level integration, which leverages read-only credentials from the foreign cloud, is the mandatory first step because all subsequent security policies, recommendations, and Defender plan coverage depend on the cloud accounts being visible to Azure. Without this connector, Defender for Cloud has no access to the AWS or GCP workloads.
- ✗
Create custom compliance policies
Why it's wrong here
Custom compliance policies, built with Azure Policy or regulatory standards, are used to apply your organization's specific security and compliance requirements to resources once they are present in Defender for Cloud. Before any cloud connector exists, there are no AWS or GCP resources to evaluate, making policy creation premature. The initial action for multi-cloud security is to create the connector; custom policies are an optional refinement that comes after inventory and recommendations are flowing.
- ✗
Deploy Azure Arc agents on all cloud VMs
Why it's wrong here
Azure Arc agents are designed for extending Azure Control Plane management to on-premises, edge, and other cloud servers, enabling Azure Policy and resource governance on those individual machines. However, for Defender for Cloud multi-cloud visibility, installing Arc agents on every AWS EC2 or GCP compute instance is neither the correct pattern nor a prerequisite—the cloud connector natively pulls security metadata without requiring per-install agents. Also, Arc agents address server-level management, not the environment-level account synchronization that the connector provides.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.