Design solutions that align with security best practices and priorities →mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They want to ensure that all virtual machines have the Log Analytics agent installed and that missing system updates are remediated automatically. Which two recommendations should be enabled in a single policy initiative?
⚠ Common exam trap
Many exam-takers think they need to create custom initiatives or use separate assignments (Option A or B) because they assume the two requirements are unrelated, but Microsoft Defender for Cloud's built-in initiative already bundles them together, making Option D the simplest and most correct approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft Defender for Cloud 'System Updates' and 'Log Analytics agent' recommendations via a built-in initiative.
Microsoft Defender for Cloud includes a built-in policy initiative (the 'ASC Default' initiative) that contains both the 'System Updates' and 'Log Analytics agent' recommendations. Enabling this single initiative automatically assigns both requirements to the selected scope, ensuring that missing system updates are remediated and the Log Analytics agent is installed on all virtual machines without needing custom policies or separate assignments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign two separate Azure Policy initiatives, one for each requirement.
Why it's wrong here
Assigning two separate Azure Policy initiatives would fragment compliance management, forcing you to track each requirement's state independently and reconcile any overlapping or contradictory effects. Defender for Cloud already ships a single built-in initiative—the Microsoft cloud security benchmark (or legacy ASC default)—that combines system-update and Log Analytics agent coverage, so splitting them doubles administrative overhead and increases the chance of assignment drift or missed recommendations without adding security value.
- ✗
Create a custom Azure Policy initiative that combines the two requirements.
Why it's wrong here
A custom Azure Policy initiative requires you to hand-author the policy definitions, parameters, and assignment logic, which duplicates what Defender for Cloud already provides out of the box. Unlike the built-in initiative, a custom one will not automatically feed into Defender for Cloud's security recommendations, regulatory compliance dashboards, or secure-score calculations, and you will own ongoing maintenance, versioning, and policy-tuning responsibilities that would otherwise be handled by Microsoft.
- ✗
Use Azure Blueprints to assign the policies to all subscriptions.
Why it's wrong here
Azure Blueprints is deprecated and has been replaced by deployment stacks and ARM/Bicep templates, so using it today is not a supported or future-proof strategy for policy assignment. Even in its prime, Blueprints was designed to orchestrate a full environment (resource groups, RBAC, policies, ARM templates) for repeatable deployments, whereas Defender for Cloud's built-in initiative is purpose-built for security recommendations and provides continuous, integrated compliance assessment without the extra blueprint lifecycle.
- ✓
Enable the Microsoft Defender for Cloud 'System Updates' and 'Log Analytics agent' recommendations via a built-in initiative.
Why this is correct
Enabling the System Updates and Log Analytics agent recommendations through Defender for Cloud's built-in initiative directly leverages the Microsoft cloud security benchmark (or the legacy ASC default) that Microsoft manages and updates. This approach automatically applies the underlying Azure Policy definitions across all selected subscriptions, correlates assessment results to secure-score and regulatory compliance controls, and requires no custom coding or manual policy maintenance—making it the intended, simplest path for meeting both requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.