Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A company uses Microsoft Defender for Cloud to protect their hybrid environment. They have on-premises servers that are monitored by Microsoft Defender for Servers. The security team notices that some servers are missing critical security updates. They want to automatically remediate missing updates on these servers. Which feature should they enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Update Manager

Azure Update Manager (option C) is the correct choice because it is the native Azure service designed to assess and automatically remediate missing OS security updates across Azure, on-premises, and multicloud servers, including those onboarded to Microsoft Defender for Servers. It provides update assessment, scheduling, and automatic patching for Windows and Linux machines, which directly addresses the team's need to remediate missing updates on their hybrid servers. Adaptive Application Controls (option A) only create allowlist/denylist rules for applications to control execution and do not patch operating systems. Azure Automation Update Management (option B) is the legacy predecessor that has been superseded by Azure Update Manager, so it is not the recommended feature. Just-in-Time VM access (option D) only restricts inbound management ports on VMs and has nothing to do with update remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adaptive Application Controls

    Why it's wrong here

    Adaptive Application Controls is a Defender for Cloud feature that builds an allowlist of known-safe executable files using machine learning and can block applications that are not on that allowlist. It is designed to reduce the attack surface from malicious or unauthorized software, but it does not inventory missing patches or apply OS updates. Consequently, it cannot be used to remediate the specific security recommendation about missing system updates.

  • ✗

    Azure Automation Update Management

    Why it's wrong here

    Azure Automation Update Management is the legacy solution that preceded Azure Update Manager. It required a dependency on Azure Automation, a Log Analytics workspace, and Hybrid Runbook Workers to perform update assessments and installations. While it could technically patch servers, it is not the service that Defender for Cloud's security recommendations natively integrate with for automated remediation. Microsoft has transitioned its recommended approach to Azure Update Manager, making this older solution an incorrect answer.

  • ✓

    Azure Update Manager

    Why this is correct

    Azure Update Manager is the current, first-party service for overseeing and applying OS updates across Azure VMs, on-premises servers, and machines in other cloud environments. It directly integrates with Defender for Cloud: the security recommendation 'Machines should have security updates installed' can be remediated using Azure Update Manager to establish a schedule or trigger immediate patching of non-compliant resources. This native integration makes it the appropriate tool for automatically remediating missing updates as part of a Defender for Cloud workflow.

  • ✗

    Just-in-Time (JIT) VM access

    Why it's wrong here

    Just-in-Time (JIT) VM access is a security control in Defender for Cloud that curbs brute-force attacks by locking down inbound traffic to specific ports and only opening them for a designated time upon approval. It does not inspect, assess, or install operating system updates on the VM. The recommendation for missing security updates is about OS patch levels, not network access, so JIT cannot serve as the remediation mechanism for update findings.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.