SC-100 Practice Question: Design security solutions for applications and data
A company uses Microsoft Defender for Cloud to protect their hybrid environment. They have on-premises servers that are monitored by Microsoft Defender for Servers. The security team notices that some servers are missing critical security updates. They want to automatically remediate missing updates on these servers. Which feature should they enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Update Manager
Azure Update Manager (option C) is the correct choice because it is the native Azure service designed to assess and automatically remediate missing OS security updates across Azure, on-premises, and multicloud servers, including those onboarded to Microsoft Defender for Servers. It provides update assessment, scheduling, and automatic patching for Windows and Linux machines, which directly addresses the team's need to remediate missing updates on their hybrid servers. Adaptive Application Controls (option A) only create allowlist/denylist rules for applications to control execution and do not patch operating systems. Azure Automation Update Management (option B) is the legacy predecessor that has been superseded by Azure Update Manager, so it is not the recommended feature. Just-in-Time VM access (option D) only restricts inbound management ports on VMs and has nothing to do with update remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Adaptive Application Controls
Why it's wrong here
Adaptive Application Controls is a Defender for Cloud feature that builds an allowlist of known-safe executable files using machine learning and can block applications that are not on that allowlist. It is designed to reduce the attack surface from malicious or unauthorized software, but it does not inventory missing patches or apply OS updates. Consequently, it cannot be used to remediate the specific security recommendation about missing system updates.
- ✗
Azure Automation Update Management
Why it's wrong here
Azure Automation Update Management is the legacy solution that preceded Azure Update Manager. It required a dependency on Azure Automation, a Log Analytics workspace, and Hybrid Runbook Workers to perform update assessments and installations. While it could technically patch servers, it is not the service that Defender for Cloud's security recommendations natively integrate with for automated remediation. Microsoft has transitioned its recommended approach to Azure Update Manager, making this older solution an incorrect answer.
- ✓
Azure Update Manager
Why this is correct
Azure Update Manager is the current, first-party service for overseeing and applying OS updates across Azure VMs, on-premises servers, and machines in other cloud environments. It directly integrates with Defender for Cloud: the security recommendation 'Machines should have security updates installed' can be remediated using Azure Update Manager to establish a schedule or trigger immediate patching of non-compliant resources. This native integration makes it the appropriate tool for automatically remediating missing updates as part of a Defender for Cloud workflow.
- ✗
Just-in-Time (JIT) VM access
Why it's wrong here
Just-in-Time (JIT) VM access is a security control in Defender for Cloud that curbs brute-force attacks by locking down inbound traffic to specific ports and only opening them for a designated time upon approval. It does not inspect, assess, or install operating system updates on the VM. The recommendation for missing security updates is about OS patch levels, not network access, so JIT cannot serve as the remediation mechanism for update findings.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.