SC-100 Design security solutions for infrastructure Practice Question
Which THREE features of Microsoft Defender for Cloud help secure Azure Kubernetes Service (AKS) clusters? (Select three.)
⚠ Common exam trap
Many candidates confuse general Azure security services (like DDoS Protection) or unrelated Defender plans (like Cosmos DB) with the specific Defender for Cloud features that directly protect AKS workloads, leading them to select options that are technically valid Azure services but not applicable to AKS cluster security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Defender for Kubernetes (cluster hardening)
Azure Defender for Kubernetes (option B) is correct because it provides cluster hardening by continuously assessing AKS configurations against CIS Kubernetes benchmark controls and surfacing misconfiguration recommendations in Microsoft Defender for Cloud. Vulnerability assessment for container images (option C) is correct because Defender for Cloud scans images stored in Azure Container Registry and images running in AKS, using Qualys-based scanning to detect known CVEs in OS packages and language dependencies. Runtime threat detection for AKS clusters (option E) is correct because Defender for Containers monitors AKS node and workload activity via eBPF-based sensors and Kubernetes audit logs to alert on suspicious behavior such as crypto-mining, privilege escalation, and anomalous process execution. Option A does not belong because Advanced threat protection for Azure Cosmos DB protects database accounts, not AKS clusters. Option D does not belong because DDoS Protection Standard mitigates volumetric network attacks at the Azure edge and is not an AKS workload security feature of Defender for Cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Advanced threat protection for Azure Cosmos DB
Why it's wrong here
Advanced threat protection for Azure Cosmos DB is a Defender for Cloud plan specifically designed for NoSQL databases, using threat intelligence and anomaly detection to flag malicious access patterns like data exfiltration or SQL injection. It does nothing for AKS clusters, which require Kubernetes-specific protection. Therefore, while useful for Cosmos DB, it does not help secure an AKS workload.
- ✓
Azure Defender for Kubernetes (cluster hardening)
Why this is correct
Azure Defender for Kubernetes, now part of Microsoft Defender for Containers, provides continuous security assessment of your cluster's configuration, including checks against CIS Kubernetes Benchmarks, overly permissive RBAC roles, and insecure pod settings. It automatically generates prioritized hardening recommendations that analysts can implement to reduce attack surface. This directly helps secure AKS clusters and is the correct answer for cluster hardening.
- ✓
Vulnerability assessment for container images
Why this is correct
Vulnerability assessment for container images, built into Defender for Containers, scans images in Azure Container Registry (and other supported registries) for known vulnerabilities in OS packages and application dependencies. It uses Qualys or Microsoft Defender Vulnerability Management engines, performing both pull-based and push-based scans. By identifying and remediating image weaknesses before deployment, it strengthens the entire AKS supply chain.
- ✗
DDoS Protection Standard
Why it's wrong here
DDoS Protection Standard is a separate Azure networking service that mitigates volumetric network-layer attacks against public IP addresses and virtual networks. It is not a feature contained within Microsoft Defender for Cloud, though Defender for Cloud can surface related alerts if the service is misconfigured. Since this question asks specifically about Defender for Cloud features for AKS, DDoS Protection Standard is an incorrect choice.
- ✓
Runtime threat detection for AKS clusters
Why this is correct
Runtime threat detection for AKS clusters, also part of Defender for Containers, continuously monitors cluster audit logs, node events, and host-level signals to identify suspicious activity such as privilege escalation, malicious containers, or crypto-mining. When a threat is detected, security alerts with recommendations are raised in Defender for Cloud, enabling immediate incident response without manual log analysis. This provides real-time protection during cluster operation, making it a correct feature.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.