SC-100 Security recommendations Practice Question
Which TWO features of Microsoft Defender for Cloud help you identify and remediate misconfigurations in your Azure environment? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security recommendations.
Security recommendations (B) is correct because Microsoft Defender for Cloud continuously assesses Azure resources against built-in and regulatory benchmarks (e.g., Azure Security Benchmark, CIS, PCI DSS) and surfaces specific, actionable remediation steps for each misconfiguration it detects. Secure score (E) is correct because it aggregates the results of those assessments into a measurable score and highlights the highest-impact misconfigurations and improvement actions, letting you prioritize and track remediation progress over time. Together, recommendations identify the misconfigurations and secure score quantifies and prioritizes them. File integrity monitoring (A) is wrong because FIM detects changes to critical OS files and registry keys on VMs, not Azure resource misconfigurations. Just-in-time VM access (C) is wrong because it reduces the attack surface by opening management ports only on demand, rather than identifying configuration issues. Adaptive application controls (D) is wrong because it uses machine-learning allowlists to control which applications can run on VMs, which is workload protection, not misconfiguration assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
File integrity monitoring (FIM).
Why it's wrong here
File integrity monitoring (FIM) in Defender for Cloud is a detection control that captures baseline snapshots of critical files, registries, and software and then alerts on unauthorized changes. It does not evaluate the security configuration of your resources against best practice or compliance frameworks, so it will not proactively identify misconfigurations such as open ports, weak encryption, or missing network security groups. As a result, FIM is a post-change integrity detective, not a configuration assessment tool.
- ✓
Security recommendations.
Why this is correct
Security recommendations are Defender for Cloud's core mechanism for surfacing misconfigurations and insecure settings in supported resources, such as VMs, storage accounts, and databases. Each recommendation results from a policy-driven assessment against Azure Security Benchmark, CIS, or other standards, and includes affected resources, impact, and remediation steps. They directly answer the question 'what is misconfigured?' and are the underlying data that drives the secure score, making them the primary feature for identifying configuration errors.
- ✗
Just-in-time (JIT) VM access.
Why it's wrong here
Just-in-time (JIT) VM access is an access-control feature that continuously locks down inbound management ports, such as SSH and RDP, and grants time-bound access on request after authorization. It narrows the attack surface by reducing port exposure but performs no analysis of the VM's internal configuration, compliance posture, or security settings. Therefore, JIT is a threat-reduction control, not a misconfiguration-detection feature.
- ✗
Adaptive application controls.
Why it's wrong here
Adaptive application controls build a machine-learning-based allowlist of processes and software that are known to be safe on your VMs, then block new or unexpected executables. This is an application-whitelisting mechanism intended to prevent malicious or unapproved code from running, not a scan of your resource configuration. It does not assess whether your security settings are misconfigured and offers no recommendations for hardening your cloud environment.
- ✓
Secure score.
Why this is correct
Secure score is a consolidated metric that aggregates the compliance status of all security recommendations into a single number from 0 to 100, reflecting your overall security posture. It lets you track remediation progress, prioritize actions by potential score improvement, and compare against your organization's targets. While it does not independently identify a specific misconfiguration, it is a powerful feature that turns the raw recommendation data into an actionable dashboard, so it directly supplements the identification of misconfigurations.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.