SC-100 Design security solutions for infrastructure Practice Question
Which TWO of the following are features of Microsoft Defender for Cloud that help secure infrastructure? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse Defender for Cloud's posture management features (Secure Score, JIT) with Microsoft Sentinel's investigation and analytics capabilities (Incident investigation, UEBA), or with Microsoft Entra ID's identity governance features (PIM), because all are part of the Microsoft security portfolio but serve distinct roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure Score
Secure Score (A) is a core Microsoft Defender for Cloud capability that continuously assesses your Azure resources and subscriptions against security recommendations and benchmarks, aggregating the results into a numeric score so you can prioritize hardening actions for your infrastructure. Just-in-time (JIT) VM access (C) is also a Defender for Cloud feature that reduces the attack surface of virtual machines by blocking inbound management ports (RDP 3389, SSH 22) by default and opening them only for approved, time-limited requests from authorized IPs. Both directly serve Defender for Cloud's mission of strengthening and monitoring infrastructure security posture. Incident investigation (B) and User and Entity Behavior Analytics (E) are capabilities of Microsoft Sentinel (the SIEM/SOAR solution), not Defender for Cloud. Privileged Identity Management (D) is a separate Microsoft Entra ID (Azure AD) service for just-in-time privileged role activation and access reviews, not a Defender for Cloud infrastructure feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secure Score
Why this is correct
Secure Score is a core feature of Microsoft Defender for Cloud that aggregates security findings and provides a numeric score based on the implementation of security controls and best practices. It helps organizations prioritize remediation actions by comparing current posture against benchmarks like Azure Security Benchmark and CIS. The score reflects the percentage of healthy security recommendations, and improving it directly reduces attack surface across compute, network, storage, and identity resources. It is not a separate product but an actionable dashboard within Defender for Cloud's Cloud Security Posture Management (CSPM) capability.
- ✗
Incident investigation
Why it's wrong here
Incident investigation is a dedicated feature of Microsoft Sentinel, the cloud-native SIEM/SOAR platform, not Defender for Cloud. Sentinel's investigation graph allows security analysts to explore entities, alerts, and activities to understand an attack's scope and root cause. Defender for Cloud, by contrast, provides security alerts and integrates with Sentinel for advanced hunting, but the full investigation experience lives in Sentinel. Therefore, classifying incident investigation as a Defender for Cloud feature is incorrect.
- ✓
Just-in-time VM access
Why this is correct
Just-in-time (JIT) VM access is a feature of Microsoft Defender for Cloud that locks down inbound traffic to Azure VMs by rejecting all traffic except for approved requests via NSG and Azure Firewall rules. When a user requests access, Defender for Cloud validates permissions and opens the ports for a specified time window, minimizing exposure to brute-force or exploitation. This capability is part of Defender for Cloud's workload protection and is often used alongside adaptive application controls and network security recommendations. It is not available in Sentinel or other standalone products.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is a feature of Microsoft Entra ID (formerly Azure AD) that provides time-based and approval-based role activation for elevated permissions. It manages just-in-time activation for Microsoft Entra ID roles, Azure resources, and some Microsoft 365 roles, with access reviews and alerts. Defender for Cloud does not include PIM; for privileged access protection in the cloud, organizations must use Entra ID PIM or broader Microsoft Entra ID Governance capabilities. Thus, attributing PIM to Defender for Cloud is a category error, conflating identity governance with cloud security posture management.
- ✗
User and Entity Behavior Analytics (UEBA)
Why it's wrong here
UEBA is a capability of Microsoft Defender for Identity (formerly Azure ATP), which analyzes user and entity activity in on-premises and hybrid environments to detect anomalous behavior signifying an attack. It uses machine learning and behavioral profiles, pivoting on entities such as users, devices, and resources to detect things like lateral movement, privilege escalation, and reconnaissance. Defender for Cloud's security recommendations and threats focus on workloads and infrastructure, not entity-level behavior analytics. So UEBA belongs to Defender for Identity, not Defender for Cloud.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.