SC-100 Practice Question: Design security solutions for applications and data
You are designing a CI/CD pipeline for a containerized application using Azure DevOps. You need to ensure that container images are scanned for vulnerabilities before being deployed to production. Which service should you integrate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud
Microsoft Defender for Cloud [CORRECT] is the right choice because it provides container image vulnerability scanning for images stored in Azure Container Registry and can be integrated into CI/CD workflows to gate deployments before production. It continuously assesses images and surfaces findings that Azure DevOps pipelines can act on. Azure Policy is for enforcing governance and compliance rules on resources, not for scanning container images for vulnerabilities. Azure Key Vault manages secrets and keys, and Azure Monitor collects telemetry and logs, so neither performs vulnerability scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy is a governance service that enforces rules on Azure resource configurations, such as requiring App Service minTLS versions or restricting allowed resource types. It evaluates the properties and metadata of resources, not the content of artifacts like container images, so it cannot detect vulnerable packages or misconfigurations inside an image. Policy can be used to audit that a scan was performed (e.g., check for a tag or result metadata) but it must rely on an external scanner to produce that data. Therefore, it is not the tool for identifying image vulnerabilities.
- ✗
Azure Key Vault
Why it's wrong here
Azure Key Vault is a cloud service designed for secure storage and management of secrets, encryption keys, and certificates. It does not perform any static analysis of container images, nor does it inspect image layers or identify known vulnerabilities (CVEs). In a CI/CD pipeline, Key Vault might be used to store credentials for accessing a registry or for signing images, but it is not a scanning mechanism. Image vulnerability scanning requires a dedicated security scanner.
- ✓
Microsoft Defender for Cloud
Why this is correct
Microsoft Defender for Cloud is the correct choice because it includes a built-in, agentless vulnerability scanner for container images stored in Azure Container Registry (ACR). When an image is pushed or pulled, Defender for Cloud automatically scans it using the Qualys scanner and matches findings against a continuously updated CVE database. The results provide severity levels, remediation guidance, and can be integrated into CI/CD gates via Defender for Cloud APIs or CLI to block deployment of images above a certain risk threshold. It also re-scans images on a regular basis to detect newly discovered vulnerabilities, providing both pre-deployment and ongoing protection.
- ✗
Azure Monitor
Why it's wrong here
Azure Monitor is a monitoring and telemetry platform that collects metrics, logs, and activity data from Azure resources. Its purpose is to provide operational insights, alerting, and dashboard visualizations—not to analyze the file system of a container image. While you could export vulnerability scan results to Azure Monitor for correlation and alerting, Monitor itself has no engine to detect CVEs in image layers. Thus, it cannot act as the image scanning component of a CI/CD pipeline.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.