Courseiva

SC-100 Practice Question: Design security solutions for applications and data

You are designing a secure DevOps pipeline using GitHub Actions and Azure. The security team requires that all container images pushed to Azure Container Registry (ACR) are scanned for vulnerabilities before deployment. If critical vulnerabilities are found, the pipeline must fail. What should you integrate into the pipeline?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Integrate Microsoft Defender for Cloud with Azure Container Registry scanning and configure a GitHub Actions step to check scan results

Option B is correct because Microsoft Defender for Cloud's container registry scanning (Defender for Containers) integrates natively with ACR to scan images on push, and a GitHub Actions step can query the scan results via the Azure CLI/REST API and fail the pipeline when critical vulnerabilities are detected. This directly satisfies the requirement to block deployment when critical findings exist. Option A does not fit because Azure Policy enforces governance on deployed resources and cannot fail a GitHub Actions build step based on scan results. Option C is wrong because Azure Bastion is a managed jump-host service for RDP/SSH access, not an image scanner. Option D is wrong because Azure Security Center is the legacy name for Defender for Cloud and, by itself, does not provide the pipeline-failing GitHub Actions integration described in B.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Azure Policy to require image scanning before deployment

    Why it's wrong here

    Azure Policy is an Azure Resource Manager governance service that can enforce tags, locations, or SKU constraints across cloud resources, but it does not execute code or inspect container image layers. Although custom policies can be written to call external APIs via Azure Functions or Logic Apps, there is no native Azure Policy capability to wait for or assess a container image vulnerability scan result during a DevOps build. Furthermore, Azure Policy evaluates resources in Azure, not artifacts in transit, so it cannot gate a GitHub Actions workflow step on scan findings. This makes the option ineffective for the stated requirement of blocking deployment based on scan outcome.

  • ✓

    Integrate Microsoft Defender for Cloud with Azure Container Registry scanning and configure a GitHub Actions step to check scan results

    Why this is correct

    Microsoft Defender for Cloud provides integrated vulnerability assessment for Azure Container Registry (ACR) images, using the Qualys scanner, which detects OS package and known software vulnerabilities. After enabling Defender for Cloud on the subscription or specifically for ACR, you can programmatically query scan results via the Microsoft Defender for Cloud REST API (e.g., Assessments - Get) or use the az acr security-status command to retrieve findings. A GitHub Actions step can then call this API in a script, parse the severity levels, and conditionally fail the job if critical or high vulnerabilities exceed a threshold. This architectural pattern is a valid 'shift-left' security gate because the scan occurs on the registry image before deployment, and the workflow enforces the policy based on real-time data.

  • ✗

    Deploy Azure Bastion to scan images during build

    Why it's wrong here

    Azure Bastion is a Platform-as-a-Service (PaaS) jump server that provides secure RDP and SSH connectivity to virtual machines through the Azure portal, eliminating public IP exposure. It has no image scanning, container registry, or workload analysis capabilities — it operates at the network transport layer for interactive administrative access. Deploying Bastion would not integrate with a GitHub Actions pipeline, nor would it have any visibility into container image layers or known vulnerabilities. The option fundamentally misunderstands the service's purpose and would add no value to a container security gating workflow.

  • ✗

    Use Azure Security Center (legacy) to scan images on push

    Why it's wrong here

    Azure Security Center was the predecessor to Microsoft Defender for Cloud; the legacy name was retired in July 2022, and all capabilities, including container registry scanning, now reside under the Microsoft Defender for Cloud brand. Even if you attempted to use the old service, it no longer receives updates and its APIs have been migrated or deprecated, meaning a GitHub Actions step would likely fail to authenticate or return data. Relying on a deprecated product is a security risk because new vulnerability signatures are not backported, so images would be assessed against an outdated vulnerability database. The correct current implementation is to enable the Defender for Cloud container security plan, not to call a legacy endpoint.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.