Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are designing a security solution for an Azure Kubernetes Service (AKS) cluster that runs containerized workloads. The cluster must be integrated with Microsoft Defender for Cloud for threat detection, and you need to ensure that container images are scanned for vulnerabilities before deployment. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure Defender for Containers in Microsoft Defender for Cloud and integrate with Azure Container Registry for image scanning.

The correct option is C: enabling Azure Defender for Containers in Microsoft Defender for Cloud and integrating it with Azure Container Registry provides native vulnerability scanning of container images and threat detection for AKS workloads. Defender for Containers specifically includes image scanning in ACR (on push and periodic rescanning) and surfaces findings in Defender for Cloud, which matches the requirement to scan images before deployment. Option A is wrong because Microsoft Defender for Cloud Apps is a CASB for SaaS discovery and governance, not container image scanning. Option B is wrong because Azure Policy for Kubernetes enforces configuration and admission controls but does not itself perform vulnerability scanning of images. Option D is wrong because Microsoft Sentinel is a SIEM/SOAR platform for log collection and analytics, not an image vulnerability scanner.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Defender for Cloud Apps to discover and assess container vulnerabilities.

    Why it's wrong here

    Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on identifying and controlling user access to SaaS applications, such as Office 365 and Google Workspace. It does not have visibility into container images or the ability to inspect their OS packages and binaries for known vulnerabilities. By the time a container image is in an Azure Container Registry, Defender for Cloud Apps has no integration with ACR and cannot perform a vulnerability assessment. This option therefore addresses a different workload tier than the container image scanning required by the scenario.

  • ✗

    Deploy Azure Policy for Kubernetes with built-in policies to enforce image scanning.

    Why it's wrong here

    Azure Policy for Kubernetes, with its built-in Azure Kubernetes Service (AKS) policy definitions, enforces admission-time governance by requiring that workloads comply with rules like 'privileged containers are not allowed' or 'container images must come from an approved registry.' While these policies can technically require that images be scanned before being deployed (e.g., by checking a tag or annotation), Azure Policy itself does not actually execute a vulnerability scan of the image content. The scan is performed by an external or integrated security service like Microsoft Defender for Containers, so enabling policies alone doesn't satisfy the need to identify container vulnerabilities.

  • ✓

    Enable Azure Defender for Containers in Microsoft Defender for Cloud and integrate with Azure Container Registry for image scanning.

    Why this is correct

    Enable Azure Defender for Containers in Microsoft Defender for Cloud, which natively integrates with Azure Container Registry to provide vulnerability assessment for AKS workloads. When this option is enabled, Defender for Cloud scans every image in ACR using a Qualys-based scanner, which detects OS and package-level CVEs and provides remediation recommendations. This is the only option that directly provides image vulnerability scanning for containers, and it also adds runtime threat detection for AKS clusters, making it the correct and comprehensive answer for the security solution design.

  • ✗

    Configure Microsoft Sentinel to collect container logs and detect vulnerabilities.

    Why it's wrong here

    Microsoft Sentinel is a scalable SIEM/SOAR platform that ingests security logs from across the enterprise, including flat Kubernetes and container logs, and applies analytics to detect suspicious behavior and potential attacks. However, Sentinel does not have a vulnerability scanner built in for container images, and it does not natively inspect ACR image manifests for CVEs. To get vulnerability detection for container images, you would need to query another service (like Defender for Containers) and pull the results into Sentinel for correlation; Sentinel alone cannot perform the actual image analysis. This option confuses log-based threat detection with image vulnerability scanning, which are two distinct capabilities.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.