SC-100 Design security solutions for infrastructure Practice Question
You are the security architect for a company that uses Microsoft Defender for Cloud. The company has Azure virtual machines (VMs) and on-premises Windows Servers onboarded to Microsoft Defender for Servers Plan 2. The security team requires that all servers be protected against fileless attacks and that suspicious process behavior be detected in near real-time. You need to recommend a solution that meets these requirements while minimizing administrative effort. What should you include in your recommendation?
⚠ Common exam trap
Candidates often confuse network access control features like just-in-time VM access with endpoint detection and response capabilities, which are distinct and serve different security purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Defender for Endpoint integration and ensure that the automatic provisioning of the Microsoft Defender for Endpoint agent is turned on for all supported machines.
The requirement is for advanced endpoint detection and response, specifically fileless attack detection and behavioral monitoring. Microsoft Defender for Servers Plan 2 includes Defender for Endpoint integration, which delivers these capabilities. Automatic provisioning ensures the agent is deployed to all supported machines with minimal administrative effort, satisfying both the technical and operational requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable just-in-time (JIT) VM access for all servers to limit exposure to brute-force attacks.
Why it's wrong here
JIT VM access reduces the attack surface by opening management ports only when needed. It does not detect fileless attacks or monitor process behavior. It is a network access control feature, not an endpoint detection and response solution, so it fails to meet the stated security requirements for detecting suspicious process behavior.
- ✗
Configure adaptive application controls in Microsoft Defender for Cloud to allow only approved applications to run on the servers.
Why it's wrong here
Adaptive application controls are used to create allowlists of applications that can run on Azure VMs. While this can block unauthorized executables, it does not provide fileless attack detection or behavioral process monitoring. It also requires a learning period and manual approval, which increases administrative effort and does not meet the near real-time detection requirement.
- ✗
Deploy the Log Analytics agent to all servers and create custom alerts based on Windows Security event logs.
Why it's wrong here
While the Log Analytics agent can collect security events and custom alerts can be created, this approach does not provide the advanced fileless attack detection and behavioral monitoring that Defender for Endpoint offers. It also requires significant manual effort to create and maintain alert rules, violating the minimal administrative effort requirement.
- ✓
Enable Microsoft Defender for Endpoint integration and ensure that the automatic provisioning of the Microsoft Defender for Endpoint agent is turned on for all supported machines.
Why this is correct
Defender for Servers Plan 2 includes integration with Microsoft Defender for Endpoint, which provides endpoint detection and response (EDR) capabilities such as fileless attack detection and behavioral monitoring. Enabling automatic provisioning ensures the agent is deployed to all supported machines without manual intervention, meeting the near real-time detection and minimal administrative effort requirements.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.