SC-100 Design security solutions for infrastructure Practice Question
Your company has a Microsoft Defender for Cloud environment with Azure Arc-enabled on-premises servers. The security team wants to ensure that all servers have the Log Analytics agent installed and that missing updates are automatically remediated for critical vulnerabilities. Which policy initiative should you assign to the management group containing these servers?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Security Benchmark
The Azure Security Benchmark initiative includes policies for agent installation and vulnerability remediation. The other options are either not policy initiatives or focus on different aspects like container security or regulatory compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy for Kubernetes
Why it's wrong here
Azure Policy for Kubernetes is a policy engine specifically for AKS and Azure Arc-enabled Kubernetes clusters, enforcing security via Open Policy Agent (OPA)/Gatekeeper admission controls. It does not contain built-in DeployIfNotExists policies that install the Log Analytics agent on on-premises VM instances, nor does it automate remediation of host-level vulnerability findings. Therefore, it cannot satisfy the requirement to deploy agents to on-premises servers.
- ✗
CIS Microsoft Azure Foundations Benchmark
Why it's wrong here
CIS Microsoft Azure Foundations Benchmark is a set of configuration guidelines for securing the Azure platform itself, such as identity, storage, and networking controls. While Defender for Cloud can assess compliance against this benchmark, it is not an initiative that automatically deploys the Log Analytics agent or repairs agent installation failures on on-premises machines. The benchmark's policies focus on auditing and hardening control-plane configurations, not operational agent lifecycle management on IaaS workloads.
- ✗
NIST SP 800-53 R5
Why it's wrong here
NIST SP 800-53 R5 is a catalog of security and privacy controls used for regulatory compliance reporting, not an operational policy initiative for agent management. Defender for Cloud maps its security findings to NIST controls, but this initiative does not include the DeployIfNotExists policy definition required to install the Log Analytics agent on non-Azure servers. It provides visibility and compliance status, but lacks the automated deployment and remediation actions needed for on-premises agent onboarding.
- ✓
Azure Security Benchmark
Why this is correct
Azure Security Benchmark (ASB) is a Microsoft-designed initiative that consolidates security best practices and is implemented as a set of Azure Policy definitions. Within Defender for Cloud, the ASB initiative includes the policy 'Deploy Log Analytics agent on Azure Arc-enabled machines' (and equivalent for Azure VMs), which uses DeployIfNotExists to automatically install the agent on on-premises servers connected via Azure Arc. This same initiative also contains policies for vulnerability remediation, making it the correct choice for agent deployment and remediation workflow.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.