Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization is deploying Microsoft Defender for Cloud to secure a hybrid environment with workloads in Azure and on-premises. You need to ensure that all servers are covered by Defender for Cloud's plans. Which two actions should you take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the Azure Connected Machine agent (Azure Arc) on on-premises servers.

The correct actions are A and C. Installing the Azure Connected Machine agent (Azure Arc) on on-premises servers is required to project non-Azure machines into Azure so Defender for Cloud can see and manage them, and enabling the Defender for Cloud plans (e.g., Defender for Servers) on the Azure subscription activates the actual protection plans that cover those servers. Option B is insufficient because foundational CSPM only provides posture assessment and does not enable workload protection plans such as Defender for Servers. Option D is not sufficient by itself because the Azure Monitor Agent collects monitoring data but does not onboard on-premises servers into Defender for Cloud without Azure Arc and the relevant Defender plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Install the Azure Connected Machine agent (Azure Arc) on on-premises servers.

    Why this is correct

    Azure Arc's Connected Machine agent projects non-Azure servers into Azure Resource Manager, making them visible to Microsoft Defender for Cloud so its server protection plans can be enabled and billed against them. This satisfies the stem's requirement to cover on-premises servers, which Defender for Cloud cannot natively discover without Arc enrolment.

  • ✗

    Enable only the foundational cloud security posture management (CSPM) on the subscription.

    Why it's wrong here

    Foundational CSPM only assesses posture and generates recommendations; it does not extend Defender plans to servers. It is the right choice when licensing cost must stay minimal and only configuration benchmarking is required, not workload protection.

  • ✓

    Enable the Defender for Cloud plans (e.g., Defender for Servers) on the Azure subscription.

    Why this is correct

    Enabling Defender for Servers on the Azure subscription automatically provisions coverage for Azure VMs and Arc-connected machines within that subscription. This satisfies the hybrid requirement because Azure Arc extends the same subscription-level plan to on-premises servers, so no separate onboarding is needed.

  • ✗

    Deploy the Azure Monitor Agent to all on-premises servers.

    Why it's wrong here

    Azure Monitor Agent collects telemetry but does not itself enrol servers into Defender for Cloud plans; on-premises machines need Azure Arc onboarding first. AMA is correct for gathering logs and metrics once a server is already connected and covered.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.