SC-100 Practice Question: Design security solutions for applications and data
Your organization is using Microsoft Defender for Cloud to assess the security posture of your Azure resources. You need to ensure that all storage accounts have secure transfer required enabled. Which Defender for Cloud feature should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policies and initiatives
Security policies and initiatives in Microsoft Defender for Cloud are the correct choice because they let you define and assign Azure Policy definitions—such as the built-in 'Secure transfer to storage accounts should be enabled' policy—that continuously assess storage accounts and flag any that lack Secure transfer required (HTTPS-only). This directly addresses the requirement to ensure all storage accounts have secure transfer enabled. File integrity monitoring is incorrect because it tracks changes to OS files and registry keys on VMs, not storage account configuration. Adaptive network hardening is incorrect because it generates NSG rules based on traffic analysis, and Just-In-Time VM access is incorrect because it restricts inbound VM ports on demand—neither evaluates storage account encryption-in-transit settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security policies and initiatives
Why this is correct
Security policies and initiatives in Microsoft Defender for Cloud are built on Azure Policy and include regulatory compliance frameworks like the Microsoft cloud security benchmark. These initiatives contain policy definitions that can audit, deny, or deploy settings such as 'Secure transfer to storage accounts should be enabled' (supportsHttpsTrafficOnly). When assigned to a subscription, Defender for Cloud continuously evaluates storage account compliance and can enforce secure transfer automatically via a DeployIfNotExists effect, directly addressing the requirement to enable secure transfer.
- ✗
File integrity monitoring
Why it's wrong here
File Integrity Monitoring (FIM) in Defender for Cloud is an agent-based workload protection feature that tracks changes to critical OS files, registry keys, and binaries on virtual machines. It records file attributes, hashes, and paths to detect tampering, but it does not evaluate the configuration of Azure PaaS storage accounts, including the 'Secure transfer required' property. FIM operates at the guest OS file level, not at the Azure Resource Manager resource configuration layer, so it is irrelevant to enforcing HTTPS on storage endpoints.
- ✗
Adaptive network hardening
Why it's wrong here
Adaptive Network Hardening (ANH) analyzes internet-facing virtual machine traffic patterns using machine learning and produces recommendations to tighten Network Security Group (NSG) rules, such as restricting allowed IP ranges and ports. NSGs act as a network firewall for VM subnets and NICs, but they do not govern the data-plane settings of Azure Storage accounts, such as the 'Secure transfer required' flag that forces HTTPS/TLS. ANH has no visibility into or control over storage account properties, so it cannot enforce or validate secure transfer for storage.
- ✗
Just-In-Time VM access
Why it's wrong here
Just-In-Time (JIT) VM access reduces the attack surface of Azure virtual machines by temporarily opening management ports (e.g., RDP/SSH) through NSG rules for a limited time after approval. If focuses entirely on inbound network access to VM public IPs and NSG rules; it has no mechanism to read, audit, or modify storage account properties like 'supportsHttpsTrafficOnly'. Since JIT is scoped to VM network security and not to Azure resource configuration, it is not a tool for enforcing secure transfer on a storage account.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.