SC-100 Design security solutions for infrastructure Practice Question
Your organization is using Microsoft Defender for Cloud to manage security across multiple Azure subscriptions. You need to ensure that all virtual machines in the subscriptions are monitored by Defender for Cloud and that security alerts are sent to the security operations team. You also need to enforce that any new VMs are automatically onboarded to Defender for Cloud. You have a Log Analytics workspace in the central subscription. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In Defender for Cloud, enable auto-provisioning for the Log Analytics agent at the management group level and specify the central workspace.
Enabling auto-provisioning of the Log Analytics agent at the management group scope ensures all VMs across subscriptions are monitored and new VMs are automatically onboarded. Option A is wrong because configuring only the workspace does not auto-provision. Option B is wrong because Azure Policy can enforce agent deployment, but auto-provisioning is simpler and more direct. Option D is wrong because enabling Defender for Cloud at the subscription level does not automatically install the agent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Defender for Cloud on each subscription and configure email notifications for alerts.
Why it's wrong here
Enabling Defender for Cloud on each subscription activates the security monitoring plan but does not deploy the Log Analytics agent to any VMs. Email notifications are a separate alerting mechanism that only sends messages when threats are detected; without the agent, the required raw security data such as baselines, patch status, and endpoint telemetry is never collected. Consequently, the VMs remain unmonitored at the data level, and the notifications would rarely have meaningful content to act on.
- ✗
Assign an Azure Policy that deploys the Log Analytics agent to all VMs.
Why it's wrong here
Assigning an Azure Policy that deploys the Log Analytics agent is a valid but inferior approach; it requires you to manually create and manage the policy initiative, while Defender for Cloud's built-in auto-provisioning already orchestrates agent installation across all subscriptions. Even with the policy, you still need to specify a Log Analytics workspace manually, and the policy only covers existing and future VMs within its assignment scope, but it does not integrate with Defender for Cloud's security settings or provide the seamless management experience of auto-provisioning. Auto-provisioning is the recommended, lowest-friction method because it is designed precisely for this purpose.
- ✓
In Defender for Cloud, enable auto-provisioning for the Log Analytics agent at the management group level and specify the central workspace.
Why this is correct
Enabling auto-provisioning at the management group level is the correct approach because it applies the Log Analytics agent deployment setting to every subscription under that group, guaranteeing unified coverage. When you specify a central workspace, all VMs report to the same Log Analytics workspace, enabling a single pane-of-glass view for security analytics and cross-subscription hunting. Auto-provisioning also automatically installs the agent on new VMs as they are created, closing the coverage gap that exists with manual or policy-based deployment methods.
- ✗
Create a Log Analytics workspace in each subscription and configure Defender for Cloud to use that workspace.
Why it's wrong here
Creating a separate Log Analytics workspace in each subscription and configuring Defender for Cloud to use it does not install the Log Analytics agent on any VM; it only changes the destination for data that is never being sent. Additionally, using multiple workspaces fragments the security data across subscription boundaries, making it harder to perform cross-subscription queries and maintain a central retention and governance strategy. This approach ignores auto-provisioning and would require a separate agent deployment mechanism, which is exactly what the question is trying to solve.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.