Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization plans to use Microsoft Defender for Cloud to protect a hybrid environment with servers in Azure and on-premises. You need to ensure that security policies are consistently applied across all servers. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Onboard all servers to Azure Arc and assign Defender for Cloud policies.

Option A is correct because onboarding on-premises and Azure servers to Azure Arc makes them manageable as connected machine resources in Azure, allowing Defender for Cloud policies and plans (such as Defender for Servers) to be applied consistently across the hybrid estate. Azure Arc is the supported mechanism for extending Azure management and Defender for Cloud coverage to non-Azure servers. Option B is wrong because Azure Automation State Configuration (DSC) enforces configuration state, not Defender for Cloud security policies. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution for analytics and detection, not policy assignment. Option D is wrong because Azure Policy guest configuration audits/configures in-guest settings but does not itself onboard servers to Defender for Cloud or apply its security plans.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Onboard all servers to Azure Arc and assign Defender for Cloud policies.

    Why this is correct

    Onboarding servers to Azure Arc registers them as Azure resources, allowing Defender for Cloud policies to be assigned and enforced consistently across on-premises and multi-cloud workloads. This enables security posture assessments, vulnerability management, and Microsoft Defender plans on non-Azure machines. Arc is the required control plane for applying Azure security policy to servers outside Azure.

  • ✗

    Deploy Azure Automation State Configuration (DSC) to all servers.

    Why it's wrong here

    Azure Automation State Configuration (DSC) pushes desired configuration states to manage drift, such as installing features or setting registry keys, but it is not a security policy engine. It cannot enforce Defender for Cloud's security baselines, vulnerability scanning, or Microsoft Defender plans. DSC addresses configuration management; Defender for Cloud requires the Azure Arc agent and policy assignments for its protections.

  • ✗

    Connect all servers to Microsoft Sentinel and use analytics rules.

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR that collects and correlates telemetry via data connectors and analytics rules for threat detection and incident response. Connecting servers to Sentinel does not imply onboarding to Defender for Cloud; Sentinel analyzes logs, whereas Defender for Cloud assigns security policies and audits compliance. Sentinel is a downstream detection layer, not a policy enforcement service.

  • ✗

    Use Azure Policy with guest configuration on all servers.

    Why it's wrong here

    Azure Policy guest configuration audits or configures settings inside a VM, but for on-premises servers it requires the Azure Arc agent to make the machine visible to Azure Policy. Without Arc, guest configuration assignments cannot be applied to non-Azure servers, and guest configuration itself is limited to guest-level settings rather than the full Defender for Cloud workload protection stack. Thus it is not a substitute for Arc onboarding plus Defender for Cloud plans.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.