SC-100 Design security solutions for infrastructure Practice Question
Your organization plans to use Microsoft Defender for Cloud to protect hybrid workloads across Azure and on-premises servers. You need to ensure that security policies are consistently applied and that compliance status is monitored centrally. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create Azure Policy initiatives and assign them to management groups and subscriptions.
The correct option is B: Create Azure Policy initiatives and assign them to management groups and subscriptions. Azure Policy initiatives (policy sets) are the mechanism Microsoft Defender for Cloud uses to evaluate and enforce security controls consistently across Azure and hybrid/Arc-connected servers, and assigning them at management-group scope cascades the same definitions to all child subscriptions so compliance is monitored centrally in Defender for Cloud's regulatory compliance dashboard. Options A and C do not fit because manually applying Azure Security Benchmark recommendations or configuring policies only inside Defender for Cloud lacks the scalable, centrally assigned initiative/scope model needed for consistent enforcement. Option D is wrong because Azure Blueprints is a deprecated orchestration service for packaging role assignments, policies, and templates at subscription scope, not the recommended way to assign policy initiatives to management groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement Azure Security Benchmark recommendations manually.
Why it's wrong here
Manually implementing Azure Security Benchmark recommendations relies on ad-hoc engineering work to align each resource configuration against the controls. This approach has no continuous monitoring, so configuration drift can silently move workloads out of compliance and there is no auditable enforcement mechanism. Azure Policy-based assignments are required to automatically assess and remediate resources at scale, making a manual process unsuitable for enterprise environments. Without automation, the effort does not scale across management groups and subscriptions.
- ✓
Create Azure Policy initiatives and assign them to management groups and subscriptions.
Why this is correct
Creating Azure Policy initiatives—such as the built-in Microsoft Cloud Security Benchmark initiative—and assigning them to management groups and subscriptions is the correct approach because Defender for Cloud pulls its recommendations and regulatory compliance findings directly from these policy assignments. The assignments define audit, Deny, and DeployIfNotExists effects that enforce secure configuration continuously across native Azure resources and hybrid machines connected via Azure Arc. This model gives organizations centralized governance, automated remediation, and a clear audit trail for compliance evidence. It is the foundation that makes Defender for Cloud's recommendations actionable and repeatable.
- ✗
Configure security policies directly in Microsoft Defender for Cloud.
Why it's wrong here
Defender for Cloud's blade labeled 'Security policies' lets you view and toggle the built-in policy initiatives that Azure Policy already assigned, but it does not provide a native interface to create new policy definitions or modify the underlying JSON rules. Any changes made there merely enable or disable specific recommendations or adjust parameters on existing assignments, so direct configuration has very limited authority. The actual evaluation and enforcement occur in the Azure Policy engine, meaning true custom policies and initiatives must be managed through Azure Policy tools or infrastructure-as-code templates. Attempting to govern security entirely from Defender for Cloud's portal therefore fails to address the need for custom compliance requirements.
- ✗
Deploy Azure Blueprints to assign policies to management groups.
Why it's wrong here
Azure Blueprints is deprecated and has been retired, so planning to assign policies through it is not a sustainable path. While Blueprints could include policy assignments as artifacts, the service never provided the full lifecycle management of policy definitions and initiatives that Azure Policy does today. Microsoft now directs customers to use deployment stacks, template specs, and native Azure Policy assignments to achieve consistent governance across management groups and subscriptions. Building new governance on a deprecated service also prevents the organization from receiving ongoing support, updates, and feature improvements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.