SC-100 Design security solutions for infrastructure Practice Question
Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. The security team wants to ensure that all virtual machines are covered by Defender for Cloud's vulnerability assessment capabilities. Which plan must be enabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Servers Plan 2
Microsoft Defender for Servers Plan 2 is the correct choice because it is the Defender for Cloud plan that includes built-in vulnerability assessment for Azure and hybrid virtual machines, using the integrated Microsoft Defender Vulnerability Management scanner. Enabling this plan on the subscription ensures VMs receive agentless or agent-based vulnerability scanning and findings surface in Defender for Cloud's recommendations. Microsoft Defender for Storage protects storage accounts, not VMs, so it does not provide VM vulnerability assessment. Microsoft Defender for Cloud Apps is a CASB solution for SaaS application visibility and control, and Defender CSPM provides posture management and attack path analysis but not the VM vulnerability assessment capability itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Storage
Why it's wrong here
Microsoft Defender for Storage is a workload protection plan that safeguards Azure Blob, Files, and Data Lake Storage by detecting abnormal access patterns, malware uploads, and data exfiltration attempts. It deploys its monitoring directly on the storage infrastructure, not on guest operating systems, so it has no visibility into VM OS packages, running services, or registry keys. As a result, it cannot perform vulnerability assessments for virtual machines, which is outside its security domain.
- ✓
Microsoft Defender for Servers Plan 2
Why this is correct
Microsoft Defender for Servers Plan 2 is the correct selection because it includes the Microsoft Defender Vulnerability Management add-on, which uses an agent (or agentless integration) to continuously scan VM operating systems and installed applications for known CVEs and misconfigurations. The scan results flow directly into Defender for Cloud's security recommendations, and findings are prioritized using real-world threat intelligence and exploit-maturity information. This makes Plan 2 the only option among the choices that provides a dedicated, integrated VM vulnerability assessment capability.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps operates as a Cloud Access Security Broker (CASB), protecting SaaS applications like Microsoft 365, Google Workspace, and Salesforce through API connectors, session controls, and user-behavior analytics. It focuses on shadow IT discovery, cloud app consent, and data-loss prevention, and it acquires telemetry from cloud APIs and proxies rather than from guest agents inside VMs. Consequently, it cannot enumerate CVEs or missing security patches on virtual machines, so it is not a tool for VM vulnerability assessment.
- ✗
Defender Cloud Security Posture Management (CSPM)
Why it's wrong here
Defender Cloud Security Posture Management (CSPM) is a plan that assesses the entire cloud estate's security posture against standards such as CIS and Azure Security Benchmark, generating compliance scores and attack-path analysis across resources. While it can flag misconfigurations that expose VMs—such as overly broad network security groups or unmanaged disks—it does not install agents in guest OSes and lacks the component that inventories installed software levels and OS package versions. Thus, it does not deliver the granular, per-VM vulnerability scanning that is exclusive to Microsoft Defender for Servers Plan 2.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.