SC-100 Design security solutions for infrastructure Practice Question
Your organization uses Microsoft Defender for Cloud to assess security posture. You need to design a solution that automatically applies a security baseline to new Azure VMs. Which feature should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy with Guest Configuration
Azure Policy with Guest Configuration is the correct choice because it uses the Guest Configuration extension (via the Azure Connected Machine/VM agent) to audit and enforce OS-level settings inside Azure VMs, including applying security baselines such as the Windows or Linux security baseline definitions. It continuously evaluates machines against the policy and can deploy configuration assignments to new VMs automatically, which directly matches the requirement to apply a baseline to new Azure VMs. The regulatory compliance dashboard (A) only reports compliance status against standards and does not apply baselines. Azure Update Management (B) handles OS patch orchestration, not security baseline configuration. Azure Automation State Configuration (C) can apply DSC configurations but is a separate, more manual pull/push mechanism and is not the Defender for Cloud-integrated baseline enforcement feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud regulatory compliance dashboard
Why it's wrong here
Microsoft Defender for Cloud's regulatory compliance dashboard is a reporting and visibility tool that aggregates compliance posture against standards like CIS and NIST. It continuously assesses your environment and surfaces recommendations, but it does not automatically apply or remediate security baselines on VMs. Enforcement requires separate mechanisms such as Azure Policy, making it insufficient for the stated requirement of automatically applying baselines.
- ✗
Azure Update Management
Why it's wrong here
Azure Update Management is designed specifically for managing operating system updates and patches, including patch compliance and scheduled deployments. It does not interpret or enforce security baseline configurations such as CIS benchmarks or Microsoft security guides, which are policy-based settings rather than software updates. Thus, it cannot automatically apply baselines to VMs, making it the wrong choice for this scenario.
- ✗
Azure Automation State Configuration (DSC)
Why it's wrong here
Azure Automation State Configuration (DSC) can apply PowerShell Desired State Configuration to VMs, but it requires custom DSC configurations and pull server or compilation infrastructure to enforce baselines. It lacks the native integration, built-in baseline definitions, and automatic compliance reporting that Azure Policy's Guest Configuration provides, and is considered a legacy approach. For modern, cloud-native baseline enforcement, Azure Policy is the recommended service.
- ✓
Azure Policy with Guest Configuration
Why this is correct
Azure Policy with Guest Configuration automatically applies and enforces security baselines inside VMs by deploying the Guest Configuration extension and evaluating OS settings against built-in policy definitions. It provides continuous compliance assessment, can proactively remediate non-compliant resources, and integrates with Microsoft Defender for Cloud's recommendations. This native, scalable solution directly meets the requirement to automatically apply baselines without custom scripting.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.