Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization uses Microsoft Defender for Cloud to secure a hybrid environment. You need to ensure that virtual machines running on-premises are assessed for security misconfigurations. What should you deploy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Arc on the on-premises servers

Azure Arc on the on-premises servers (option C) is correct because Azure Arc projects non-Azure machines into Azure as connected machine resources, which is the prerequisite for Defender for Cloud to assess on-premises VMs for security misconfigurations via the Azure Monitor Agent and its recommendations. Without Arc-enabling the servers, Defender for Cloud cannot treat them as supported compute resources for misconfiguration assessment. Option A (Log Analytics agent) only collects log/telemetry data and does not by itself enable Defender for Cloud's security posture assessment of on-premises machines. Option B (Vulnerability Assessment solution) addresses CVE scanning rather than general security misconfiguration assessment, and it also depends on the machine already being onboarded. Option D (Azure Policy guest configuration) audits settings inside Azure VMs and Arc-enabled machines but is not the deployment that enables Defender for Cloud assessment of on-premises servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Log Analytics agent on the on-premises servers

    Why it's wrong here

    The Log Analytics agent (or its successor, the Azure Monitor agent) is a data-collection component that forwards event and performance data to a Log Analytics workspace. Installing it on an on-premises server does not create an Azure Resource Manager resource for that machine, so Defender for Cloud cannot see it as a manageable asset. Without Azure Arc to establish that control-plane identity, Defender for Cloud has no resource ID to associate with security assessments or recommendations, making the agent alone insufficient.

  • ✗

    Microsoft Defender for Cloud's Vulnerability Assessment solution

    Why it's wrong here

    Microsoft Defender for Cloud's vulnerability assessment option—whether using Qualys or Microsoft Defender Vulnerability Management—is an extension that runs on an already-onboarded Azure resource. For on-premises servers, that onboarding requires Azure Arc first; otherwise, there is no Azure resource object for the scanner to be attached to and no place for findings to be written into Defender for Cloud's compliance database. The vulnerability assessment solution is a secondary capability that depends on Arc-enabled infrastructure, not a replacement for it.

  • ✓

    Azure Arc on the on-premises servers

    Why this is correct

    Azure Arc-enabled servers uses the Connected Machine agent to register on-premises machines as full Azure resources with resource IDs in Azure Resource Manager. This registration is what enables Defender for Cloud to perform security assessments, monitor for vulnerabilities, and produce compliance recommendations across hybrid workloads. By placing the on-premises server under Azure's management plane, Arc is the essential prerequisite that unlocks Defender for Cloud's full set of features for machines outside Azure.

  • ✗

    Azure Policy guest configuration

    Why it's wrong here

    Azure Policy Guest Configuration audits and applies configuration settings inside a virtual or physical machine, such as registry keys, installed applications, or Windows security baselines, through Azure Policy assignments. It does not, by itself, activate Defender for Cloud security assessments or vulnerability scanning, and for on-premises servers it also requires Azure Arc to give the machine an Azure resource identity. Guest configuration is one of many Azure management services that assumes the machine is already represented in Azure, not the mechanism that enables Defender for Cloud.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.