mediumMultiple ChoiceObjective-mapped
SC-200 Practice Question: A company runs its critical workloads on Azure…
A company runs its critical workloads on Azure Kubernetes Service (AKS). The security team wants to use Microsoft Defender for Cloud to protect the AKS clusters. After enabling Defender for Cloud on the subscription, they also need to enable the Defender for Containers plan. Which of the following capabilities becomes available specifically after enabling the Defender for Containers plan (with the plan turned on)?
⚠ Common exam trap
Watch out — candidates often confuse the general security monitoring capabilities of Defender for Cloud (like audit log streaming or policy enforcement) with the specific runtime threat detection that only the Defender for Containers plan enables, leading them to select options that are available without the plan or require separate configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security alerts for container runtime threats, such as privilege escalation in a container.
Enabling the Defender for Containers plan in Microsoft Defender for Cloud activates host-level and cluster-level threat detection for AKS, including runtime threat protection. This allows Defender for Cloud to generate security alerts for container-specific threats such as privilege escalation, container breakout, and suspicious process execution within containers, which are not available with just the basic Defender for Cloud enabled on the subscription.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy for Kubernetes add-on installation to enforce pod security policies.
Why it's wrong here
The Azure Policy for Kubernetes add-on is an independent governance component that enforces compliance guardrails like Pod Security Policies or allowed container images. It evaluates and blocks non-compliant resource creation but does not perform runtime behavioral analysis or generate security alerts. While Defender for Containers can incorporate policy for compliance, installing this add-on is not a benefit that comes from enabling the plan itself.
- ✗
Kubernetes audit logs are automatically streamed to the Log Analytics workspace.
Why it's wrong here
AKS audit logs are not automatically streamed to a Log Analytics workspace; you must explicitly configure diagnostic settings to route them. Even when streaming is enabled, raw audit logs alone provide no threat detection—they are merely a data source. Defender for Containers consumes those logs to generate behavioral alerts, but the log streaming is a prerequisite configuration, not an outcome or unique capability of the plan.
- ✓
Security alerts for container runtime threats, such as privilege escalation in a container.
Why this is correct
Defender for Containers provides advanced runtime threat detection that analyzes Kubernetes audit logs and container activity using behavioral analytics. It specifically identifies container runtime threats such as privilege escalation inside a container, container breakouts, and suspicious process execution. This capability to generate actionable, security alerts is the core value of the plan and distinguishes it from static policy enforcement or raw log ingestion.
- ✗
Integration with Microsoft Sentinel for monitoring AKS logs.
Why it's wrong here
Microsoft Sentinel is a separate SIEM product that requires its own data connector configuration to ingest AKS logs. This integration can be implemented independently of Defender for Containers and does not require the Defender plan to be enabled. Sentinel provides centralized monitoring, investigation, and hunting capabilities, but it is not a feature or benefit that the Defender for Containers plan delivers directly.
Go deeper
Related to this question
About these practice questions
One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Microsoft Defender for Cloud to protect an Azure Kubernetes Service (AKS) cluster. The security team wants to receive security alerts about suspicious activities within the cluster, such as a container running with root privileges or attempts to read sensitive host paths. Which Defender for Cloud plan must be enabled to generate these alerts?
medium- A.Defender for Servers
- ✓ B.Defender for Containers
- C.Defender for Cloud Apps
- D.Defender for SQL
Why B: Defender for Containers is the specific plan that provides threat detection for Azure Kubernetes Service (AKS) clusters, including alerts for suspicious activities such as containers running with root privileges or attempts to read sensitive host paths. This plan monitors the Kubernetes control plane and container runtime to generate security alerts based on Kubernetes audit logs and container-specific signals.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.