Courseiva
mediumMultiple Choice

SC-200 Adaptive network hardening Practice Question

A company uses Microsoft Defender for Cloud to protect Azure virtual machines. The security team receives an alert indicating that a VM is communicating with a known malicious IP address. Which Defender for Cloud feature can be used to automatically block outbound traffic to that IP address by adjusting the network security group (NSG)?

⚠ Common exam trap

Do not confuse adaptive network hardening with just-in-time VM access. JIT only manages inbound management ports on a schedule. Adaptive network hardening only recommends inbound NSG rules; neither automatically blocks outbound traffic to a known-malicious destination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adaptive network hardening

None of the listed Defender for Cloud features automatically blocks outbound traffic to a known malicious IP address by adjusting the NSG. Adaptive network hardening only analyzes traffic patterns and threat intelligence to recommend inbound NSG hardening rules; it does not automatically apply outbound deny rules. Automatic outbound blocking would typically require Azure Firewall threat intelligence, a Microsoft Sentinel automation playbook, or a manually configured NSG deny rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adaptive application controls

    Why it's wrong here

    Adaptive application controls are not used for network NSG traffic blocking; they manage allowed applications on VMs.

  • ✗

    Just-in-time VM access

    Why it's wrong here

    Just-in-time VM access controls inbound management ports, not outbound traffic to a malicious IP address.

  • ✓

    Adaptive network hardening

    Why this is correct

    Adaptive network hardening only recommends inbound NSG rules based on traffic patterns and threat intelligence; it does not automatically block outbound malicious traffic.

  • ✗

    File integrity monitoring

    Why it's wrong here

    File integrity monitoring detects changes to files and system settings, not network traffic.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security team uses Microsoft Defender for Cloud to protect Azure virtual machines. They notice that a VM is generating alerts for unusual outbound connections. The team wants to use a Defender for Cloud feature that learns the VM's typical network behavior and provides recommendations to tighten network security group rules, while also alerting on suspicious deviations. Which feature should they enable?

medium
  • ✓ A.Adaptive network hardening
  • B.Just-In-Time VM access
  • C.File integrity monitoring
  • D.Vulnerability scanning

Why A: Adaptive network hardening (ANH) is the correct feature because it uses machine learning to learn a VM's typical traffic patterns (including outbound connections), then analyzes the current Network Security Group (NSG) rules against those learned patterns. It provides recommendations to tighten NSG rules to allow only the traffic that is actually used, and it generates security alerts when it detects deviations from the learned baseline, such as unusual outbound connections.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.