mediumMultiple Choice
SC-200 Adaptive network hardening Practice Question
A company uses Microsoft Defender for Cloud to protect Azure virtual machines. The security team receives an alert indicating that a VM is communicating with a known malicious IP address. Which Defender for Cloud feature can be used to automatically block outbound traffic to that IP address by adjusting the network security group (NSG)?
⚠ Common exam trap
Do not confuse adaptive network hardening with just-in-time VM access. JIT only manages inbound management ports on a schedule. Adaptive network hardening only recommends inbound NSG rules; neither automatically blocks outbound traffic to a known-malicious destination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adaptive network hardening
None of the listed Defender for Cloud features automatically blocks outbound traffic to a known malicious IP address by adjusting the NSG. Adaptive network hardening only analyzes traffic patterns and threat intelligence to recommend inbound NSG hardening rules; it does not automatically apply outbound deny rules. Automatic outbound blocking would typically require Azure Firewall threat intelligence, a Microsoft Sentinel automation playbook, or a manually configured NSG deny rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Adaptive application controls
Why it's wrong here
Adaptive application controls are not used for network NSG traffic blocking; they manage allowed applications on VMs.
- ✗
Just-in-time VM access
Why it's wrong here
Just-in-time VM access controls inbound management ports, not outbound traffic to a malicious IP address.
- ✓
Adaptive network hardening
Why this is correct
Adaptive network hardening only recommends inbound NSG rules based on traffic patterns and threat intelligence; it does not automatically block outbound malicious traffic.
- ✗
File integrity monitoring
Why it's wrong here
File integrity monitoring detects changes to files and system settings, not network traffic.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security team uses Microsoft Defender for Cloud to protect Azure virtual machines. They notice that a VM is generating alerts for unusual outbound connections. The team wants to use a Defender for Cloud feature that learns the VM's typical network behavior and provides recommendations to tighten network security group rules, while also alerting on suspicious deviations. Which feature should they enable?
medium- ✓ A.Adaptive network hardening
- B.Just-In-Time VM access
- C.File integrity monitoring
- D.Vulnerability scanning
Why A: Adaptive network hardening (ANH) is the correct feature because it uses machine learning to learn a VM's typical traffic patterns (including outbound connections), then analyzes the current Network Security Group (NSG) rules against those learned patterns. It provides recommendations to tighten NSG rules to allow only the traffic that is actually used, and it generates security alerts when it detects deviations from the learned baseline, such as unusual outbound connections.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.