mediumMultiple ChoiceObjective-mapped
SC-200 Practice Question: A company uses Microsoft Defender for Cloud with…
A company uses Microsoft Defender for Cloud with Defender for Servers enabled. The security team wants to integrate a third-party vulnerability assessment solution (e.g., Qualys) and have findings appear in the Defender for Cloud recommendations. What must be done?
⚠ Common exam trap
Many candidates assume Defender for Cloud automatically integrates with any third-party scanner or that enabling MDVM will bridge to third-party tools, when in fact a specific agent installation and connector configuration is required for third-party solutions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the Qualys agent on the VMs and configure the vulnerability assessment solution in Defender for Cloud.
To integrate a third-party vulnerability assessment solution like Qualys with Microsoft Defender for Cloud, you must install the Qualys agent on the VMs and then configure the vulnerability assessment solution in Defender for Cloud. This allows Defender for Cloud to receive and display the vulnerability findings from Qualys as part of its security recommendations. Without this explicit configuration, Defender for Cloud cannot ingest third-party scanner data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Install the Qualys agent on the VMs and configure the vulnerability assessment solution in Defender for Cloud.
Why this is correct
Deploying the Qualys agent on every Virtual Machine is mandatory because Defender for Cloud uses that agent to collect and transmit vulnerability data to the Qualys cloud service. After installation, the solution must be registered under Defender for Cloud's Vulnerability assessment settings, which patches the security policy with the associated plan. Once configured, the Qualys findings appear in the 'Vulnerabilities in your virtual machines should be remediated' recommendation, and auto-provisioning can later be enabled for new VMs.
- ✗
Enable the built-in Microsoft Defender Vulnerability Management (MDVM) solution; it automatically integrates with any third-party scanner.
Why it's wrong here
The built-in MDVM (Microsoft Defender Vulnerability Management) solution relies on the Microsoft Defender for Endpoint sensor, not a third-party Qualys agent, and it does not expose a connector that ingests Qualys or other third-party scanner result streams. Enabling MDVM effectively replaces the need for an external scanner, so it cannot supplement or augment an existing Qualys deployment. If both are enabled, Defender for Cloud prioritizes the built-in solution and ignores third-party findings, which is the opposite of integrating them.
- ✗
Set up automatic provisioning of the Log Analytics agent and enable vulnerability assessment in the regulatory compliance dashboard.
Why it's wrong here
Automatic provisioning of the Log Analytics agent (now the Azure Monitor Agent) deploys software that collects Windows and Linux security events, syslog, and performance counters, but it has no Qualys scanning functionality and cannot transmit vulnerability scan results to Defender for Cloud. The regulatory compliance dashboard aggregates Azure Policy assessments and industry benchmark standards such as ISO, SOC 2, and NIST, yet it has no ingestion pipeline for third-party vulnerability assessment findings. Therefore, pursuing this option leaves the VMs without Qualys and without the corresponding vulnerability recommendations.
- ✗
Nothing; Defender for Cloud automatically scans all Azure VMs for vulnerabilities using the integrated Qualys scanner.
Why it's wrong here
Defender for Cloud does not scan Azure VMs by default using an integrated Qualys scanner; the built-in vulnerability scanner is MDVM, which must be explicitly enabled through a Defender plan and uses the Microsoft Defender for Endpoint (MDE) sensor, not Qualys. The Qualys integration is an opt-in third-party solution that requires a Qualys agent installed on each VM and a subscription registered in the vulnerability assessment settings blade. With neither the MDVM plan nor the Qualys agent configured, the 'Machines should have a vulnerability assessment solution' recommendation remains unhealthy, proving that no automatic third-party scanning is occurring.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.