mediumMultiple Choice
SC-200 Practice Question: A company uses Microsoft Defender for Cloud with…
A company uses Microsoft Defender for Cloud with enhanced security features enabled. The security team wants to automatically disable the local administrative account on all existing and future Azure virtual machines by applying a guest configuration policy. Which Defender for Cloud feature should they use?
⚠ Common exam trap
Many exam-takers confuse network-level access controls (JIT) or application whitelisting (Adaptive application controls) with OS-level configuration management, which is exclusively handled by Guest configuration (Azure Policy).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Guest configuration (Azure Policy)
Guest configuration (Azure Policy) is the only feature that can audit and remediate settings inside a virtual machine's operating system, such as disabling the local administrative account. Defender for Cloud integrates with Azure Policy's guest configuration extension to enforce desired state configurations on both existing and future VMs via policy assignments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Just-In-Time (JIT) VM access
Why it's wrong here
Just-In-Time (JIT) VM access is a network-layer security control that locks down inbound traffic to management ports such as RDP and SSH, granting temporary access only after a user is approved. It operates solely on NSG rules and does not interact with the guest operating system, so it cannot audit or remediate local account configurations. Disabling an account like a default local administrator requires guest-level policy enforcement, not network access control.
- ✓
Guest configuration (Azure Policy)
Why this is correct
Guest configuration (Azure Policy) is the correct mechanism because it deploys the guest configuration agent into the VM or Arc-enabled machine to audit and remediate settings inside the guest OS. It can apply policy definitions that target local accounts, including disabling unused or default accounts, using PowerShell Desired State Configuration. With the DeployIfNotExists effect, the policy can automatically apply the remediation, making it the only option that physically changes the local account state.
- ✗
Adaptive application controls
Why it's wrong here
Adaptive application controls are a Defender for Cloud feature that uses machine learning to create and enforce allowlists for executables running on your VMs. This feature controls the process execution layer, allowing only trusted applications to start, but it has no awareness of user accounts or local security policies. Therefore, it cannot disable or verify local accounts; its scope is limited to application whitelisting, not identity or guest OS configuration management.
- ✗
Regulatory compliance dashboard
Why it's wrong here
The regulatory compliance dashboard provides an aggregated score of your compliance posture against selected standards such as CIS, NIST, or the Azure Security Benchmark. It is a read-only reporting tool: it does not apply changes to VMs, even if a standard requires disabling local accounts. To actually enforce the required setting, you must assign and remediate a policy like guest configuration, making the dashboard only a monitoring mechanism, not the implementation mechanism.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.