mediumMultiple Choice
SC-200 Practice Question: A large enterprise uses Microsoft Defender for…
A large enterprise uses Microsoft Defender for Cloud with all enhanced security plans enabled. They want to automatically enable the Defender for Cloud plans on new Azure subscriptions that are created under their management group. Which approach should they use?
⚠ Common exam trap
Candidates often confuse configuring default security policies (which only set recommendation baselines) with the Azure Policy initiative that actually enables the pricing tiers for Defender for Cloud plans on new subscriptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the built-in Azure Policy initiative 'Enable Microsoft Defender for Cloud on all subscriptions' at the management group level.
The built-in Azure Policy initiative 'Enable Microsoft Defender for Cloud on all subscriptions' is designed to be assigned at a management group scope, automatically enabling all Defender for Cloud plans on new subscriptions as they are created under that management group. This leverages Azure Policy's compliance evaluation and remediation tasks to enforce the security plans across the entire hierarchy without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign the built-in Azure Policy initiative 'Enable Microsoft Defender for Cloud on all subscriptions' at the management group level.
Why this is correct
The built-in Azure Policy initiative 'Enable Microsoft Defender for Cloud on all subscriptions' is a policy set designed to apply the Defender plans (including Servers, SQL, and Storage) to every subscription within the assigned scope. When assigned at the management group level, Azure Policy automatically deploys the necessary plan enablement and pricing tier configuration to both existing and future subscriptions, removing the need for manual per-subscription setup. This is the intended native mechanism for centralizing the enablement of Defender plans across an enterprise.
- ✗
Configure 'Continuous export' settings in Defender for Cloud to export policies to Log Analytics for each subscription.
Why it's wrong here
Continuous export is a data-streaming feature in Defender for Cloud that forwards security alerts, recommendations, and findings to a Log Analytics workspace, Event Hub, or similar destination. It does not create or assign any policy that would enable Defender plans on a subscription, nor does it modify the plan configuration or pricing tier. Therefore, while it is useful for centralizing telemetry and enabling downstream analytics, it has absolutely no effect on whether current or future subscriptions have the Defender plans activated.
- ✗
Set the default security policies at the management group level in Defender for Cloud's environment settings.
Why it's wrong here
Setting the default security policies at the management group level in Defender for Cloud's environment settings determines which security benchmarks and controls are evaluated, and which recommendations are displayed. These security policies govern the compliance monitoring scope, but they do not enable the Defender plans themselves—the plans are separate, individually toggleable features with their own pricing tiers. Even if a new subscription inherits those security policies, it will still lack the underlying Defender plan protections unless the plans are explicitly enabled through another mechanism.
- ✗
Enable 'Auto provisioning' for the Log Analytics agent in Defender for Cloud.
Why it's wrong here
Enabling 'Auto provisioning' for the Log Analytics agent (or Azure Monitor Agent) installs the agent on supported virtual machines to collect log and event data that Defender for Cloud can consume. This action only affects data collection on existing and future VMs; it does not enable Defender plans on the subscription, nor does it apply any policy to activate those plans on new subscriptions. Without the corresponding Defender plan being enabled, the collected data is not used for advanced, plan-specific protections, so this alone does not meet the scenario requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A large enterprise uses Microsoft Defender for Cloud with all enhanced security plans (e.g., Defender for Servers, Defender for SQL) enabled on a management group. The security team wants to automatically enable these plans on new Azure subscriptions that are created under this management group. Which approach is the most efficient and scalable?
medium- ✓ A.Use an Azure Policy definition that enforces the Microsoft Defender for Cloud pricing tier (Standard) at the management group scope.
- B.Manually enable the plans for each new subscription when it is created.
- C.Create an Azure Automation runbook that runs on a schedule and enables plans for all subscriptions under the management group.
- D.Use Azure Blueprints to define the Defender for Cloud settings in the blueprint definition.
Why A: Azure Policy can be assigned at the management group scope to enforce the 'Standard' pricing tier for Microsoft Defender for Cloud on all current and future subscriptions. This ensures that when a new subscription is created under that management group, the policy automatically evaluates and remediates the subscription to enable the required Defender plans, providing a fully automated, scalable, and governance-driven approach without manual intervention or custom scripting.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.