Courseiva
easyMultiple ChoiceObjective-mapped

SC-200 Practice Question: A security administrator in Microsoft Defender…

A security administrator in Microsoft Defender for Cloud notices that the Secure Score is lower than expected. Which action would most effectively improve the Secure Score by reducing the attack surface?

⚠ Common exam trap

Test-takers frequently confuse 'reducing the attack surface' with 'improving detection' (e.g., enabling auditing or installing EDR agents), but the Secure Score's attack surface reduction category specifically rewards proactive controls like JIT that limit exposure, not reactive monitoring or alert management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Just-in-Time (JIT) VM access for all virtual machines.

Enabling Just-in-Time (JIT) VM access reduces the attack surface by locking down inbound traffic to Azure VMs, allowing only authorized users to open specific ports (e.g., RDP 3389, SSH 22) for a limited time. This directly improves the Secure Score because Microsoft Defender for Cloud includes JIT recommendations as a high-impact security control, and implementing it reduces the number of exposed management ports that attackers can target.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Just-in-Time (JIT) VM access for all virtual machines.

    Why this is correct

    Enabling Just-in-Time (JIT) VM access is a built-in security recommendation in Microsoft Defender for Cloud that directly improves your Secure Score through the 'Enable management ports to be closed just-in-time' control. By restricting access to management ports (SSH/RDP) to authorized users, approved IP ranges, and limited time windows, JIT reduces the network attack surface. This is a high-impact, infrastructure-level control that is part of the default Azure Security Benchmark initiative, so implementing it yields an immediate and measurable increase in the Secure Score.

  • Configure auditing on all SQL databases.

    Why it's wrong here

    Configuring auditing on all SQL databases is a data compliance and forensic best practice, but it is not part of the core Secure Score controls evaluated in the default dashboard. SQL auditing captures database events for detection and compliance, but it does not directly reduce the attack surface or address a specific recommendation that powers the score in the same way as infrastructure hardening controls. As a result, while it is valuable for log-based detection and regulatory reporting, it will not produce a meaningful increase in the Secure Score because the default policy initiative does not prioritize this as a scoring control.

  • Disable all low-severity security alerts in the subscription.

    Why it's wrong here

    Disabling low-severity security alerts in your subscription does not improve Secure Score, and it actually degrades your security posture by hiding potential threats. Secure Score is calculated from the compliance state of security recommendations, not from alert severity; alerts are generated from active threats and are not part of the score calculation at all. Disabling alerts simply suppresses notifications and reduces visibility, which can cause the score to indirectly worsen if important recommendations go unaddressed due to less awareness of suspicious activity.

  • Install EDR agents on all on-premises servers.

    Why it's wrong here

    Installing EDR agents (Microsoft Defender for Endpoint) on all on-premises servers is a feature of Microsoft Defender for Endpoint, not a built-in Secure Score control in Defender for Cloud. While Defender for Cloud can onboard on-premises servers and the MDE integration may generate related recommendations, the Secure Score is driven by Azure resource-specific recommendations such as JIT, disk encryption, and MFA. Furthermore, the default Secure Score dashboard focuses on Azure resources; on-premises servers are not scored until they are onboarded as Azure Arc resources, so simply installing EDR agents does not influence the score in the default dashboard.

About these practice questions

This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.