Courseiva
easyMultiple ChoiceObjective-mapped

SC-200 Practice Question: A security analyst is using Microsoft Defender…

A security analyst is using Microsoft Defender for Cloud's adaptive application controls (AAC) to allowlist trusted applications on Azure VMs. After enabling AAC and running in 'Audit' mode for a week, the analyst wants to switch to 'Enforce' mode. Which pre-requisite must be met before enforcement can be applied?

⚠ Common exam trap

Watch out — candidates often assume any supported OS or license is sufficient, but Microsoft specifically requires the two-week audit baseline to prevent enforcement from blocking legitimate applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The VM must have a baseline of allowed applications generated from at least two weeks of audit data.

Adaptive application controls require a minimum of two weeks of audit data to establish a reliable baseline of allowed applications before enforcement can be applied. This baseline ensures that legitimate applications are not blocked when switching from Audit to Enforce mode, reducing false positives and operational disruptions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The VM must have the Guest Configuration extension installed.

    Why it's wrong here

    The Guest Configuration extension is an Azure Policy component used for in-guest compliance checks of settings such as registry keys, services, and security baselines—it is not involved in Adaptive Application Controls (AAC). AAC relies on the Log Analytics agent or Azure Monitor Agent to collect running application inventory and process execution telemetry from the VM. Installing the Guest Configuration extension therefore does not satisfy any AAC prerequisite, and its absence is not why enforcement mode cannot be enabled.

  • A valid Microsoft Defender for Servers Plan 2 license must be assigned to the VM.

    Why it's wrong here

    Defender for Cloud (with Defender for Servers Plan 2) is required for AAC. But that's already in place if AAC is enabled. The specific pre-requisite for enforce mode is having a baseline from audit mode.

  • The VM must have a baseline of allowed applications generated from at least two weeks of audit data.

    Why this is correct

    Adaptive Application Controls must first run in audit-only mode for at least two weeks so Defender for Cloud can observe normal application usage and build a baseline of known-good executables, including file paths, publishers, and hashes. This audit-derived baseline is the specific prerequisite for switching a policy to enforce mode; without it, the allowlist would be incomplete and would cause legitimate applications to be blocked. Therefore, having a baseline generated from at least two weeks of audit data is the required condition before enforcement can be safely enabled.

  • The VM must be running on a supported operating system like Windows Server 2016 or later.

    Why it's wrong here

    Running a supported operating system is a general requirement for onboarding a VM to Microsoft Defender for Cloud and for enabling Adaptive Application Controls at all, but it is not the distinct condition for moving from audit mode to enforcement mode. If AAC is already enabled on the VM, the OS is already supported, so this factor is not the missing prerequisite. The actual gate for enforcement is the existence of a two-week audit-derived baseline of allowed applications, not the OS version or SKU.

About these practice questions

This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.