Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security team uses Microsoft Defender for Cloud…

A security team uses Microsoft Defender for Cloud to protect Azure virtual machines. They notice that a VM is generating alerts for unusual outbound connections. The team wants to use a Defender for Cloud feature that learns the VM's typical network behavior and provides recommendations to tighten network security group rules, while also alerting on suspicious deviations. Which feature should they enable?

⚠ Common exam trap

Many exam-takers confuse Just-In-Time VM access (which also deals with network security) with adaptive network hardening, but JIT only manages inbound port access, not outbound traffic analysis or rule tightening based on learned behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adaptive network hardening

Adaptive network hardening (ANH) is the correct feature because it uses machine learning to learn a VM's typical traffic patterns (including outbound connections), then analyzes the current Network Security Group (NSG) rules against those learned patterns. It provides recommendations to tighten NSG rules to allow only the traffic that is actually used, and it generates security alerts when it detects deviations from the learned baseline, such as unusual outbound connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Adaptive network hardening

    Why this is correct

    Adaptive network hardening continuously analyzes actual traffic flows to and from Azure resources, learning the legitimate patterns of communication. It then compares these learned flows against the current NSG rules and recommends—or can automatically apply—tightened rules that block traffic that does not match the baseline. When a deviation from the learned pattern is observed, such as an unexpected source IP or port combination, it raises an alert, making it the appropriate control for detecting anomalous network behavior.

  • ✗

    Just-In-Time VM access

    Why it's wrong here

    Just-In-Time (JIT) VM access is incorrect because it only governs temporary, time-boxed openings of management ports like RDP and SSH for authorized admin requests. It does not inspect, learn, or alert on general network traffic flows between resources. Its purpose is to reduce the attack surface of management endpoints, not to detect suspicious deviations in broader network communication patterns.

  • ✗

    File integrity monitoring

    Why it's wrong here

    File integrity monitoring (FIM) is incorrect because it focuses on the integrity of on-disk artifacts, such as registry keys, configuration files, and binaries, by comparing current states against a known-good baseline. It triggers alerts when files or registry values are modified, which is valuable for detecting tampering but entirely unrelated to analyzing live network traffic flows or NSG effectiveness. Therefore, it cannot provide the network behavior learning that the security team needs.

  • ✗

    Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning is incorrect because it identifies software weaknesses, missing patches, and misconfigurations by querying installed applications and operating system versions. It provides a point-in-time assessment of exposure to known CVEs, not an ongoing analysis of actual network connections or traffic patterns. While useful for hardening posture, it does not learn normal network behavior and cannot alert on suspicious deviations in communications.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.