mediumMultiple ChoiceObjective-mapped
SC-200 Practice Question: A company has Azure virtual machines running…
A company has Azure virtual machines running Windows Server. The security team wants to use Microsoft Defender for Cloud's vulnerability assessment solution to identify missing security updates. Which of the following is required to enable built-in vulnerability assessment for VMs?
⚠ Common exam trap
A common mix-up: candidates assume a separate agent or marketplace solution is required, but Microsoft’s built-in assessment is automatically included with the Defender for Servers plan, making the other options unnecessary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Defender for Servers plan
The built-in vulnerability assessment solution in Microsoft Defender for Cloud for Azure VMs is powered by Qualys and is automatically provisioned when the Defender for Servers plan is enabled. This integration does not require manual agent installation or third-party solutions; enabling the plan activates the scanner on supported VMs to identify missing security updates and other vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Defender for Servers plan
Why this is correct
Enabling Defender for Servers activates the built-in vulnerability assessment that automatically deploys the Qualys agent extension to supported Windows Server VMs, discovering missing security updates and configuration vulnerabilities without additional licensing. This integration is native to Defender for Cloud, and once the plan is enabled, the assessment runs continuously, surfacing findings in the Security Center recommendations such as "Machines should have vulnerability findings resolved." It does not require manual installation of any separate agent or marketplace product.
- ✗
Install the Log Analytics agent manually
Why it's wrong here
The Log Analytics agent (or its successor, the Azure Monitor agent) is designed purely for collecting logs, performance counters, and telemetry for analysis in Log Analytics workspaces and Microsoft Sentinel, not for executing vulnerability scans. Defender for Cloud's built-in vulnerability assessment relies on its own Qualys-based extension, which is separate and is deployed automatically when you enable Defender for Servers; manually installing the Log Analytics agent does not provision that scanner. Therefore, this action would not produce missing security update findings and is not a prerequisite for the built-in VA.
- ✗
Configure a vulnerability assessment solution from Azure Marketplace
Why it's wrong here
While Azure Marketplace offers third-party vulnerability assessment solutions (e.g., Qualys, Rapid7, Tenable), these are optional integrations that require their own licenses and configuration in Defender for Cloud. The built-in vulnerability assessment included with Defender for Servers already covers missing security updates on Windows Server VMs, so purchasing and configuring an external solution is unnecessary for this requirement. Choosing a marketplace solution would add cost and complexity without providing a functional advantage over the native capability for detecting missing updates.
- ✗
Enable the regulatory compliance dashboard
Why it's wrong here
The regulatory compliance dashboard in Defender for Cloud provides visibility into how well your environment aligns with standards like CIS, NIST SP 800-53, and the Azure Security Benchmark, based on existing security assessments. It does not perform or enable any vulnerability scanning on your VMs; it simply aggregates and displays data collected from assessments that already run, including the built-in VA if it is enabled. Thus, enabling this dashboard does not deploy any scanner agent or generate missing security update findings on its own.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.