Courseiva
easyMultiple ChoiceObjective-mapped

SC-200 Practice Question: Enable Microsoft Defender for Cloud's enhanced…

A company wants to enable Microsoft Defender for Cloud's enhanced security features for all Azure virtual machines in a subscription. What is the first action they should take in the Defender for Cloud pricing & settings page?

⚠ Common exam trap

It's easy for candidates to confuse the order of operations, thinking that installing the Log Analytics agent or enabling vulnerability assessment is the first step, when in fact the subscription-level plan toggle must be enabled to unlock all enhanced security features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Turn on the 'Servers' plan for the subscription

To enable Microsoft Defender for Cloud's enhanced security features for Azure VMs, the first step is to turn on the 'Servers' plan at the subscription level in the Defender for Cloud pricing & settings page. This activates Defender for Servers, which provides threat detection, vulnerability assessment, and just-in-time access. Without enabling this plan, no enhanced security features are available, regardless of other configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Turn on the 'Servers' plan for the subscription

    Why this is correct

    Enabling the 'Servers' plan at the subscription level is the authoritative first step that activates Microsoft Defender for Cloud's enhanced security features (formerly Azure Defender) for every supported VM in that subscription. This plan turns on capabilities such as threat detection, just-in-time VM access, and integrated vulnerability assessment, making it the required prerequisite before any other configuration or agent deployment can deliver full value. Without this plan enabled, other settings remain dormant or incomplete.

  • Install the Log Analytics agent on each VM

    Why it's wrong here

    Although the Log Analytics agent (or Azure Monitor Agent) is essential for collecting security telemetry like event logs and inventory data, installing it on each VM does not by itself enable enhanced security features. In fact, the Servers plan often auto-provisions the agent during enablement, so manually installing it first is both premature and unnecessary. The agent is a data-collection mechanism, not the licensing or feature activation control for Defender for Cloud.

  • Enable vulnerability assessment

    Why it's wrong here

    Enabling vulnerability assessment—whether through the integrated Qualys solution or Microsoft Defender Vulnerability Management—is a discrete capability that becomes available only after the Servers plan is turned on. It cannot be independently activated to grant broader enhanced security features; rather, it is one subordinate component that the Servers plan encompasses. Attempting to enable it before the plan is active will fail or have no effect on the overall security posture.

  • Assign a regulatory compliance policy

    Why it's wrong here

    Assigning a regulatory compliance policy, such as a custom Azure Policy initiative for CIS or NIST, only configures compliance assessments and reporting in Defender for Cloud; it does not activate any enhanced security features. These policies rely on the underlying plan being enabled to assess certain security controls, but the assignment itself is a governance action, not a service activation. Thus, it is a separate post-enablement activity, not the prerequisite that turns on the plan's protections.

About these practice questions

One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.