mediumMultiple Choice
SC-200 Practice Question: Wants to enable vulnerability assessment for all…
An organization wants to enable vulnerability assessment for all Azure virtual machines, including future ones, using the integrated Qualys or Microsoft Defender Vulnerability Management solution. What is the recommended approach in Microsoft Defender for Cloud?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Policy with the primary deployment mechanism, but the correct approach requires enabling the Defender for Servers plan first, as the policy initiative is dependent on that plan being active.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Defender for Servers plan and configure auto-provisioning of the vulnerability assessment solution.
The recommended approach is to enable the Defender for Servers plan, which automatically provisions the integrated vulnerability assessment solution (Qualys or Microsoft Defender Vulnerability Management) on all existing and future Azure VMs. This ensures continuous scanning without manual intervention, leveraging auto-provisioning to deploy the necessary extension.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the Defender for Servers plan and configure auto-provisioning of the vulnerability assessment solution.
Why this is correct
Enabling Defender for Servers activates the integrated vulnerability assessment capability (Microsoft Defender Vulnerability Management) and configuring auto-provisioning ensures the VA solution is automatically installed on all existing and future Azure VMs. This eliminates manual per-VM setup and provides continuous, centralized vulnerability findings in Defender for Cloud. It is the recommended, fully supported path for environment-wide coverage.
- ✗
Manually install the Log Analytics agent and then configure vulnerability assessment on each VM.
Why it's wrong here
Manually installing the Log Analytics agent and then configuring a vulnerability assessment solution individually on each VM is unscalable and error-prone for large environments, and the agent itself is not a VA scanner—it merely serves as a telemetry pipeline for tools like Qualys or the built-in scanner. This approach also requires ongoing maintenance for every VM, has no central enforcement, and bypasses Defender for Cloud's auto-provisioning mechanisms that are designed to manage this at scale. It is therefore not a valid substitute for enabling the Defender for Servers plan.
- ✗
Use Azure Policy to assign the built-in initiative that deploys the vulnerability assessment solution and associates it with VMs.
Why it's wrong here
Azure Policy's built-in 'Deploy if Not Exists' initiative can technically deploy the vulnerability assessment extension to non-compliant VMs, but it assumes the Defender for Servers plan is already enabled because the VA solution requires the underlying security plan to function. The policy is a governance and compliance enforcement tool, not an alternative to enabling the plan—attempting to use it alone without Defender for Servers will fail or produce incomplete results. Microsoft recommends enabling the plan first, then using the policy to ensure continuous deployment across all subscriptions.
- ✗
Enable Azure Security Center's free tier and manually download the vulnerability assessment tool.
Why it's wrong here
The free tier of Azure Security Center (now Defender for Cloud) provides only basic security recommendations and resource hygiene assessments; vulnerability assessments for VMs require one of the paid Defender for Servers plans. Additionally, there is no supported mechanism to 'manually download' a vulnerability assessment tool—Microsoft's built-in VA solution is automatically provisioned through the Defender plan, and third-party scanners are integrated via connectors, not downloads. Relying on the free tier would leave your VMs without any vulnerability coverage.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.