mediumMultiple ChoiceObjective-mapped
SC-200 Practice Question: A security administrator wants to enable…
A security administrator wants to enable vulnerability assessment for all existing and future Azure virtual machines in a subscription using the integrated Microsoft Defender Vulnerability Management solution. What is the recommended action in Microsoft Defender for Cloud?
⚠ Common exam trap
Watch out — candidates often confuse the 'Vulnerability assessment for machines' component with a separate policy assignment or manual agent installation, not realizing that the correct action is a simple toggle in the Defender for Servers plan settings that automatically handles provisioning and lifecycle management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Vulnerability assessment for machines' component in the Defender for Servers plan settings within the subscription's pricing & settings page.
Enabling the 'Vulnerability assessment for machines' component in the Defender for Servers plan settings within the subscription's pricing & settings page automatically provisions the integrated Microsoft Defender Vulnerability Management (MDVM) solution to all existing and future Azure VMs without manual agent installation. This is the recommended and native method in Microsoft Defender for Cloud to enable vulnerability assessment at scale, leveraging the built-in Qualys or MDVM scanner that is managed by the platform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the 'Vulnerability assessment for machines' component in the Defender for Servers plan settings within the subscription's pricing & settings page.
Why this is correct
Enabling the 'Vulnerability assessment for machines' component in the Defender for Servers plan settings is the native, integrated approach within Microsoft Defender for Cloud. This action automatically provisions the Microsoft Defender Vulnerability Management solution to all existing and future Azure VMs and Arc-enabled servers, eliminating the need for per-VM manual steps. It ensures continuous coverage as new machines are added, directly satisfying the requirement to enable vulnerability assessment for existing and future resources at the subscription level.
- ✗
Manually install the Microsoft Defender Vulnerability Management agent on each VM via an Azure Policy initiative.
Why it's wrong here
Manually installing the Microsoft Defender Vulnerability Management agent on each VM via an Azure Policy initiative is operationally inefficient and does not scale for ongoing resource growth. While Azure Policy can automate agent deployment, this approach is not the recommended action in Defender for Cloud, as the integrated 'Vulnerability assessment for machines' component already handles automatic agent deployment when enabled. Relying on a custom policy also introduces redundancy and potential configuration drift, whereas the native setting centrally manages the solution across the entire subscription.
- ✗
Create an Azure Policy that assigns the 'Configure machines to receive a vulnerability assessment provider' built-in policy to the subscription.
Why it's wrong here
Creating this Azure Policy fails because it configures machines to *receive* a vulnerability assessment provider, rather than *enabling* the integrated Microsoft Defender Vulnerability Management solution itself at the subscription level. The policy ensures the necessary extensions are deployed for assessment, which is a prerequisite for *any* vulnerability assessment. It is tempting as it uses Azure Policy and mentions vulnerability assessment, and would be correct if the goal was to ensure machines are prepared to receive assessments from an *already enabled* solution, or a third-party provider.
- ✗
Enable 'Vulnerability assessment for machines' in the Azure Security Benchmark compliance dashboard.
Why it's wrong here
Enabling 'Vulnerability assessment for machines' in the Azure Security Benchmark compliance dashboard is ineffective because that dashboard is designed solely for reporting and visualizing compliance posture against standards. It does not expose settings to activate any vulnerability assessment solution; instead, it displays the results of assessments that have already been configured elsewhere. Therefore, interacting with this dashboard cannot provision the vulnerability assessment component, making it an incorrect action for enabling assessment across existing and future VMs.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security administrator wants to enable vulnerability assessment for all existing and future Azure virtual machines using the integrated Microsoft Defender Vulnerability Management solution. Which action should they take in Microsoft Defender for Cloud?
medium- ✓ A.Enable 'Microsoft Defender for Servers' plan and check the 'Vulnerability assessment' option in the environment settings
- B.Install the Log Analytics agent and configure the Qualys connector on each VM
- C.Create a policy assignment from the built-in initiative 'Enable Azure Monitor for VMs'
- D.Enable 'Servers' workload protection in Defender for Cloud and then manually deploy the VA agent to each existing VM using Azure Policy
Why A: To enable vulnerability assessment for all existing and future Azure VMs using the integrated Microsoft Defender Vulnerability Management solution, you must enable the 'Microsoft Defender for Servers' plan in Defender for Cloud and then check the 'Vulnerability assessment' option within the environment settings. This action activates the built-in, agentless vulnerability assessment engine that is part of Defender for Cloud, automatically scanning VMs without requiring additional agents or manual deployment.
Variation 2. A security administrator wants to ensure that all existing and future Azure virtual machines have Microsoft Defender for Cloud's built-in vulnerability assessment solution (Qualys or Microsoft) installed without manual intervention. Which feature should the administrator configure?
medium- A.Continuous export of security findings to Log Analytics
- ✓ B.Auto-provisioning of the vulnerability assessment solution
- C.Just-in-time VM access
- D.Regulatory compliance dashboard
Why B: Auto-provisioning of the vulnerability assessment solution ensures that Microsoft Defender for Cloud automatically installs either the Qualys or Microsoft built-in vulnerability assessment extension on all existing and future Azure VMs without manual intervention. This feature is specifically designed to enable continuous vulnerability scanning by deploying the agent at scale, covering both new and existing resources as they are provisioned or discovered.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.