Courseiva
mediumMultiple Choice

SC-200 Practice Question: Has enabled Microsoft Defender for Cloud's…

An organization has enabled Microsoft Defender for Cloud's enhanced security features. They want to ensure that newly provisioned Azure virtual machines automatically have the built-in vulnerability assessment solution installed. Which configuration should they enable in Defender for Cloud?

⚠ Common exam trap

Watch out — candidates often confuse the Log Analytics agent's auto-provisioning (which enables data collection for security alerts) with the separate vulnerability assessment auto-provisioning, assuming that log collection alone covers vulnerability scanning, when in fact a dedicated extension is required for that purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Auto-provisioning of the vulnerability assessment solution

Microsoft Defender for Cloud's enhanced security features include a dedicated auto-provisioning setting specifically for the built-in vulnerability assessment solution (powered by Qualys). When enabled, this setting automatically deploys the vulnerability assessment extension to all new and existing Azure VMs, ensuring continuous vulnerability scanning without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Auto-provisioning of the Log Analytics agent

    Why it's wrong here

    The Log Analytics agent is a data-collection agent that gathers Windows and Linux security events, syslog, and performance counters, but it performs no vulnerability scanning. It cannot detect missing OS patches, misconfigurations, or known CVEs, because that requires a separate vulnerability assessment engine (e.g., Qualys or Microsoft Defender Vulnerability Management). Enabling auto-provisioning of the Log Analytics agent only ensures logs reach the workspace; it does not fulfill the requirement for continuous vulnerability scanning.

  • ✓

    Auto-provisioning of the vulnerability assessment solution

    Why this is correct

    Auto-provisioning of the vulnerability assessment solution is the correct setting because when enabled, Defender for Cloud automatically deploys a vulnerability assessment scanner (either the Qualys agent or the Microsoft integrated solution) to all new and existing VMs. This agent continuously scans for software vulnerabilities and missing updates without requiring manual per-VM installation. By enabling this auto-provisioning, you ensure that every newly created VM is immediately covered by vulnerability scanning, which directly addresses the requirement for continuous scanning.

  • ✗

    Automatic provisioning of all security agents

    Why it's wrong here

    There is no single toggle that auto-provisions 'all security agents' in Defender for Cloud; provisioning is controlled granularly per solution type (Log Analytics, vulnerability assessment, endpoint protection, etc.). Even if you enable every provisioning option manually, the vulnerability assessment solution still must be enabled explicitly, and the so-called 'all security agents' setting does not exist in the Azure portal or API. Relying on a non-existent umbrella setting would leave VMs unprotected because the vulnerability scanner would not be automatically deployed solely by enabling other agents.

  • ✗

    Azure Policy assignment for Update Management

    Why it's wrong here

    Azure Policy assignment for Update Management governs patch deployment and schedule-to-install updates, but it does not perform vulnerability assessment and does not install a vulnerability scanning agent. Update Management uses the Log Analytics agent and relies on update data from the VM, while vulnerability assessment actively probes and analyzes missing security updates and misconfigurations against CVE databases. Assigning policy for Update Management may help remediate known issues, but it cannot automatically deploy the Qualys or Microsoft scanner required for continuous vulnerability scanning.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.