mediumMultiple Choice
SC-200 Practice Question: Has enabled Microsoft Defender for Cloud's…
An organization has enabled Microsoft Defender for Cloud's enhanced security features. They want to ensure that newly provisioned Azure virtual machines automatically have the built-in vulnerability assessment solution installed. Which configuration should they enable in Defender for Cloud?
⚠ Common exam trap
Watch out — candidates often confuse the Log Analytics agent's auto-provisioning (which enables data collection for security alerts) with the separate vulnerability assessment auto-provisioning, assuming that log collection alone covers vulnerability scanning, when in fact a dedicated extension is required for that purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auto-provisioning of the vulnerability assessment solution
Microsoft Defender for Cloud's enhanced security features include a dedicated auto-provisioning setting specifically for the built-in vulnerability assessment solution (powered by Qualys). When enabled, this setting automatically deploys the vulnerability assessment extension to all new and existing Azure VMs, ensuring continuous vulnerability scanning without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Auto-provisioning of the Log Analytics agent
Why it's wrong here
The Log Analytics agent is a data-collection agent that gathers Windows and Linux security events, syslog, and performance counters, but it performs no vulnerability scanning. It cannot detect missing OS patches, misconfigurations, or known CVEs, because that requires a separate vulnerability assessment engine (e.g., Qualys or Microsoft Defender Vulnerability Management). Enabling auto-provisioning of the Log Analytics agent only ensures logs reach the workspace; it does not fulfill the requirement for continuous vulnerability scanning.
- ✓
Auto-provisioning of the vulnerability assessment solution
Why this is correct
Auto-provisioning of the vulnerability assessment solution is the correct setting because when enabled, Defender for Cloud automatically deploys a vulnerability assessment scanner (either the Qualys agent or the Microsoft integrated solution) to all new and existing VMs. This agent continuously scans for software vulnerabilities and missing updates without requiring manual per-VM installation. By enabling this auto-provisioning, you ensure that every newly created VM is immediately covered by vulnerability scanning, which directly addresses the requirement for continuous scanning.
- ✗
Automatic provisioning of all security agents
Why it's wrong here
There is no single toggle that auto-provisions 'all security agents' in Defender for Cloud; provisioning is controlled granularly per solution type (Log Analytics, vulnerability assessment, endpoint protection, etc.). Even if you enable every provisioning option manually, the vulnerability assessment solution still must be enabled explicitly, and the so-called 'all security agents' setting does not exist in the Azure portal or API. Relying on a non-existent umbrella setting would leave VMs unprotected because the vulnerability scanner would not be automatically deployed solely by enabling other agents.
- ✗
Azure Policy assignment for Update Management
Why it's wrong here
Azure Policy assignment for Update Management governs patch deployment and schedule-to-install updates, but it does not perform vulnerability assessment and does not install a vulnerability scanning agent. Update Management uses the Log Analytics agent and relies on update data from the VM, while vulnerability assessment actively probes and analyzes missing security updates and misconfigurations against CVE databases. Assigning policy for Update Management may help remediate known issues, but it cannot automatically deploy the Qualys or Microsoft scanner required for continuous vulnerability scanning.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.