Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security administrator wants to enforce…

A security administrator wants to enforce Just-in-Time (JIT) VM access for all Azure virtual machines in a management group to reduce the attack surface. The administrator wants to automatically enable JIT on any new VM and remediate existing non-compliant VMs. What should the administrator configure in Microsoft Defender for Cloud?

⚠ Common exam trap

A common mix-up: candidates think manual configuration (A) or custom policies (D) are needed, but the exam tests knowledge of built-in policy initiatives that can be assigned at a management group for automated, scalable enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the built-in policy initiative 'Configure just-in-time network access on virtual machines' at the management group level.

The built-in policy initiative 'Configure just-in-time network access on virtual machines' can be assigned at the management group scope to automatically enable JIT on new VMs and remediate existing non-compliant VMs via a DeployIfNotExists effect. This ensures consistent enforcement across all subscriptions under that management group without manual per-subscription configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually enable JIT in Defender for Cloud's 'Just-in-time VM access' blade for each subscription.

    Why it's wrong here

    Manually enabling JIT in Defender for Cloud's blade is a point-in-time, human-driven action that configures only the specific VM resource you have selected in the portal. It does not create any policy or initiative that can be inherited by future VMs, and it cannot automatically detect and remediate unconfigured or non-compliant machines across subscriptions. While it works for a single existing VM, it completely fails to meet the requirement of enforcing JIT for all Azure VMs, because any new VM deployed after that manual click remains unprotected until someone remembers to enable JIT again.

  • ✓

    Assign the built-in policy initiative 'Configure just-in-time network access on virtual machines' at the management group level.

    Why this is correct

    Assigning the built-in policy initiative 'Configure just-in-time network access on virtual machines' at the management group level is the correct approach because policy initiatives in Azure Policy are inherited by all child subscription and resource group scopes, and they include a deploymentIfNotExists effect that automatically enables JIT on existing VMs and applies the configuration to any new VM as soon as it is created. This initiative leverages the native integration between Azure Policy and Microsoft Defender for Cloud, so non-compliant VMs are either remediated automatically or flagged for remediation, giving you continuous enforcement across your entire environment without manual intervention. By assigning at the management group level, you cover every subscription in that hierarchy with a single, auditable, and idempotent governance action.

  • ✗

    Configure Azure Policy Guest Configuration to require JIT on virtual machines.

    Why it's wrong here

    Azure Policy Guest Configuration (now called Azure Policy's guest configuration feature) is specifically designed to audit and configure settings inside a virtual machine's operating system, such as installed applications, Windows/Linux security baselines, or local user accounts—not to manage Azure network security group (NSG) rules or network-level features like Just-in-Time VM access. JIT operates at the Azure network layer by dynamically opening or closing NSG rules to specific ports and source IPs, which is outside the scope of guest configuration agents running in the OS. Therefore, this option would be architecturally incorrect: even if you could craft a guest configuration assignment that checks some OS indicator, it would not be able to enforce the NSG rule modifications that JIT requires, so it would provide no real JIT protection.

  • ✗

    Create a custom Azure Policy definition to enforce JIT and assign it to each subscription.

    Why it's wrong here

    Creating a custom Azure Policy for JIT VM access is incorrect because Microsoft Defender for Cloud natively provides a built-in JIT VM access solution, including policies for automatic enablement and remediation. A custom policy would duplicate this functionality and not leverage the integrated security offering. This option is tempting as Azure Policy is ideal for enforcing custom configurations or assigning existing policies at scale across subscriptions, ensuring compliance for various resource settings not natively managed by Defender for Cloud.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.