easyMultiple Choice
SC-200 Practice Question: A security administrator needs to ensure that all…
A security administrator needs to ensure that all newly provisioned Azure virtual machines automatically install the Microsoft Defender for Cloud agent (Log Analytics agent) to enable security monitoring. Which configuration should be enabled in Defender for Cloud?
⚠ Common exam trap
Many exam-takers confuse 'enabling the Defender for Servers plan' with automatic agent deployment, but the plan only enables threat detection capabilities and does not handle the agent installation process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auto-provisioning of the Log Analytics agent
Auto-provisioning of the Log Analytics agent in Microsoft Defender for Cloud automatically installs the Log Analytics agent (Microsoft Monitoring Agent) on all new Azure VMs. This ensures that security monitoring data, such as security events and syslog, is collected and sent to the Log Analytics workspace without manual intervention. The setting is found under 'Environment settings' > 'Auto provisioning' and must be toggled to 'On' for the agent to be deployed on newly provisioned VMs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Auto-provisioning of the Log Analytics agent
Why this is correct
Auto-provisioning of the Log Analytics agent is the correct mechanism that Microsoft Defender for Cloud uses to automatically deploy the agent to Azure VMs. When this setting is enabled, Defender for Cloud installs the Log Analytics agent (or now Azure Monitor Agent) as a VM extension on both existing machines and every newly provisioned VM, and connects it to the selected Log Analytics workspace. This guarantees that security data is collected from all VMs without manual intervention, which is exactly what the requirement asks for.
- ✗
Enable the Defender for Servers plan
Why it's wrong here
Enabling the Defender for Servers plan turns on endpoint threat detection capabilities, such as fileless attack detection, host firewall recommendations, and integration with Defender for Endpoint, but it does not install the Log Analytics agent. Agent installation is handled separately by auto-provisioning settings under 'Data collection' in the Defender for Cloud environment configuration. Without auto-provisioning enabled, a new VM will still exist without the Log Analytics agent even if the Defender for Servers plan is active, so this option addresses monitoring features rather than the agent rollout itself.
- ✗
Configure a vulnerability assessment solution
Why it's wrong here
Configuring a vulnerability assessment solution, such as the integrated Qualys scanner or Microsoft Defender Vulnerability Management, focuses on scanning your VMs for vulnerabilities, not on the underlying agent provisioning. Although many vulnerability scanners deploy an extension or require an agent, that agent is specific to the scanner and does not constitute the Log Analytics agent, nor does it run automatically for all newly created VMs. The vulnerability assessment solution must be configured per VM or in policy, but it does not fulfill the continuous, automatic Log Analytics agent installation requirement.
- ✗
Enable just-in-time (JIT) VM access
Why it's wrong here
Just-in-time (JIT) VM access is a network security feature in Defender for Cloud that creates temporary NSG and Azure Firewall rules to open specific ports only when requested; it has no relation to software agents. JIT is implemented entirely through Azure networking controls and does not need to be present on the VM, and it definitely cannot install the Log Analytics agent on new VMs. Enabling JIT therefore addresses a different security requirement (reducing the attack surface) and leaves the agent deployment problem completely unsolved.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security administrator wants to ensure that all Azure virtual machines have automatic provisioning of the Log Analytics agent enabled by default in Microsoft Defender for Cloud. Where should this configuration be set?
easy- A.In the Azure portal under each virtual machine's 'Extensions + applications' blade
- ✓ B.In Microsoft Defender for Cloud, under 'Environment settings' > 'Data collection'
- C.In Microsoft Sentinel, under 'Data connectors' for Defender for Cloud
- D.In Azure Policy, by assigning the 'Deploy Log Analytics agent' initiative
Why B: The automatic provisioning of the Log Analytics agent for all Azure virtual machines in Defender for Cloud is configured under 'Environment settings' > 'Data collection'. This setting enables Defender for Cloud to automatically deploy the Log Analytics agent to new and existing VMs, ensuring security monitoring without manual intervention.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.