Courseiva
mediumMultiple Choice

SC-200 Practice Question: Match each Microsoft Defender for Cloud feature…

Match each Microsoft Defender for Cloud feature on the left with its primary purpose on the right.

⚠ Common exam trap

It's easy for candidates to confuse Just-In-Time VM Access with Adaptive Application Controls because both reduce attack surface, but JIT controls network-level access to management ports while Adaptive Application Controls controls which applications can execute at the OS level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Just-In-Time VM Access → Provides time-limited access to management ports via NSG rules; Adaptive Application Controls → Allowlists known safe applications to run on VMs; File Integrity Monitoring → Detects changes to sensitive registry keys and files; Regulatory Compliance Dashboard → Assesses Azure resources against industry standards

It accurately matches each Microsoft Defender for Cloud feature to its primary purpose. Just-In-Time (JIT) VM Access reduces the attack surface by locking down management ports (e.g., RDP 3389, SSH 22) and granting time-limited access via NSG rules only when requested. Adaptive Application Controls uses machine learning to create an allowlist of known safe applications, blocking unknown executables on VMs. File Integrity Monitoring (FIM) tracks changes to sensitive registry keys, files, and certificates, alerting on unauthorized modifications. The Regulatory Compliance Dashboard continuously assesses Azure resources against built-in standards like CIS, NIST, and Azure Security Benchmark, providing a compliance score and recommendations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Just-In-Time VM Access → Provides time-limited access to management ports via NSG rules; Adaptive Application Controls → Allowlists known safe applications to run on VMs; File Integrity Monitoring → Detects changes to sensitive registry keys and files; Regulatory Compliance Dashboard → Assesses Azure resources against industry standards

    Why this is correct

    Just-In-Time (JIT) VM Access correctly describes time-limited opening of management ports (e.g., RDP/SSH) through NSG rules, while Adaptive Application Controls correctly describes an allowlist-based mechanism that uses machine learning to permit only known safe executables. File Integrity Monitoring (FIM) correctly targets changes to sensitive registry keys and files, and the Regulatory Compliance Dashboard correctly assesses Azure resources against industry standards such as CIS and PCI DSS. This alignment accurately captures each feature's core operational purpose without conflating network access, application control, integrity verification, or compliance assessment.

  • ✗

    The first and second mappings are reversed; the remaining mappings are unchanged.

    Why it's wrong here

    Reversing the first two mappings would force Just-In-Time VM Access to be paired with allowlisting known safe applications, which is inaccurate because JIT operates at the network layer by modifying NSG rules for a limited window, not by controlling executable behavior. Simultaneously, Adaptive Application Controls would be incorrectly described as providing time-limited access to management ports, whereas it actually uses a per-VM allowlist of trusted processes and binaries. Thus, the error confuses network-level access control with application-level whitelisting.

  • ✗

    All features map to the same monitoring purpose.

    Why it's wrong here

    Treating all four features as equivalent to 'monitoring' collapses their distinct control-plane functions: JIT is a conditional network access policy, Adaptive Application Controls is a service-side application governance tool, File Integrity Monitoring is a security auditing capability, and Regulatory Compliance Dashboard is a governance reporting interface. While some may produce logs or alerts, their primary purposes are not identical to passive monitoring, and each operates on a different Azure resource layer and telemetry source. Therefore, the option incorrectly ignores the specific operational differences between access control, app allowlisting, file integrity auditing, and compliance assessment.

  • ✗

    The compliance and access-control mappings are swapped.

    Why it's wrong here

    Swapping the compliance and access-control mappings would pair Just-In-Time VM Access with regulatory compliance assessment, which ignores the fact that JIT is an operational mechanism that grants temporary network access via NSG rules, not a dashboard that evaluates Azure subscriptions against standards. Conversely, the Regulatory Compliance Dashboard would be incorrectly described as providing time-limited access to management ports, when it actually aggregates security findings and policy compliance across services. This alternative fails because it exchanges a real-time access enforcement feature with a post-hoc assessment and visibility tool.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.