hardMultiple Choice
SC-200 Practice Question: Is responsible for protecting containerized…
A security engineer is responsible for protecting containerized workloads in Azure Kubernetes Service (AKS) clusters. They want to enable Microsoft Defender for Cloud to detect threats against the Kubernetes control plane and container runtime. Additionally, they want to ensure vulnerability assessments are performed on images stored in Azure Container Registry. Which Defender for Cloud plan should the engineer enable?
⚠ Common exam trap
Watch out — candidates often confuse the legacy Defender for Container Registries plan (Option D) as sufficient, not realizing it lacks control plane threat detection and has been replaced by the unified Defender for Containers plan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft Defender for Containers plan on the subscription.
The Microsoft Defender for Containers plan is the only plan that provides integrated threat detection for the AKS control plane and container runtime, as well as vulnerability assessment for images in Azure Container Registry. This plan replaces the legacy Defender for Container Registries and Defender for Kubernetes plans, offering a unified solution for container security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Microsoft Defender for Servers plan on the subscription.
Why it's wrong here
Defender for Servers is designed to protect operating systems of VMs and physical servers, including the underlying node OS in AKS, but it lacks visibility into container-level activity such as pod-to-pod communication, privilege escalation within containers, and Kubernetes control plane operations. Successful containerized attacks often target misconfigured Kubernetes components or workload identities, not just the host kernel, so a server plan alone leaves those attack surfaces unmonitored.
- ✓
Enable the Microsoft Defender for Containers plan on the subscription.
Why this is correct
Defender for Containers is the Microsoft Defender for Cloud plan specifically built for AKS and can also cover Kubernetes distributions in Azure Arc-enabled environments. It combines control plane threat detection from Kubernetes audit logs, workload runtime protection via a daemon set, and vulnerability assessment for images from any registry, making it the correct choice for protecting containerized workloads. Enabling this plan on the subscription provides consolidated coverage for both the orchestration layer and the containers themselves.
- ✗
Enable the Microsoft Defender for App Service plan on the subscription.
Why it's wrong here
Defender for App Service protects web applications hosted on Azure App Service plans by monitoring incoming HTTP traffic and the App Service sandbox for known web attack patterns like path traversal or SQL injection. It has no deployment in or awareness of Kubernetes clusters, cannot see container internals, and does not analyze Kubernetes audit events, so enabling it on the subscription would have zero effect on AKS workload security.
- ✗
Enable the Microsoft Defender for Container Registries plan (legacy) on the registry.
Why it's wrong here
The legacy Defender for Container Registries plan scans ACR images for vulnerabilities at push time and supplies patching recommendations, but it is only an image-assessment tool and does not perform runtime detection or monitor the Kubernetes data plane. In addition, Microsoft has deprecated this plan in favor of Defender for Containers, which absorbs registry scanning alongside cluster-level threat detection. Activating the legacy plan on the registry alone would leave runtime attacks and control-plane risks entirely uncovered.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.