SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud to assess security posture. You need to ensure that any new Azure subscription automatically has Microsoft Defender for Cloud enabled with the 'Defender for Cloud (CSPM)' plan active. What should you do?
⚠ Common exam trap
Test-takers frequently confuse Azure Arc (which extends Azure management to non-Azure environments) with Azure Policy (which enforces configurations on Azure subscriptions), leading them to incorrectly select Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign a built-in Azure Policy initiative that deploys Microsoft Defender for Cloud configuration to subscriptions.
Azure Policy can enforce compliance at scale by assigning the built-in initiative 'Deploy Microsoft Defender for Cloud configuration' to a management group or subscription. This initiative includes policies that automatically enable Microsoft Defender for Cloud and activate the 'Defender for Cloud (CSPM)' plan on new subscriptions, ensuring consistent security posture without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an automation account that runs a PowerShell script daily to check and enable Defender for Cloud.
Why it's wrong here
An automation account running a PowerShell script daily is a reactive, point-in-time check rather than a continuous enforcement mechanism. Subscriptions created between runs would remain unprotected until the next scheduled execution, and the approach requires ongoing maintenance of runbooks, identities, and error handling. It also lacks the native compliance and remediation reporting that Azure Policy provides, so it cannot guarantee 'auto-enable' for all current and future subscriptions as a single consolidated control.
- ✗
Configure Azure Arc to enforce the plan on new subscriptions.
Why it's wrong here
Azure Arc is designed to onboard hybrid and multi-cloud resources (servers, Kubernetes clusters) so they can be managed from Azure, not to enforce policies on Azure subscriptions themselves. While Arc extends Defender for Cloud's protections to non-Azure machines, it does not automatically enable Defender plans on newly created subscriptions. The correct method for subscription-level enforcement uses Azure Policy, which operates on the Azure control plane, whereas Arc is an agent-based management layer for external infrastructure.
- ✓
Assign a built-in Azure Policy initiative that deploys Microsoft Defender for Cloud configuration to subscriptions.
Why this is correct
The correct answer is to assign the built-in Azure Policy initiative that deploys Microsoft Defender for Cloud configuration, such as the 'Microsoft Defender for Cloud' initiative, to the root management group or subscription scope. This initiative uses DeployIfNotExists and Modify effects to automatically enable the Defender plans, configure data collection, and remediate any drift. Because policy inheritance flows to all child scopes, every new subscription is continuously assessed and brought into compliance without manual or scheduled intervention, providing a fully governed, auditable enforcement mechanism.
- ✗
Use Microsoft Sentinel's 'Subscription Migration' playbook.
Why it's wrong here
Microsoft Sentinel's 'Subscription Migration' playbook is an orchestration workflow for migrating Sentinel workspaces, alerts, and incidents between subscriptions or tenants, not for enabling Defender for Cloud. It has no effect on Defender plan activation or subscription security posture. Using it for Defender for Cloud would be an invalid application of a Sentinel-specific data migration tool, and it does not provide any policy-based enforcement or auto-provisioning.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.