Courseiva

SC-200 Manage a security operations environment Practice Question

Your security team uses Microsoft Defender for Cloud to assess the security posture of Azure resources. You need to ensure that all virtual machines have endpoint protection enabled. Which policy initiative should you assign?

⚠ Common exam trap

Many exam-takers confuse 'deploying endpoint protection' with 'configuring security features' (like Exploit Guard) or 'applying broad benchmarks' (like Azure Security Benchmark), rather than recognizing that only the specific 'Deploy Microsoft Defender for Endpoint' initiative installs the endpoint protection agent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Microsoft Defender for Endpoint

The 'Deploy Microsoft Defender for Endpoint' policy initiative is specifically designed to ensure that all Azure VMs have endpoint protection enabled. This initiative deploys the Microsoft Defender for Endpoint agent to VMs that are missing it, directly addressing the requirement for endpoint protection. Other options focus on encryption, exploit guard configuration, or general security benchmarks, not the deployment of endpoint protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable encryption on Azure VMs

    Why it's wrong here

    Enable encryption on Azure VMs is an Azure Policy initiative that deploys Azure Disk Encryption using BitLocker for Windows and DM-Crypt for Linux, addressing data-at-rest confidentiality on attached disks. It does not include any policy definitions for installing or onboarding an endpoint detection and response (EDR) agent, so it cannot satisfy an endpoint protection requirement. Disk encryption protects against offline theft or physical access, not malware or active attacks, which require a separate endpoint protection solution.

  • ✓

    Deploy Microsoft Defender for Endpoint

    Why this is correct

    Deploy Microsoft Defender for Endpoint is a built-in policy initiative in Microsoft Defender for Cloud that contains definitions such as 'Configure machines to automatically onboard to Microsoft Defender for Endpoint' and 'Endpoint protection solution should be installed on virtual machines.' This initiative actually installs and deploys the Defender for Endpoint agent to Azure VMs, enabling EDR, real-time antimalware protection, and vulnerability management. Because it directly fulfills the regulatory goal of deploying endpoint protection, it is the correct initiative to assign for this requirement.

  • ✗

    Deploy Windows Defender Exploit Guard

    Why it's wrong here

    Deploy Windows Defender Exploit Guard is a more narrow policy that configures exploit mitigation features—attack surface reduction, controlled folder access, and network protection—on machines that already have Windows Defender. It does not deploy or install any endpoint protection agent; rather, it assumes an underlying EDR/antimalware product is already present and only tweaks specific security hardening settings. The broader initiative 'Deploy Microsoft Defender for Endpoint' is the correct one because it handles the actual deployment and onboarding, whereas Exploit Guard simply augments an existing deployment.

  • ✗

    Azure Security Benchmark

    Why it's wrong here

    Azure Security Benchmark (rebranded as Microsoft cloud security benchmark) is a comprehensive set of security recommendations covering identity, network, data protection, and logging, with hundreds of individual controls that are used for compliance scoring and baselines. It is not a deployment initiative—it does not include DeployIfNotExists policies that install agents or enable services on VMs, but rather audits and scores existing configuration. While it contains endpoint protection controls, the focused 'Deploy Microsoft Defender for Endpoint' initiative is the appropriate assignment when the specific requirement is to deploy endpoint protection to Azure VMs.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.