Courseiva

Microsoft Defender for Cloud Capabilities: Cloud Security Posture Management, Just-in-Time VM Access, and Vulnerability Assessment

Which THREE are capabilities of Microsoft Defender for Cloud?

Quick Answer

The answer is Cloud Security Posture Management (CSPM), Just-in-Time VM Access, and Vulnerability Assessment. These three are core capabilities of Microsoft Defender for Cloud because they directly address different layers of cloud security: CSPM continuously evaluates your environment against compliance frameworks and security benchmarks, while Just-in-Time VM Access reduces the attack surface by locking down inbound traffic to Azure VMs through Network Security Group rules that only open management ports like RDP or SSH when an authorized user requests access for a specific time window and from a specific IP address. Vulnerability Assessment, meanwhile, scans your resources for known weaknesses and integrates with the broader Defender for Cloud dashboard. On the SC-900 exam, this question tests your understanding of Defender for Cloud’s operational features rather than its pricing or deployment models—a common trap is confusing Azure Policy with CSPM, but remember that CSPM is a Defender for Cloud capability, not a separate service. A useful memory tip is to think of the acronym “CJV” (Cloud posture, Just-in-time, Vulnerability) to recall the three distinct pillars of protection.

⚠ Common exam trap

Many exam-takers confuse the 'recommendations' or 'alerts' shown in Defender for Cloud (which may mention DDoS or SIEM integration) with Defender for Cloud's own native capabilities, leading them to incorrectly select D or E as direct features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Just-in-time (JIT) VM access

Microsoft Defender for Cloud provides just-in-time (JIT) VM access (A), which locks down management ports (RDP/SSH) and grants time-limited, approved access on request, reducing the attack surface of Azure and non-Azure VMs. It also delivers vulnerability assessment for virtual machines (B), using integrated scanners such as Microsoft Defender for Endpoint or Qualys to surface OS and software CVEs and remediation guidance. Cloud Security Posture Management (CSPM) (C) is a core capability, continuously assessing configurations against benchmarks like Microsoft Cloud Security Benchmark and CIS, and providing secure score and regulatory compliance dashboards. DDoS protection (D) is not a Defender for Cloud capability; it is delivered by Azure DDoS Protection (Basic/Network Protection) as a separate service. SIEM and security orchestration (E) belong to Microsoft Sentinel, which is a distinct product, even though it can ingest Defender for Cloud alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Just-in-time (JIT) VM access

    Why this is correct

    Just-in-time VM access is a Defender for Cloud capability that blocks inbound management ports by default and opens them only on approved, time-bound requests, reducing the attack surface of Azure and multicloud virtual machines against brute-force and scanning attempts.

  • ✓

    Vulnerability assessment for virtual machines

    Why this is correct

    Vulnerability assessment for virtual machines is a core Microsoft Defender for Cloud capability, scanning supported VMs for missing patches and security misconfigurations. It satisfies the stem's requirement by continuously surfacing CVEs and weaknesses through Defender for Servers, integrated with Microsoft Defender Vulnerability Management rather than relying on manual audits.

  • ✓

    Cloud Security Posture Management (CSPM)

    Why this is correct

    Cloud Security Posture Management continuously assesses Azure, AWS and GCP configurations against benchmarks such as Microsoft cloud security benchmark and CIS, identifying misconfigurations and hardening recommendations. It is a core, foundational Defender for Cloud capability.

  • ✗

    DDoS protection

    Why it's wrong here

    DDoS protection is provided by Azure DDoS Protection, which scrubs volumetric and protocol attacks at the network edge. Defender for Cloud covers posture assessment, secure score and threat protection for workloads; DDoS mitigation is the correct selection when the requirement is absorbing attack traffic itself.

  • ✗

    SIEM and security orchestration

    Why it's wrong here

    SIEM and security orchestration belong to Microsoft Sentinel, which ingests and correlates logs across sources. Defender for Cloud instead delivers cloud security posture management and workload protection; Sentinel is the right choice when centralised detection, hunting and automated response playbooks are required.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are capabilities of Microsoft Defender for Cloud?

easy
  • ✓ A.Enable just-in-time access to virtual machines
  • B.Centralize security event log analysis from multiple sources
  • C.Monitor domain controllers for malicious activity
  • ✓ D.Assess and improve the security posture of your cloud resources
  • E.Manage mobile devices and enforce compliance policies

Why A: Option A is correct because Microsoft Defender for Cloud provides just-in-time (JIT) VM access, which locks down inbound RDP/SSH ports and grants time-limited, request-based access to virtual machines, reducing exposure to brute-force attacks. Option D is correct because Defender for Cloud's core Secure Score capability continuously assesses cloud resources against security recommendations and benchmarks (e.g., Microsoft Cloud Security Benchmark) to measure and improve security posture. Option B does not belong because centralized multi-source security event log analysis is the role of Microsoft Sentinel (SIEM), not Defender for Cloud. Option C does not belong because monitoring domain controllers for malicious activity is handled by Microsoft Defender for Identity, a separate service. Option E does not belong because mobile device management and compliance enforcement are capabilities of Microsoft Intune, not Defender for Cloud.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.