Microsoft Defender for Cloud Hybrid Workload Security Dashboard
A company runs virtual machines in Azure and also maintains on-premises servers connected via Azure Arc. The security team needs a single dashboard to view security recommendations, detect misconfigurations, and track a secure score across both environments. They also want to enable advanced threat protection features such as just-in-time (JIT) VM access and file integrity monitoring for these workloads. Which Microsoft security solution should they implement?
Quick Answer
The answer is Microsoft Defender for Cloud. This solution is correct because it provides a single, unified hybrid workload security dashboard that aggregates security recommendations, detects misconfigurations, and tracks a secure score across both Azure virtual machines and on-premises servers connected via Azure Arc. It also enables advanced threat protection features like just-in-time (JIT) VM access and file integrity monitoring, directly addressing the need for a centralized view and proactive defenses across mixed environments. On the SC-900 exam, this scenario tests your understanding of how Defender for Cloud extends beyond Azure-native resources to cover hybrid and multicloud workloads, often appearing as a question that contrasts it with Azure Security Center or Microsoft Sentinel. A common trap is choosing Azure Policy, which enforces compliance but lacks the unified dashboard and threat protection features. Remember the memory tip: “Defender for Cloud is the single pane of glass for hybrid secure score and JIT.”
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender for Cloud (a CSPM and workload protection platform) with Microsoft Sentinel (a SIEM), but the question explicitly asks for a single dashboard for security posture, secure score, and advanced threat protection features like JIT and file integrity monitoring, which are exclusive to Defender for Cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud
Microsoft Defender for Cloud provides a unified dashboard that displays security recommendations, misconfigurations, and a secure score across both Azure and on-premises workloads connected via Azure Arc. It also includes advanced threat protection features like just-in-time (JIT) VM access and file integrity monitoring, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Cloud
Why this is correct
Defender for Cloud provides a unified dashboard with secure score, recommendations, and advanced threat protection for hybrid workloads including on-premises servers via Azure Arc.
- ✗
Microsoft Sentinel
Why it's wrong here
Sentinel is a SIEM for security log analysis and incident response, not a posture management tool for providing a secure score and recommendations.
When this WOULD be correct
A company needs to aggregate security events from multiple sources (e.g., Azure, on-premises, third-party) for threat detection, incident response, and automated orchestration. The question would specify log collection, correlation, and alerting across diverse data sources.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Defender for Endpoint focuses on endpoint detection and response for devices, not on overall cloud workload posture management or JIT VM access.
When this WOULD be correct
A company needs to protect endpoints (e.g., workstations, servers) from advanced threats, with capabilities like antivirus, EDR, and threat hunting. The question would specify endpoint security, not hybrid cloud workload management or secure score.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Defender for Cloud Apps is a cloud access security broker that discovers and controls cloud app usage, not a workload protection platform for VMs and servers.
When this WOULD be correct
A company uses multiple SaaS applications (e.g., Office 365, Salesforce) and needs to detect shadow IT, control access, and prevent data leaks from these apps. They also require visibility into user activities and anomaly detection across cloud apps.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for CloudCorrect answer▾
Why this is correct
Defender for Cloud provides a unified dashboard with secure score, recommendations, and advanced threat protection for hybrid workloads including on-premises servers via Azure Arc.
✗Microsoft SentinelWrong answer — click to see why▾
Why this is wrong here
Microsoft Sentinel is a SIEM and SOAR solution for collecting and analyzing security logs, not a dashboard for security recommendations, misconfigurations, or secure score across hybrid environments. It does not provide just-in-time VM access or file integrity monitoring.
★ When this WOULD be the correct answer
A company needs to aggregate security events from multiple sources (e.g., Azure, on-premises, third-party) for threat detection, incident response, and automated orchestration. The question would specify log collection, correlation, and alerting across diverse data sources.
Why candidates choose this
Candidates may confuse Sentinel's security monitoring capabilities with Defender for Cloud's posture management and workload protection, especially since both involve security dashboards and threat detection.
✗Microsoft Defender for EndpointWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR) for devices, not on providing a unified dashboard for security recommendations, misconfigurations, secure score, or advanced cloud workload protections like JIT VM access and file integrity monitoring across hybrid environments.
★ When this WOULD be the correct answer
A company needs to protect endpoints (e.g., workstations, servers) from advanced threats, with capabilities like antivirus, EDR, and threat hunting. The question would specify endpoint security, not hybrid cloud workload management or secure score.
Why candidates choose this
Candidates may confuse 'Defender for Endpoint' with 'Defender for Cloud' due to similar naming, or assume endpoint protection covers all security needs, overlooking the specific requirements for cloud workload protection and secure score.
✗Microsoft Defender for Cloud AppsWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on SaaS application security, not on providing a unified dashboard for VM secure score, misconfigurations, or advanced threat protection like JIT VM access and file integrity monitoring across Azure and on-premises servers.
★ When this WOULD be the correct answer
A company uses multiple SaaS applications (e.g., Office 365, Salesforce) and needs to detect shadow IT, control access, and prevent data leaks from these apps. They also require visibility into user activities and anomaly detection across cloud apps.
Why candidates choose this
Candidates may confuse 'Cloud Apps' with 'Cloud' and think it covers all cloud workloads, or they may assume it includes VM security features due to the 'Defender' branding.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Azure virtual machines and also has physical servers in their on-premises datacenter. The security team needs a single dashboard to view security recommendations, detect misconfigurations, and get a secure score for both environments. They also want to integrate with Microsoft Defender for Cloud for threat protection. Which Microsoft security solution provides this unified visibility across hybrid workloads?
medium- ✓ A.Microsoft Defender for Cloud
- B.Microsoft Sentinel
- C.Microsoft Defender for Endpoint
- D.Microsoft Security Center
Why A: Microsoft Defender for Cloud provides a unified dashboard that delivers security recommendations, misconfiguration detection, and a secure score across both Azure virtual machines and on-premises physical servers. It natively integrates with Microsoft Defender for Cloud's threat protection capabilities, enabling hybrid workload coverage without additional licensing or complex setup.
Variation 2. A company runs workloads in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). The security team needs a single, unified dashboard to continuously assess the security posture of all cloud resources, identify misconfigurations, and receive prioritized recommendations for remediation. Which Microsoft security solution should they use?
medium- ✓ A.Microsoft Defender for Cloud
- B.Microsoft Defender for Cloud Apps
- C.Microsoft Sentinel
- D.Microsoft Defender for Endpoint
Why A: Microsoft Defender for Cloud is the correct solution because it provides a unified cloud security posture management (CSPM) dashboard that continuously assesses resources across Azure, AWS, and GCP. It identifies misconfigurations against industry benchmarks (e.g., CIS, NIST) and delivers prioritized, actionable recommendations to remediate risks, directly meeting the requirement for a single dashboard across multi-cloud environments.
Variation 3. A company runs workloads in Azure and Amazon Web Services (AWS). The security team wants a single, unified dashboard to assess the security posture of all cloud resources, get prioritized recommendations for misconfigurations, and enable just-in-time (JIT) virtual machine access across both cloud environments. Which Microsoft security solution should they use?
medium- A.Microsoft Sentinel
- B.Microsoft Defender for Cloud Apps
- ✓ C.Microsoft Defender for Cloud
- D.Azure Policy
Why C: Microsoft Defender for Cloud is the correct solution because it provides a unified dashboard for assessing security posture across multi-cloud environments, including Azure and AWS. It delivers prioritized recommendations for misconfigurations using the Microsoft cloud security benchmark and supports just-in-time (JIT) VM access to reduce attack surfaces by controlling inbound traffic on demand.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.