SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
You are a security administrator for Adventure Works, which uses Microsoft Defender for Cloud to protect its Azure and on-premises resources. The company has a hybrid environment with Windows Server virtual machines in Azure and on-premises. You need to ensure that Microsoft Defender for Cloud can assess vulnerabilities on these servers. What should you do?
⚠ Common exam trap
The trap here is assuming that installing a monitoring agent or using Azure Policy alone can enable vulnerability assessment, when the Defender for Servers plan is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft Defender for Servers plan and deploy the integrated vulnerability assessment solution.
To assess vulnerabilities on Azure and on-premises servers, you must enable the Microsoft Defender for Servers plan and deploy the integrated vulnerability assessment solution. This solution, powered by Qualys, scans servers for vulnerabilities and provides findings in Microsoft Defender for Cloud. Other options do not provide vulnerability assessment capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the Microsoft Defender for Servers plan and deploy the integrated vulnerability assessment solution.
Why this is correct
Microsoft Defender for Servers includes a built-in vulnerability assessment solution powered by Qualys. By enabling the Defender for Servers plan and deploying the integrated solution, you can automatically scan your Azure and on-premises servers for vulnerabilities. This provides continuous assessment and actionable recommendations in Defender for Cloud.
- ✗
Enable the Microsoft Defender for Storage plan for all storage accounts.
Why it's wrong here
Microsoft Defender for Storage protects Azure Storage accounts from threats like malware uploads and anomalous access. It does not provide vulnerability assessment for servers. Enabling it would not help assess vulnerabilities on Windows Server VMs. The correct plan for server vulnerability assessment is Microsoft Defender for Servers.
- ✗
Install the Microsoft Monitoring Agent on each server and configure a Log Analytics workspace.
Why it's wrong here
While the Microsoft Monitoring Agent and a Log Analytics workspace are used for data collection and monitoring, they alone do not provide vulnerability assessment. Vulnerability assessment requires the Defender for Servers plan and the integrated vulnerability assessment solution. The agent is necessary for data ingestion, but it is not sufficient to enable vulnerability scanning.
- ✗
Configure Azure Policy to enforce vulnerability assessment on all virtual machines.
Why it's wrong here
Azure Policy can audit and enforce configurations, but it does not itself perform vulnerability assessment. While you can use policy to ensure the vulnerability assessment solution is deployed, the actual assessment is provided by the Defender for Servers plan. Policy alone does not enable the scanning capability; it is a governance tool, not a security assessment tool.
Go deeper
Related to this question
Learn chapter
Cloud App Governance and App Consent
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability assessment
A vulnerability assessment is a systematic review of security weaknesses in an information system, evaluating if the system is susceptible to any known vulnerabilities, assigning severity levels, and recommending remediation or mitigation.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.