Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your company uses Microsoft Defender for Cloud to secure Azure resources. You need to enable network security recommendations for all virtual networks. Which security policy should you enable?

⚠ Common exam trap

Test-takers frequently confuse a specific security feature (like adaptive network hardening or JIT VM access) with a broad security policy framework (Azure Security Benchmark) that provides overarching recommendations for network security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Security Benchmark

The Azure Security Benchmark provides a comprehensive set of security recommendations, including network security controls for virtual networks, such as restricting inbound/outbound traffic and enforcing encryption. Enabling this policy in Microsoft Defender for Cloud applies built-in Azure Policy initiatives that assess and recommend network security configurations across all virtual networks. This directly meets the requirement to enable network security recommendations for all virtual networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Security Benchmark

    Why this is correct

    The Azure Security Benchmark is a Microsoft-authored, Azure-specific set of guidelines and best practices for securing resources on Azure. It provides a comprehensive framework, including built-in policies within Azure Policy, that Defender for Cloud uses to assess the security posture of your environment and generate actionable network security recommendations. These recommendations are directly aligned with industry standards and regulatory compliance requirements, offering a foundational security baseline.

  • Adaptive network hardening

    Why it's wrong here

    Adaptive network hardening is a specific recommendation generated by Microsoft Defender for Cloud, focusing on tightening Network Security Group (NSG) rules for Azure Virtual Machines. It analyzes actual traffic patterns to suggest more restrictive NSG configurations, reducing the attack surface by recommending to block unnecessary ports. However, it is a dynamic, machine-learning-driven *recommendation* for specific resources, not the overarching *benchmark* or *policy set* that provides broad network security guidance.

  • Network Security Group (NSG) flow logs

    Why it's wrong here

    Network Security Group (NSG) flow logs are a diagnostic feature that records information about IP traffic flowing through an NSG. These logs capture source/destination IP addresses, ports, protocols, and whether traffic was allowed or denied, providing crucial data for auditing, troubleshooting, and security analysis. While flow logs are essential for monitoring network activity and can inform security decisions, they are a data source for observation, not a mechanism that inherently provides security recommendations or policies itself.

  • Just-in-time VM access

    Why it's wrong here

    Just-in-time (JIT) VM access is a feature within Microsoft Defender for Cloud designed to reduce the attack surface of virtual machines by limiting the time management ports are open. It allows temporary, controlled access to specific ports only when needed, significantly decreasing exposure to brute-force attacks. While JIT is a powerful security control for access management, it is a specific *feature* to secure VM management ports, not a comprehensive *benchmark* or *policy set* for general network security recommendations across an entire Azure environment.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.