SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company uses Microsoft Defender for Cloud to secure Azure resources. You need to enable network security recommendations for all virtual networks. Which security policy should you enable?
⚠ Common exam trap
Test-takers frequently confuse a specific security feature (like adaptive network hardening or JIT VM access) with a broad security policy framework (Azure Security Benchmark) that provides overarching recommendations for network security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Security Benchmark
The Azure Security Benchmark provides a comprehensive set of security recommendations, including network security controls for virtual networks, such as restricting inbound/outbound traffic and enforcing encryption. Enabling this policy in Microsoft Defender for Cloud applies built-in Azure Policy initiatives that assess and recommend network security configurations across all virtual networks. This directly meets the requirement to enable network security recommendations for all virtual networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Security Benchmark
Why this is correct
The Azure Security Benchmark is a Microsoft-authored, Azure-specific set of guidelines and best practices for securing resources on Azure. It provides a comprehensive framework, including built-in policies within Azure Policy, that Defender for Cloud uses to assess the security posture of your environment and generate actionable network security recommendations. These recommendations are directly aligned with industry standards and regulatory compliance requirements, offering a foundational security baseline.
- ✗
Adaptive network hardening
Why it's wrong here
Adaptive network hardening is a specific recommendation generated by Microsoft Defender for Cloud, focusing on tightening Network Security Group (NSG) rules for Azure Virtual Machines. It analyzes actual traffic patterns to suggest more restrictive NSG configurations, reducing the attack surface by recommending to block unnecessary ports. However, it is a dynamic, machine-learning-driven *recommendation* for specific resources, not the overarching *benchmark* or *policy set* that provides broad network security guidance.
- ✗
Network Security Group (NSG) flow logs
Why it's wrong here
Network Security Group (NSG) flow logs are a diagnostic feature that records information about IP traffic flowing through an NSG. These logs capture source/destination IP addresses, ports, protocols, and whether traffic was allowed or denied, providing crucial data for auditing, troubleshooting, and security analysis. While flow logs are essential for monitoring network activity and can inform security decisions, they are a data source for observation, not a mechanism that inherently provides security recommendations or policies itself.
- ✗
Just-in-time VM access
Why it's wrong here
Just-in-time (JIT) VM access is a feature within Microsoft Defender for Cloud designed to reduce the attack surface of virtual machines by limiting the time management ports are open. It allows temporary, controlled access to specific ports only when needed, significantly decreasing exposure to brute-force attacks. While JIT is a powerful security control for access management, it is a specific *feature* to secure VM management ports, not a comprehensive *benchmark* or *policy set* for general network security recommendations across an entire Azure environment.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Network security
Network security is the practice of protecting a computer network from unauthorized access, misuse, malfunction, modification, destruction, or improper disclosure, ensuring the confidentiality, integrity, and availability of data and resources.
Key term
Denial-of-service
A Denial-of-service (DoS) attack is an attempt to make a computer, network, or online service unavailable to its intended users by overwhelming it with fake traffic or requests.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.