SC-900 Azure Update Manager Practice Question
Your organization uses Microsoft Defender for Cloud to protect Azure virtual machines. You need to ensure that critical vulnerabilities identified on the VMs are automatically remediated using a just-in-time patching mechanism. What should you configure?
⚠ Common exam trap
Candidates might confuse security controls (like JIT VM access) with actual patch deployment mechanisms. The question specifically asks for a patching mechanism, not an access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Azure Update Manager
Azure Update Manager is a unified service that provides managed update capabilities for Azure VMs and Arc-enabled servers. It enables just-in-time patching by allowing you to schedule and apply critical updates as needed, automatically remediating vulnerabilities. In contrast, Adaptive application controls and just-in-time VM access in Defender for Cloud are security controls that reduce attack surface but do not apply patches. Intune is for endpoint management, and Azure Automation Update Management is a legacy solution being replaced by Azure Update Manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable adaptive application controls and just-in-time VM access in Defender for Cloud
Why it's wrong here
Incorrect. Adaptive application controls and just-in-time VM access enhance security by controlling applications and network access, but they do not install patches.
- ✗
Deploy Microsoft Intune for update management
Why it's wrong here
Incorrect. Microsoft Intune is a cloud-based endpoint management solution, not designed for managing updates on Azure VMs.
- ✗
Configure Azure Automation Update Management
Why it's wrong here
Incorrect. Azure Automation Update Management is a legacy solution; Azure Update Manager is the current recommended service for patching.
- ✓
Enable Azure Update Manager
Why this is correct
Correct. Azure Update Manager provides automated patching for Azure VMs, enabling just-in-time remediation of critical vulnerabilities.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.