Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization wants to use Microsoft Defender for Cloud to secure Azure virtual machines. Which feature should they enable to get vulnerability assessment without additional agents?

⚠ Common exam trap

It's easy for candidates to confuse 'vulnerability assessment' with other security controls like file integrity monitoring or adaptive application controls, not realizing that Defender for Cloud offers a dedicated, agentless vulnerability scanning capability specifically for VMs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vulnerability assessment

Microsoft Defender for Cloud includes a built-in vulnerability assessment solution for Azure virtual machines that does not require any additional agents. When enabled, it uses the Qualys scanner integrated directly into the platform to continuously scan for vulnerabilities, providing findings without the need to deploy or manage separate agents on the VMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • File integrity monitoring

    Why it's wrong here

    File integrity monitoring (FIM) tracks modifications to critical operating system files, application files, and registry keys to detect potential tampering or malware. While crucial for detecting post-compromise activity or unauthorized changes, it does not actively scan for software vulnerabilities, misconfigurations, or missing patches within the system itself. Its primary role is to monitor the integrity of files, not to assess the inherent security weaknesses of the software.

  • Just-in-time VM access

    Why it's wrong here

    Just-in-time (JIT) VM access significantly reduces the attack surface by only opening management ports, such as RDP or SSH, for a limited duration and from specified IP addresses when explicitly requested. This security control minimizes exposure to brute-force attacks and unauthorized access attempts. However, JIT access is a preventative measure against unauthorized network access, not a mechanism to discover or assess software vulnerabilities present *within* the virtual machine's operating system or installed applications.

  • Adaptive application controls

    Why it's wrong here

    Adaptive application controls in Microsoft Defender for Cloud create an allowlist of known-safe applications for Windows servers, preventing the execution of unauthorized or malicious software. This capability enhances security by restricting what can run on a machine, thereby reducing the risk of malware execution and preventing the spread of threats. While effective in preventing certain types of attacks, it does not perform scans to identify existing software vulnerabilities, misconfigurations, or missing patches within the approved applications or the operating system itself.

  • Vulnerability assessment

    Why this is correct

    Microsoft Defender for Cloud's vulnerability assessment capability actively scans virtual machines, SQL databases, and other resources for security weaknesses, misconfigurations, and missing updates. It identifies known vulnerabilities (CVEs) in operating systems and installed applications, providing actionable recommendations to remediate these findings. This feature is crucial for maintaining a strong security posture by proactively discovering and addressing potential entry points for attackers, often leveraging integrated solutions like Qualys or Microsoft Defender for Endpoint's TVM.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.