nerdexam
Microsoft

SC-100 · Question #249

You have an Azure subscription. The subscription contains 100 virtual machines that run Windows Server. The virtual machines are managed by using Azure Policy and Microsoft Defender for Servers. You…

The correct answer is D. adaptive application controls in Defender for Servers. Adaptive application controls in Microsoft Defender for Servers (part of Defender for Cloud) is the feature specifically designed to manage application allowlists and blocklists on virtual machines. It uses machine learning to analyze running processes and recommend an…

Design security solutions for infrastructure

Question

You have an Azure subscription. The subscription contains 100 virtual machines that run Windows Server. The virtual machines are managed by using Azure Policy and Microsoft Defender for Servers. You need to enhance security on the virtual machines. The solution must meet the following requirements:

  • Ensure that only apps on an allowlist can be run.
  • Require administrators to confirm each app added to the allowlist.
  • Automatically add unauthorized apps to a blocklist when an attempt is

made to launch the app.

  • Require administrators to approve an app before the app can be moved

from the blocklist to the allowlist. What should you include in the solution?

Options

  • Aa compute policy in Azure Policy
  • Bapp governance in Microsoft Defender for Cloud Apps
  • Cadmin consent settings for enterprise applications in Microsoft Entra ID
  • Dadaptive application controls in Defender for Servers

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    13% (3)
  • C
    4% (1)
  • D
    75% (18)

Explanation

Adaptive application controls in Microsoft Defender for Servers (part of Defender for Cloud) is the feature specifically designed to manage application allowlists and blocklists on virtual machines. It uses machine learning to analyze running processes and recommend an allowlist, requires administrator review and approval for each application before it is added to the allowlist, and automatically flags unauthorized applications as potential violations when they attempt to run - effectively treating them as blocklisted until an admin approves them. A (Azure Policy compute policies) enforces VM configuration but does not manage per-application allowlists. B (app governance in Defender for Cloud Apps) governs OAuth app permissions in SaaS environments, not VM-level process execution. C (admin consent for enterprise apps in Entra ID) controls OAuth consent for cloud apps, not on-VM application execution.

Topics

#Adaptive Application Controls#Defender for Servers#Application Control#Virtual Machine Security

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice