nerdexam
Microsoft

SC-100 · Question #316

You have an Azure subscription. The subscription contains 100 virtual machines that run Linux on Windows Server. The subscription uses Microsoft Defender for Servers Plan 1. You need to recommend a…

The correct answer is B. Microsoft Defender Vulnerability Management. Microsoft Defender Vulnerability Management (MDVM) is the right choice because it provides a unified dashboard that addresses all three listed requirements with minimal administrative effort: (1) it surfaces asset inventory and can identify VMs not enrolled or onboarded to…

Design security solutions for infrastructure

Question

You have an Azure subscription. The subscription contains 100 virtual machines that run Linux on Windows Server. The subscription uses Microsoft Defender for Servers Plan 1. You need to recommend a solution to identify and remediate virtual machines that have the following characteristics:

  • Are NOT onboarded to Defender for Servers
  • Are missing critical updates
  • Have risky apps installed

The solution must minimize administrative effort. What should you include in the recommendation?

Options

  • AMicrosoft Defender External Attack Surface Management (Defender EASM)
  • BMicrosoft Defender Vulnerability Management
  • CMicrosoft Defender Threat Intelligence (Defender TI)
  • DMicrosoft Intune Advanced Analytics

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    81% (30)
  • C
    5% (2)
  • D
    11% (4)

Explanation

Microsoft Defender Vulnerability Management (MDVM) is the right choice because it provides a unified dashboard that addresses all three listed requirements with minimal administrative effort: (1) it surfaces asset inventory and can identify VMs not enrolled or onboarded to Defender for Servers; (2) it identifies missing critical security updates across operating systems; and (3) it detects risky or vulnerable software applications installed on endpoints. MDVM is natively integrated with Defender for Cloud and Defender for Servers, so no separate tooling or manual correlation is needed. Option A (Defender EASM) focuses on discovering and managing an organization's external internet-facing attack surface, not internal VM compliance gaps. Option C (Defender TI) is a threat intelligence feed for researching threat actors and indicators of compromise, not for remediating VM-level vulnerabilities. Option D (Intune Advanced Analytics) is a device management and compliance tool primarily for endpoint management, not Azure VM security posture.

Topics

#Vulnerability Management#Microsoft Defender for Servers#Security Posture Management#Infrastructure Security

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice