nerdexam
Microsoft

SC-100 · Question #340

You have an Azure subscription. You have a subscription to a third-party cloud provider. The subscription contains 100 virtual machines. You manage cloud security for both subscriptions from the…

The correct answer is B. Azure Arc C. Microsoft Defender for Cloud. Validating security posture across both Azure and a third-party cloud requires two capabilities: extending Azure's management plane to the external cloud, and then assessing security posture from that plane. Azure Arc (B) is the bridge: it onboards non-Azure resources…

Design security solutions for infrastructure

Question

You have an Azure subscription. You have a subscription to a third-party cloud provider. The subscription contains 100 virtual machines. You manage cloud security for both subscriptions from the Azure subscription. You need to recommend a solution to validate the security posture of the virtual machines. Which two services should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct answer is worth one point.

Options

  • AMicrosoft Sentinel
  • BAzure Arc
  • CMicrosoft Defender for Cloud
  • DAzure Lighthouse
  • EMicrosoft Defender for Endpoint

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    71% (24)
  • D
    15% (5)
  • E
    12% (4)

Explanation

Validating security posture across both Azure and a third-party cloud requires two capabilities: extending Azure's management plane to the external cloud, and then assessing security posture from that plane. Azure Arc (B) is the bridge: it onboards non-Azure resources - including VMs running in other cloud providers - as Arc-enabled machines, making them visible and manageable within the Azure ecosystem. Microsoft Defender for Cloud (C) is the Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) that performs the actual security posture assessment, identifies misconfigurations, and generates security recommendations and a secure score. Once third-party VMs are onboarded via Arc, Defender for Cloud can extend its posture evaluation to them. A (Sentinel) is a SIEM/SOAR tool for threat detection and investigation, not posture validation. D (Azure Lighthouse) is for delegated management across multiple Azure tenants, not multi-cloud VM security. E (Defender for Endpoint) provides EDR capabilities but does not assess cloud security posture or configuration compliance.

Topics

#Cross-cloud security#Azure Arc#Microsoft Defender for Cloud#Security posture management

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice