nerdexam
Microsoft

SC-100 · Question #84

You have an Azure subscription that is used as an Azure landing zone for an application. You need to evaluate the security posture of all the workloads in the landing zone. What should you do first?

The correct answer is C. Enable the Defender plan for all resource types in Microsoft Defender for Cloud. Enabling the Defender plan for all resource types in Microsoft Defender for Cloud (C) is the correct first step because Defender for Cloud is the primary Azure tool for security posture management (CSPM). Without enabling the paid Defender plans, you only get a limited…

Design security operations, identity, and compliance capabilities

Question

You have an Azure subscription that is used as an Azure landing zone for an application. You need to evaluate the security posture of all the workloads in the landing zone. What should you do first?

Options

  • AAdd Microsoft Sentinel data connectors.
  • BConfigure Continuous Integration/Continuous Deployment (CI/CD) vulnerability scanning.
  • CEnable the Defender plan for all resource types in Microsoft Defender for Cloud.
  • DObtain Azure Active Directory Premium Plan 2 licenses.

How the community answered

(36 responses)
  • A
    17% (6)
  • B
    6% (2)
  • C
    72% (26)
  • D
    6% (2)

Explanation

Enabling the Defender plan for all resource types in Microsoft Defender for Cloud (C) is the correct first step because Defender for Cloud is the primary Azure tool for security posture management (CSPM). Without enabling the paid Defender plans, you only get a limited free-tier assessment; enabling all plans activates full coverage including vulnerability assessments, threat protection, and Secure Score recommendations for every resource type in the landing zone. Adding Microsoft Sentinel data connectors (A) is useful for threat detection, but Sentinel is a SIEM tool, not a security posture management tool. CI/CD vulnerability scanning (B) addresses pipeline security, not runtime workload posture. Azure AD Premium Plan 2 (D) enables identity protection features like Privileged Identity Management but does not evaluate workload security posture.

Topics

#Azure Defender for Cloud#Security Posture Management#Cloud Workload Protection#Security Operations

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice