SC-200 · Question #222
You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1. You enable agentless scanning. You need to prevent Server1 from being scanned. The…
The correct answer is A. Create an exclusion tag. Microsoft Defender for Cloud's agentless scanning supports resource-level exclusions via Azure resource tags. By applying a designated exclusion tag (e.g., 'ExcludeFromMDCVulnAssessment') directly to Server1, the scanner automatically skips that resource. This requires no…
Question
You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1. You enable agentless scanning. You need to prevent Server1 from being scanned. The solution must minimize administrative effort. What should you do?
Options
- ACreate an exclusion tag.
- BUpgrade the subscription to Defender for Servers Plan 2.
- CCreate a governance rule.
- DCreate an exclusion group.
How the community answered
(34 responses)- A74% (25)
- B3% (1)
- C18% (6)
- D6% (2)
Explanation
Microsoft Defender for Cloud's agentless scanning supports resource-level exclusions via Azure resource tags. By applying a designated exclusion tag (e.g., 'ExcludeFromMDCVulnAssessment') directly to Server1, the scanner automatically skips that resource. This requires no subscription-level changes, no policy creation, and no group management - making it the minimum-effort solution. Upgrading to Plan 2 (B) would expand capabilities rather than exclude resources. Governance rules (C) are for compliance posture management, not scan exclusions. Exclusion groups (D) are not a native feature of Defender for Servers agentless scanning.
Topics
Community Discussion
No community discussion yet for this question.