SC-100 Security Posture Management 2 — Questions and Answers
Question 1: A security architect is designing posture management for a hybrid environment. Which Defender for Cloud feature provides agentless assessment of on-premises servers onboarded through Azure Arc?
- Defender for Servers Plan 1 with MMA agent
- Agentless scanning available in Defender CSPM and Defender for Servers Plan 2 (Correct answer)
- Log Analytics workspace direct connection
- Microsoft Monitoring Agent (MMA) only
Correct answer: Agentless scanning available in Defender CSPM and Defender for Servers Plan 2
Agentless scanning in Defender CSPM and Defender for Servers Plan 2 can assess Azure Arc-onboarded machines without requiring an agent installed on the server.
Question 2: Which metric in Microsoft Defender for Cloud represents the maximum achievable Secure Score if all recommendations are remediated?
- Current score
- Potential score increase
- Max score (Correct answer)
- Security health percentage
Correct answer: Max score
The Max score in Defender for Cloud represents the highest possible Secure Score if every recommendation within a security control is remediated.
Question 3: An architect needs to exempt a specific resource from a Defender for Cloud recommendation without affecting the overall Secure Score calculation for other resources. What should they configure?
- Disable the entire security policy for the subscription
- Create an exemption rule on the recommendation for that specific resource (Correct answer)
- Remove the resource from the monitored scope
- Set the recommendation severity to Informational
Correct answer: Create an exemption rule on the recommendation for that specific resource
Exemption rules in Defender for Cloud allow specific resources or subscriptions to be excluded from a recommendation, either as mitigated or as a waiver, without disabling it globally.
Question 4: What is the role of 'security initiatives' in Microsoft Defender for Cloud?
- They are automated runbooks that respond to security alerts
- They are collections of Azure Policy definitions grouped to achieve a specific security goal (Correct answer)
- They define RBAC roles for security team members
- They are pre-built threat hunting queries in Microsoft Sentinel
Correct answer: They are collections of Azure Policy definitions grouped to achieve a specific security goal
Security initiatives in Defender for Cloud are collections of Azure Policy definitions assigned together to assess and enforce security standards across your environment.
Question 5: Which Defender for Cloud feature continuously monitors the security configuration of Azure resources and provides prioritized recommendations to reduce attack surface?
- Microsoft Defender Threat Intelligence
- Continuous assessment with security recommendations (Correct answer)
- Microsoft Defender for Endpoint EDR
- Azure Security Benchmark audit logs
Correct answer: Continuous assessment with security recommendations
Continuous assessment in Defender for Cloud constantly evaluates resource configurations against the Microsoft Cloud Security Benchmark and provides prioritized remediation recommendations.
Question 6: A company wants to track posture improvements over time and share progress reports with executive leadership. Which Defender for Cloud capability supports this need?
- Alert suppression rules
- Workbooks and the Governance feature with SLA tracking (Correct answer)
- Adaptive network hardening
- Just-in-time VM access logs
Correct answer: Workbooks and the Governance feature with SLA tracking
Defender for Cloud Workbooks provide customizable dashboards for posture trends, and the Governance feature assigns owners to recommendations with due dates and SLA tracking for executive reporting.
Question 7: What does the 'Microsoft Cloud Security Benchmark' (MCSB) replace, and what is its primary purpose?
- It replaces NIST SP 800-53 as the global security standard
- It replaces the Azure Security Benchmark and provides prescriptive best-practice recommendations aligned to common compliance frameworks (Correct answer)
- It replaces CIS Controls specifically for AWS workloads
- It replaces Secure Score as the primary posture metric
Correct answer: It replaces the Azure Security Benchmark and provides prescriptive best-practice recommendations aligned to common compliance frameworks
MCSB succeeded the Azure Security Benchmark and provides Microsoft's best-practice security recommendations mapped to common frameworks like CIS, NIST, and PCI-DSS across cloud services.
A security architect is designing posture management for a hybrid environment.
Which Defender for Cloud feature provides agentless assessment of on-premises servers onboarded through Azure Arc?