SC-900 Microsoft Defender for Cloud 2 — Questions and Answers
Question 1: What does Microsoft Defender for Servers provide?
- Threat detection and advanced defenses for Windows and Linux virtual machines and on-premises servers (Correct answer)
- Server performance monitoring, auto-scaling, and capacity planning
- Backup and disaster recovery services for Azure virtual machines
- Network segmentation and micro-segmentation for VM traffic
Correct answer: Threat detection and advanced defenses for Windows and Linux virtual machines and on-premises servers
Microsoft Defender for Servers provides threat detection, vulnerability assessment, and advanced defenses for Windows and Linux machines in any environment.
Question 2: What is the purpose of Just-in-Time (JIT) VM access in Microsoft Defender for Cloud?
- To lock down inbound traffic to VMs and open management ports only when access is needed for a limited time (Correct answer)
- To automatically scale virtual machines based on real-time CPU and memory demand
- To provide instant recovery of virtual machines following a security incident or breach
- To enable real-time performance monitoring and diagnostics on virtual machines
Correct answer: To lock down inbound traffic to VMs and open management ports only when access is needed for a limited time
JIT VM access minimizes attack surface by keeping management ports closed and opening them only for approved requests during a defined time window.
Question 3: What are Adaptive Application Controls in Microsoft Defender for Cloud?
- An intelligent machine learning-based solution that defines allowlists of known-safe applications for machines (Correct answer)
- A tool for auto-scaling applications based on user load and CPU utilization
- A compliance feature for classifying and labeling application data
- A deployment tool for packaging and distributing containerized applications
Correct answer: An intelligent machine learning-based solution that defines allowlists of known-safe applications for machines
Adaptive Application Controls use machine learning to recommend and enforce allowlists of applications that should be permitted to run on specific groups of machines.
Question 4: What does Microsoft Defender for SQL protect?
- Azure SQL Database, SQL Managed Instance, Azure Synapse Analytics, and SQL Server on machines (Correct answer)
- Only on-premises SQL Server installations in corporate data centers
- Only Azure Cosmos DB and other NoSQL database services
- Only SQL Server instances running in Azure Virtual Machines exclusively
Correct answer: Azure SQL Database, SQL Managed Instance, Azure Synapse Analytics, and SQL Server on machines
Microsoft Defender for SQL covers multiple deployment models including Azure SQL Database, SQL Managed Instance, Synapse Analytics, and SQL Server on any machine.
Question 5: What is the regulatory compliance dashboard in Microsoft Defender for Cloud used for?
- Showing compliance status mapped against regulatory standards such as PCI DSS, ISO 27001, and SOC 2 (Correct answer)
- Filing compliance reports directly with government regulatory agencies
- Managing and assigning Azure Policy definitions across subscriptions
- Auditing user access to sensitive compliance-related documents and files
Correct answer: Showing compliance status mapped against regulatory standards such as PCI DSS, ISO 27001, and SOC 2
The regulatory compliance dashboard maps your current security controls to specific compliance frameworks, showing your compliance posture at a glance.
Question 6: What does Microsoft Defender for Containers provide?
- Threat protection, vulnerability assessment, and misconfiguration detection for Kubernetes and container environments (Correct answer)
- Container registry hosting and image distribution for Azure users
- Auto-scaling and load balancing for containerized microservices
- Cost optimization recommendations for Azure Kubernetes Service clusters
Correct answer: Threat protection, vulnerability assessment, and misconfiguration detection for Kubernetes and container environments
Microsoft Defender for Containers provides runtime threat protection, image vulnerability scanning, and misconfiguration detection for Kubernetes environments.
Question 7: What is Adaptive Network Hardening in Microsoft Defender for Cloud?
- A feature that analyzes network traffic and recommends stricter NSG rules based on actual traffic patterns (Correct answer)
- An automated tool that configures Azure Firewall policies
- A DDoS protection service for Azure public-facing resources
- A VPN management tool for hybrid network connectivity
Correct answer: A feature that analyzes network traffic and recommends stricter NSG rules based on actual traffic patterns
Adaptive Network Hardening analyzes actual traffic and threat intelligence to recommend Network Security Group rules that go beyond the current permissive configuration.
What does Microsoft Defender for Servers provide?