Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard

A small non-profit organization wants to implement a basic, cost-effective security solution to protect its Azure virtual machines (VMs) from common threats, such as malware and suspicious activities. They need file integrity monitoring and just-in-time VM access but have a limited budget. Which capability of Microsoft Defender for Cloud should they enable?

  1. AMicrosoft Defender for Containers
  2. BMicrosoft Defender for Servers
  3. CMicrosoft Defender for SQL
  4. DMicrosoft Defender for App Service
Show answer & explanation

Correct answer: B. Microsoft Defender for Servers

Microsoft Defender for Servers (a plan within Microsoft Defender for Cloud) provides threat protection for Windows and Linux VMs, including file integrity monitoring, just-in-time VM access, and adaptive application controls, which aligns with the needs for basic VM protection and specific security controls.

Why the other options are wrong

  • A. Microsoft Defender for Containers protects containerized workloads, not VMs.
  • C. Microsoft Defender for SQL protects SQL databases, not VMs.
  • D. Microsoft Defender for App Service protects Azure App Service resources, not VMs.

Microsoft Defender for Servers

A plan within Microsoft Defender for Cloud that provides advanced threat protection for Windows and Linux virtual machines and physical servers, including features like just-in-time VM access, file integrity monitoring, and adaptive application controls.

  • Protects Azure VMs and on-premises servers
  • Includes Just-in-Time (JIT) VM access
  • Provides File Integrity Monitoring (FIM)

Memory trick: Defender for Servers protects your virtual machines like a strong guard.

More Describe the capabilities of Microsoft Security solutions questions