Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

This topic focuses on configuring Microsoft Defender for Servers in Microsoft Defender for Cloud, including:

  • Selecting Defender for Servers Plan 1 or Plan 2
  • Configuring vulnerability scanning
  • Understanding agent-based and agentless assessments
  • Integrating Microsoft Defender for Endpoint
  • Configuring endpoint detection and response (EDR)
  • Protecting Azure, on-premises, AWS, and GCP servers
  • Reviewing security recommendations and protection coverage
  • Troubleshooting incomplete or unhealthy protection

1. What Is Microsoft Defender for Servers?

Microsoft Defender for Servers is a workload protection plan in Microsoft Defender for Cloud that protects supported Windows and Linux servers and virtual machines.

It can provide:

  • Endpoint detection and response
  • Antivirus and antimalware protection
  • Vulnerability assessment
  • Software inventory
  • Security recommendations
  • Security configuration assessment
  • File Integrity Monitoring
  • Agentless secret scanning
  • Agentless malware scanning
  • Agentless software inventory
  • Operating-system update assessment
  • Regulatory compliance insights
  • Integration with Microsoft Defender for Endpoint
  • Integration with Microsoft Sentinel

Defender for Servers supports servers running in:

  • Azure
  • On-premises datacenters
  • Amazon Web Services
  • Google Cloud Platform
  • Other supported hybrid environments

For non-Azure servers, Azure Arc-enabled servers is generally the preferred onboarding method when the organization requires the broadest Defender for Servers functionality.

Defender for Servers is not a replacement for:

  • Operating-system hardening
  • Patch management
  • Identity security
  • Network segmentation
  • Secure application development
  • Backup protection
  • Firewall configuration
  • Incident response procedures

Instead, it provides centralized security visibility, assessment, detection, and protection capabilities across supported server environments.


2. Defender for Servers Plans

Defender for Servers has two primary paid plans:

  • Plan 1
  • Plan 2

Plan 1

Plan 1 is the entry-level plan and focuses primarily on endpoint protection capabilities provided through the Microsoft Defender for Endpoint integration.

Important capabilities include:

  • Endpoint detection and response
  • Microsoft Defender for Endpoint integration
  • Antivirus and antimalware protection
  • Threat detection
  • Endpoint investigation
  • Attack surface reduction capabilities
  • Vulnerability information through the Defender for Endpoint sensor

Plan 1 is appropriate when the primary requirement is server endpoint protection and EDR.

Plan 2

Plan 2 includes Plan 1 capabilities and adds advanced server security and assessment capabilities.

Depending on the supported server type and configuration, Plan 2 can provide:

  • Agentless vulnerability assessment
  • Agentless software inventory
  • Agentless secret scanning
  • Agentless malware scanning
  • File Integrity Monitoring
  • Operating-system configuration assessment
  • Security baseline assessment
  • Operating-system update assessment
  • Premium Microsoft Defender Vulnerability Management capabilities
  • Additional security posture capabilities
  • A free daily data-ingestion benefit for eligible data types and supported configurations

Plan 2 also supports advanced vulnerability-management capabilities such as certificate assessment, security baseline assessment, and vulnerable application blocking where supported.

Plan Comparison

CapabilityPlan 1Plan 2
Microsoft Defender for Endpoint integrationYesYes
EDRYesYes
Antivirus and antimalwareYesYes
Agent-based vulnerability assessmentYesYes
Agentless vulnerability assessmentNoYes
Agentless software inventoryLimited or not availableYes, where supported
Agentless secret scanningNoYes, where supported
Agentless malware scanningNoYes, where supported
File Integrity MonitoringNoYes
Advanced Defender Vulnerability Management capabilitiesNoYes
Operating-system security baseline assessmentNoYes, where supported
Operating-system update assessmentNoYes

Feature availability varies by:

  • Operating system
  • Azure or non-Azure environment
  • Azure Arc onboarding status
  • Subscription and resource scope
  • Defender for Servers plan
  • Agent availability
  • Current Microsoft support matrix

Do not assume that every feature is available for every Azure VM, Arc-enabled server, AWS instance, or GCP instance.


3. Where Defender for Servers Is Configured

Defender for Servers is configured in Microsoft Defender for Cloud.

A typical configuration path is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the relevant Azure subscription, AWS account, or GCP project.
  4. Open the Defender plans page.
  5. Locate Defender for Servers.
  6. Select the desired plan.
  7. Open the plan’s settings to configure monitoring and security features.

When Defender for Servers is enabled, several capabilities are enabled by default. You can then modify individual settings according to the organization’s requirements.

Common Configuration Areas

Defender for Servers settings can include:

  • Endpoint protection
  • Vulnerability assessment
  • Agentless scanning
  • File Integrity Monitoring
  • Security configuration assessment
  • Operating-system update assessment
  • Data collection
  • Log Analytics workspace configuration
  • Resource-level exclusions
  • Coverage and monitoring settings

4. Subscription-Level and Resource-Level Configuration

Microsoft generally recommends enabling Defender for Servers at the subscription level.

Subscription-level enablement provides:

  • Consistent coverage
  • Easier governance
  • Centralized configuration
  • Better visibility into protected and unprotected resources
  • Simplified licensing management
  • Easier policy-based deployment

However, resource-level configuration can be useful when:

  • Different machines require different plans.
  • A specific server must be excluded.
  • A phased deployment is required.
  • A test environment is being evaluated.
  • The organization needs more granular coverage.

Important Plan Scope Detail

Plan 1 can be enabled or disabled at the resource level.

Plan 2 is generally enabled at the subscription level. It can be disabled at the resource level, but it cannot be enabled at the resource level in the same way as Plan 1.

Exam Tip

If a question asks for the simplest way to protect all supported machines in a subscription, choose subscription-level Defender for Servers enablement unless the scenario specifically requires granular resource-level configuration.


5. Azure, Hybrid, and Multicloud Protection

Azure Virtual Machines

Azure VMs are already Azure resources. Defender for Cloud can associate them directly with the subscription and resource group.

The general process is:

  1. Enable Defender for Servers for the subscription.
  2. Select Plan 1 or Plan 2.
  3. Configure the required monitoring and scanning settings.
  4. Verify Defender for Endpoint and vulnerability-assessment status.

On-Premises Servers

On-premises servers should generally be onboarded as Azure Arc-enabled servers.

Azure Arc provides:

  • An Azure resource representation
  • An Azure resource ID
  • Resource-group placement
  • Azure RBAC integration
  • Azure Policy integration
  • Extension deployment
  • Defender for Cloud integration

AWS and GCP Servers

AWS accounts and GCP projects can be connected to Defender for Cloud through native multicloud connectors.

The connector can help discover and onboard supported machines as Azure Arc-enabled servers. This allows Defender for Cloud to apply supported server protection capabilities to those machines.

For the broadest Defender for Servers functionality, AWS and GCP machines generally require Azure Arc onboarding.


6. Azure Arc and Defender for Servers

Azure Arc is important because Defender for Servers is not simply a dashboard that reads cloud inventory.

The Azure Connected Machine agent can:

  • Establish the machine’s relationship with Azure
  • Provide the machine’s Azure resource identity
  • Enable supported extensions
  • Support policy and configuration assessment
  • Allow Defender for Cloud to deploy required components
  • Provide management and security connectivity

A typical architecture is:

Azure VM
|
+-----------------------------+
|
On-premises server |
| |
AWS EC2 instance |
| |
GCP Compute Engine instance |
| |
v v
Azure Arc-enabled server ---> Microsoft Defender for Cloud
|
+--> Defender for Servers
|
+--> Defender for Endpoint
|
+--> Defender Vulnerability Management
|
+--> Security recommendations
|
+--> Microsoft Sentinel

Directly installing the Defender for Endpoint agent on a non-Azure server can provide endpoint protection and EDR, but it is not equivalent to full Azure Arc onboarding. Some Defender for Servers capabilities require Arc-enabled onboarding.


7. Vulnerability Scanning

Vulnerability scanning identifies weaknesses in software and operating-system configurations.

Examples include:

  • Missing security updates
  • Vulnerable software versions
  • Known CVEs
  • Unsupported applications
  • Insecure configurations
  • Vulnerable browser extensions
  • Weak certificates
  • Exposed secrets
  • Applications that should be blocked or remediated

Defender for Servers integrates with Microsoft Defender Vulnerability Management.

Vulnerability information can be viewed through Defender for Cloud and the unified vulnerability-management experience in the Microsoft Defender portal.

Vulnerability Scanning Methods

Defender for Servers supports two main scanning approaches:

  1. Agent-based vulnerability scanning
  2. Agentless vulnerability scanning

8. Agent-Based Vulnerability Scanning

Agent-based scanning uses the Microsoft Defender for Endpoint sensor on the machine.

The sensor collects information about:

  • Installed software
  • Software versions
  • Operating-system information
  • Vulnerability exposure
  • Security configuration
  • Endpoint security state

Agent-based scanning is available with Defender for Servers Plan 1 and Plan 2 when the Defender for Endpoint integration is enabled and supported.

Advantages

  • Detailed machine-level information
  • Continuous assessment
  • Integration with endpoint protection
  • Fresh vulnerability data
  • Unified endpoint and vulnerability view
  • Works across supported Azure, Arc, AWS, and GCP machines

Requirements

Agent-based scanning generally requires:

  • A supported operating system
  • Defender for Servers Plan 1 or Plan 2
  • Defender for Endpoint integration
  • A healthy Defender for Endpoint sensor
  • Required network connectivity
  • Successful agent provisioning

For on-premises machines, Defender for Endpoint must generally be installed for agent-based vulnerability scanning.


9. Agentless Vulnerability Scanning

Agentless scanning evaluates supported machines without requiring a traditional scanning agent inside the operating system.

Agentless scanning is available with Defender for Servers Plan 2.

It can provide information about:

  • Software inventory
  • Vulnerabilities
  • Secrets
  • Malware
  • Machine posture
  • Other supported security assessments

Advantages

  • Minimal impact on machine performance
  • No additional operating-system scanning agent for supported capabilities
  • Useful when another EDR product is installed
  • Useful for broad cloud coverage
  • Can identify security issues even when agent-based coverage is incomplete

Limitations

Agentless scanning is not universally available for every:

  • Operating system
  • Cloud platform
  • Server type
  • Feature
  • Configuration
  • Security assessment

Always verify support before designing an architecture around agentless scanning.


10. How Agent-Based and Agentless Scanning Work Together

When both agent-based and agentless scanning are available, Defender for Cloud can present a unified view.

Typical behavior includes:

  • Machines with only agent-based scanning show agent-based results.
  • Machines with only agentless scanning show agentless results.
  • Machines with both methods generally use agent-based results for better freshness.
  • Machines using a partner vulnerability solution may show partner results by default.
  • Agentless results can be used for machines without a functioning partner scanner or when Defender Vulnerability Management results are explicitly selected.

This behavior prevents duplicate findings and helps Defender for Cloud select the most appropriate available source.


11. Partner Vulnerability Scanners

Organizations may already use a third-party vulnerability scanner.

Defender for Cloud supports partner-based vulnerability assessment solutions, including supported Qualys and Rapid7 integrations.

With a partner solution:

  1. The partner scanner evaluates the machine.
  2. Vulnerability results are reported to the partner management platform.
  3. The partner platform sends relevant findings to Defender for Cloud.
  4. Security teams can review the findings in Defender for Cloud.
  5. Administrators can open the partner console for detailed information.

A paid Defender for Servers plan is not necessarily required merely to use a supported partner vulnerability-assessment solution. However, other Defender for Cloud capabilities may require a paid plan.

Exam Tip

If the question asks for a Microsoft-native vulnerability solution, choose Microsoft Defender Vulnerability Management.

If the question describes an existing Qualys or Rapid7 deployment, consider the supported partner integration instead of automatically deploying another scanner.


12. Configuring Vulnerability Assessment

A typical configuration process is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the target subscription.
  4. Open Defender for Servers settings.
  5. Select Monitoring coverage or the relevant settings area.
  6. Locate Vulnerability assessment for machines.
  7. Select the required assessment solution.
  8. Apply the configuration.
  9. Verify that the scanner is deployed or active.
  10. Review the resulting recommendations and findings.

Vulnerability scanning is enabled by default in many Defender for Servers configurations, but administrators can manually modify the scanning settings when necessary.

Required Permissions

The permissions needed depend on the deployment method.

For example:

  • An administrator deploying the scanner may require Owner-level permissions at the resource-group level.
  • A security reader can view vulnerability findings.
  • Additional permissions may be required to modify Defender for Cloud plans or resource settings.

Use least privilege and avoid granting broad subscription-wide permissions unnecessarily.


13. Microsoft Defender for Endpoint Integration

Defender for Endpoint is the primary endpoint protection and EDR integration used by Defender for Servers.

The integration can provide:

  • Antivirus
  • Antimalware protection
  • Endpoint detection and response
  • Behavioral detection
  • Threat intelligence
  • Automated investigation and response
  • Threat hunting
  • Attack surface reduction
  • Security alerts
  • Vulnerability information
  • Software inventory

When Defender for Servers is enabled, Defender for Endpoint integration is enabled by default in supported configurations. Defender for Cloud can automatically provision the Defender for Endpoint sensor on supported machines.

EDR Data Flow

Protected server
|
v
Microsoft Defender for Endpoint sensor
|
v
Microsoft Defender for Endpoint service
|
v
Microsoft Defender for Cloud
|
+--> Security recommendations
+--> Security alerts
+--> Vulnerability findings
+--> Incident investigation
|
v
Microsoft Sentinel, when integrated

Security teams can review alerts in Defender for Cloud and pivot to the Microsoft Defender portal for deeper investigation and response.


14. Configuring Endpoint Protection

Endpoint protection settings are configured within the Defender for Servers plan settings.

Administrators should verify:

  • Defender for Endpoint integration is enabled.
  • The server is supported.
  • The endpoint sensor is installed.
  • The sensor is healthy.
  • Antivirus is enabled.
  • Security intelligence is current.
  • The machine is reporting to the correct tenant.
  • Conflicting endpoint security products are not preventing operation.
  • Required network endpoints are reachable.

Important Distinction

Enabling Defender for Servers does not guarantee that every machine is healthy immediately.

A server can be:

  • Connected to Azure Arc but missing Defender for Endpoint
  • Onboarded to Defender for Endpoint but not reporting correctly
  • Reporting EDR alerts but missing vulnerability data
  • Protected by antivirus but failing security configuration checks
  • Covered by Defender for Cloud but excluded from a specific feature

Protection status must be verified at the machine level.


15. Assessing EDR Configuration

Defender for Cloud can assess whether Defender for Endpoint is configured correctly.

Examples of EDR configuration checks include:

  • Antivirus is disabled or only partially configured.
  • Antivirus signatures are outdated.
  • Full or quick scans have not run recently.
  • Endpoint protection settings are incomplete.
  • The EDR solution is not functioning as expected.

Defender for Cloud can generate recommendations such as:

  • Resolve EDR configuration issues.
  • Enable or correctly configure antivirus.
  • Update outdated antivirus signatures.
  • Run required endpoint scans.

These checks help identify machines that technically have an EDR product installed but are not adequately protected.


16. EDR and Non-Microsoft Endpoint Products

An organization may already use a non-Microsoft EDR product.

In that situation, the organization should evaluate:

  • Whether Defender for Endpoint can coexist with the existing product
  • Whether the existing product must be removed
  • Whether passive or limited Defender for Endpoint modes are supported
  • Whether agentless scanning can provide vulnerability visibility
  • Whether the desired Defender for Servers features require Defender for Endpoint
  • Whether the existing EDR product provides equivalent capabilities

Agentless scanning can be useful for supported cloud machines when another EDR solution is installed. However, agentless scanning does not replace the full detection and response capabilities of Defender for Endpoint.


17. File Integrity Monitoring

File Integrity Monitoring, available with Defender for Servers Plan 2, helps identify changes to important files and registry settings.

It can help detect:

  • Unauthorized configuration changes
  • Changes to critical system files
  • Changes to security settings
  • Suspicious modifications
  • Potential persistence mechanisms
  • Changes that may indicate compromise

File Integrity Monitoring requires additional configuration after enabling Plan 2 and generally requires a Log Analytics workspace.

Administrators should identify:

  • Critical files
  • Critical directories
  • Important registry paths
  • Appropriate monitoring rules
  • Alerting requirements
  • Retention requirements

File Integrity Monitoring is not the same as a full backup solution. It identifies changes; it does not automatically restore files to a previous state.


18. Operating-System Security Configuration Assessment

Defender for Servers Plan 2 can assess operating-system configuration against supported security baselines.

Examples include:

  • Password policy
  • Security options
  • Services
  • Registry settings
  • File permissions
  • Operating-system security configuration
  • Other baseline settings

Some assessments require the Azure Policy machine configuration extension.

Machine Configuration can evaluate and, in supported scenarios, enforce settings inside the operating system.

Difference Between Defender Recommendations and Machine Configuration

  • Defender for Cloud recommendations identify security weaknesses.
  • Machine Configuration evaluates and can enforce specific configuration settings.
  • Azure Policy governs Azure resources and can assign or deploy configuration requirements.

These capabilities work together but are not interchangeable.


19. Data Collection and Log Analytics

Some Defender for Servers features require data collection through supported monitoring methods.

A Log Analytics workspace may be required for:

  • File Integrity Monitoring
  • Certain Plan 2 data-ingestion benefits
  • Supported monitoring and security data collection

When Plan 2 is enabled, eligible data types may receive a free daily ingestion benefit, subject to the current requirements and supported collection methods.

The benefit does not mean that all Log Analytics ingestion is free. It applies only to eligible data types and supported configurations.

Verify the Following

  • The machine reports to the intended workspace.
  • The appropriate data collection rule is configured.
  • Azure Monitor Agent is installed where required.
  • The workspace is in an appropriate region.
  • Data is actually arriving.
  • Retention and cost settings are appropriate.
  • Security data is not being collected unnecessarily.

20. Security Recommendations and Remediation

Defender for Cloud can generate recommendations for issues such as:

  • Defender for Endpoint is not installed.
  • Antivirus is disabled.
  • Vulnerability assessment is missing.
  • Vulnerable software is installed.
  • Security updates are missing.
  • EDR configuration is incomplete.
  • The server is not connected to Azure Arc.
  • Required extensions are missing.
  • Security configuration does not meet the baseline.
  • File Integrity Monitoring is not configured.

Recommendations can be remediated by:

  • Installing required agents
  • Enabling Defender for Servers
  • Updating software
  • Applying security configurations
  • Enabling antivirus
  • Correcting network access
  • Deploying extensions
  • Assigning appropriate policies
  • Reconfiguring the machine

A recommendation is not necessarily proof of an active attack. It usually indicates a security weakness or missing control.


21. Monitoring Protection Coverage

Defender for Cloud provides coverage information that helps identify:

  • Protected machines
  • Unprotected machines
  • Machines with incomplete onboarding
  • Machines missing required agents
  • Machines with unhealthy extensions
  • Machines without vulnerability assessment
  • Machines without EDR
  • Machines excluded from protection

Use coverage information to verify that the intended machines are actually protected.

A successful Arc connection alone does not prove that Defender for Servers, Defender for Endpoint, and vulnerability scanning are all functioning.


22. Troubleshooting Defender for Servers

The Server Is Missing from Defender for Cloud

Check:

  • Azure Arc connection status
  • Subscription and resource group
  • Onboarding credentials
  • Agent installation
  • Operating-system support
  • Network connectivity
  • Azure permissions
  • Resource provider registration

Defender for Endpoint Is Missing

Check:

  • Defender for Servers plan
  • Defender for Endpoint integration
  • Extension provisioning
  • Operating-system support
  • Proxy configuration
  • Firewall rules
  • TLS inspection
  • Existing endpoint security software
  • Local administrative permissions

Vulnerability Findings Are Missing

Check:

  • Whether vulnerability scanning is enabled
  • Whether the selected plan supports the desired scanning method
  • Whether the Defender for Endpoint sensor is healthy
  • Whether agentless scanning is supported
  • Whether a partner scanner is being used
  • Whether the initial scan has completed
  • Whether the machine is reporting current data

EDR Recommendations Appear

Check:

  • Antivirus status
  • Signature update status
  • Recent scan activity
  • Defender for Endpoint sensor health
  • Security policy configuration
  • Whether the machine is reporting to the correct tenant

File Integrity Monitoring Is Not Working

Check:

  • Defender for Servers Plan 2
  • Log Analytics workspace
  • Required monitoring configuration
  • Data collection rules
  • Azure Monitor Agent
  • Workspace connectivity
  • Monitored file and registry paths

23. Best Practices

Select the Plan Based on Requirements

Use Plan 1 when the primary need is endpoint protection and EDR.

Use Plan 2 when the organization requires advanced capabilities such as:

  • Agentless scanning
  • File Integrity Monitoring
  • Advanced vulnerability management
  • Security baseline assessment
  • Agentless secret or malware scanning
  • Additional server posture capabilities

Enable at the Appropriate Scope

Prefer subscription-level enablement for consistent coverage, but use resource-level controls when the deployment requires exceptions or phased adoption.

Use Azure Arc for Non-Azure Servers

Use Azure Arc-enabled servers for on-premises, AWS, and GCP servers when the organization needs the broadest supported Defender for Servers functionality.

Verify Protection, Not Just Enrollment

After onboarding, verify:

  • Arc connection
  • Defender for Endpoint status
  • Vulnerability scanning
  • Security recommendations
  • EDR alerts
  • Extension health
  • Data collection
  • Policy compliance

Use Least Privilege

Restrict access to:

  • Defender for Cloud configuration
  • Defender for Endpoint administration
  • Extension deployment
  • Vulnerability assessment configuration
  • Log Analytics workspaces
  • Resource groups and subscriptions

Avoid Duplicate Scanners

If a partner vulnerability scanner is already deployed, determine whether it should remain the authoritative scanner or whether Defender Vulnerability Management should be used.

Keep Security Components Updated

Maintain:

  • Operating-system updates
  • Defender for Endpoint sensor
  • Azure Connected Machine agent
  • Azure Monitor Agent
  • Security extensions
  • Vulnerability-scanning components

24. Key Exam Takeaways

  1. Defender for Servers Plan 1 focuses primarily on endpoint protection and EDR.
  2. Plan 2 includes Plan 1 capabilities plus advanced posture, scanning, and monitoring features.
  3. Agent-based vulnerability scanning uses the Defender for Endpoint sensor.
  4. Agentless vulnerability scanning is available with Plan 2 for supported machines.
  5. Defender Vulnerability Management is integrated with Defender for Servers.
  6. Direct Defender for Endpoint onboarding is not equivalent to full Azure Arc onboarding.
  7. Azure Arc is generally required for the broadest Defender for Servers functionality on non-Azure servers.
  8. AWS and GCP accounts can be connected to Defender for Cloud through native multicloud connectors.
  9. Defender for Cloud can assess EDR configuration, including antivirus status, signatures, and scan activity.
  10. A machine can be connected to Azure Arc but still lack healthy Defender for Endpoint protection.
  11. File Integrity Monitoring requires Plan 2 and additional configuration.
  12. Some Plan 2 capabilities require a Log Analytics workspace.
  13. Vulnerability scanning results can come from Defender Vulnerability Management or a supported partner scanner.
  14. Always check feature support for the specific operating system and cloud environment.
  15. Subscription-level enablement is generally preferred for consistent coverage.

Practice Exam Questions

Question 1

An organization wants to protect Azure VMs with endpoint detection and response and antivirus capabilities, but it does not require advanced agentless scanning or File Integrity Monitoring.

Which Defender for Servers plan is the most appropriate starting point?

A. Defender for Servers Plan 1
B. Defender for Servers Plan 2
C. Defender for Storage
D. Defender for Containers

Answer: A

Explanation: Plan 1 focuses primarily on endpoint protection capabilities provided through the Microsoft Defender for Endpoint integration. Plan 2 is required for additional advanced capabilities such as agentless scanning and File Integrity Monitoring.


Question 2

A company wants to perform vulnerability assessments on supported AWS EC2 instances without installing a traditional vulnerability-scanning agent inside the operating system.

Which configuration should the company use?

A. Defender for Servers Plan 1 with Azure Bastion
B. Defender for Servers Plan 2 with agentless scanning
C. Microsoft Sentinel only
D. Azure Firewall Premium only

Answer: B

Explanation: Defender for Servers Plan 2 supports agentless vulnerability scanning for supported machines, including supported onboarded AWS machines.


Question 3

An administrator has enabled Defender for Servers Plan 1. The organization wants vulnerability information based on installed software and the Microsoft Defender for Endpoint sensor.

What should the administrator configure?

A. Agent-based vulnerability scanning through Defender for Endpoint
B. Azure Front Door
C. Azure Private Link
D. File Integrity Monitoring

Answer: A

Explanation: Agent-based vulnerability scanning uses the Defender for Endpoint sensor and is available with Defender for Servers Plan 1 or Plan 2 when the required integration is enabled.


Question 4

An on-premises server is directly onboarded to Microsoft Defender for Endpoint. The administrator expects all Defender for Servers Plan 2 features to be available.

What is the correct conclusion?

A. All Plan 2 features are available automatically.
B. Direct Defender for Endpoint onboarding provides no protection.
C. Some advanced Defender for Servers capabilities require Azure Arc onboarding.
D. Plan 2 is available only for Windows client devices.

Answer: C

Explanation: Direct Defender for Endpoint onboarding can provide endpoint protection and EDR, but some Defender for Servers capabilities require the machine to be onboarded through Azure Arc.


Question 5

Which capability is primarily responsible for endpoint detection and response in Defender for Servers?

A. Azure Resource Graph
B. Microsoft Defender for Endpoint
C. Azure Policy
D. Azure Backup

Answer: B

Explanation: Microsoft Defender for Endpoint provides endpoint protection and EDR capabilities that are integrated into Defender for Servers.


Question 6

Defender for Cloud reports that a server’s antivirus signatures are outdated and that recent scans have not been completed.

What type of issue is this?

A. An EDR configuration issue
B. An Azure subscription billing issue
C. A storage firewall issue
D. An Azure Arc resource-group issue

Answer: A

Explanation: Defender for Cloud can assess EDR configuration and identify issues such as outdated signatures, disabled antivirus, or missing recent scans.


Question 7

An organization wants to monitor unauthorized changes to critical files and registry settings on supported servers.

Which Defender for Servers capability should it configure?

A. Agentless secret scanning
B. File Integrity Monitoring
C. Azure Bastion
D. Azure DDoS Protection

Answer: B

Explanation: File Integrity Monitoring helps detect changes to monitored files and registry settings. It is available with Defender for Servers Plan 2 and requires additional configuration.


Question 8

An organization already uses a supported Qualys vulnerability scanner and wants its findings to appear in Defender for Cloud.

What should the organization use?

A. A supported partner vulnerability-assessment integration
B. Azure Bastion
C. Microsoft Sentinel automation rules only
D. Azure Firewall application rules

Answer: A

Explanation: Defender for Cloud supports partner vulnerability-assessment integrations, including supported Qualys and Rapid7 scenarios.


Question 9

A server is shown as connected in Azure Arc, but Defender for Endpoint alerts and vulnerability information are missing.

What should the administrator check first?

A. Whether Azure Front Door is deployed
B. Whether Defender for Servers is enabled and the required Defender for Endpoint components are healthy
C. Whether the server has an Azure public IP address
D. Whether Azure Bastion is configured

Answer: B

Explanation: An Azure Arc connection does not automatically prove that Defender for Servers and Defender for Endpoint are fully operational. The administrator should verify the plan, integration, extension status, and sensor health.


Question 10

An organization wants to assess operating-system security settings against supported security baselines on Arc-enabled servers.

Which combination is most appropriate?

A. Azure DNS and Azure Firewall
B. Microsoft Sentinel and Azure Bastion
C. Defender for Servers Plan 2 and supported machine-configuration capabilities
D. Azure Storage and Azure Backup

Answer: C

Explanation: Defender for Servers Plan 2 supports operating-system configuration assessment, and supported scenarios may require the Azure Policy machine configuration extension.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply