This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
--> Implement security for servers and virtual machines (VMs)
--> Implement and manage agentless scanning for VMs in Defender for Servers
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Microsoft Defender for Servers is a workload protection plan in Microsoft Defender for Cloud that helps protect Windows and Linux servers running in:
- Azure
- Amazon Web Services
- Google Cloud Platform
- On-premises environments
- Other environments connected through Azure Arc
One of its important capabilities is vulnerability assessment. Vulnerability assessment identifies operating-system and software weaknesses, outdated applications, missing security updates, and other conditions that could expose a server to attack.
Defender for Servers supports two primary vulnerability-scanning approaches:
- Agent-based scanning
- Agentless scanning
Understanding the difference between these approaches, when agentless scanning is available, how to enable it, and how its results are used is important for the SC-500 exam.
What Is Agentless Scanning?
Agentless scanning assesses a virtual machine without requiring a vulnerability-scanning agent to be installed inside the guest operating system.
Instead of depending entirely on an operating-system agent, agentless scanning uses cloud-level access and inspection capabilities to collect information about supported machines. This can include information about:
- Operating-system configuration
- Installed software
- Vulnerable applications
- Security posture
- Machine configuration
- Potential exposure to known vulnerabilities
Agentless scanning is particularly useful when:
- Installing another agent is undesirable.
- The organization already uses a different endpoint security product.
- A machine cannot easily support an additional agent.
- The organization wants broader visibility into machine posture.
- The organization needs to assess supported cloud machines without relying exclusively on an in-guest sensor.
Agentless scanning is not a replacement for every endpoint security capability. It primarily improves assessment and visibility. It does not provide the same continuous in-guest detection and response functionality as Microsoft Defender for Endpoint.
Defender for Servers Plans
Agentless scanning is closely associated with Defender for Servers Plan 2.
Defender for Servers Plan 1
Plan 1 primarily provides core server protection capabilities, including integration with Microsoft Defender for Endpoint.
Important capabilities include:
- Endpoint detection and response
- Endpoint protection
- Software inventory through the integrated endpoint security experience
- Agent-based vulnerability assessment through Defender for Endpoint
- Security recommendations and alerts in Defender for Cloud
Plan 1 does not provide the full set of Plan 2 agentless assessment capabilities.
Defender for Servers Plan 2
Plan 2 includes the capabilities of Plan 1 and adds more advanced server protection and assessment features, including:
- Agentless machine scanning
- Additional Microsoft Defender Vulnerability Management capabilities
- Compliance and security posture assessment
- Operating-system configuration assessment
- Operating-system update assessment
- File Integrity Monitoring
- Additional malware and secrets-scanning capabilities in supported scenarios
- Premium vulnerability-management capabilities
The exact capabilities available can vary by operating system, cloud environment, machine type, and supported integration. Therefore, an exam question may require checking not only the selected plan but also whether the machine and environment support the feature.
Microsoft documentation identifies agentless scanning as a Plan 2 capability, while agent-based scanning through Defender for Endpoint is available with both Plan 1 and Plan 2.
Agent-Based Versus Agentless Scanning
| Characteristic | Agent-based scanning | Agentless scanning |
|---|---|---|
| Requires an in-guest agent | Yes | No vulnerability-scanning agent is required |
| Common integration | Microsoft Defender for Endpoint | Defender for Servers Plan 2 capabilities |
| Available with Plan 1 | Yes, through Defender for Endpoint | No |
| Available with Plan 2 | Yes | Yes |
| Provides endpoint detection and response | Through Defender for Endpoint | No |
| Useful when another EDR is installed | May create overlap or require careful planning | Often useful for supported cloud machines |
| Data freshness | Often more continuous or current | Depends on collection and assessment process |
| Coverage | Depends on sensor health and onboarding | Depends on supported machine and cloud scenario |
| Primary value | In-guest protection and vulnerability visibility | Agentless posture and vulnerability visibility |
Agent-Based Scanning
Agent-based scanning uses the Microsoft Defender for Endpoint sensor. The sensor collects endpoint information and supports capabilities such as:
- Endpoint detection and response
- Software inventory
- Vulnerability assessment
- Threat detection
- Security alerts
- Investigation and response
Agent-based scanning is generally valuable when the organization wants continuous endpoint protection and detailed in-guest telemetry.
However, it requires the sensor to be installed, onboarded, supported, and healthy. If the sensor is missing or malfunctioning, vulnerability results may be incomplete or unavailable.
Agentless Scanning
Agentless scanning does not require the same in-guest vulnerability-scanning agent. It can provide vulnerability and posture information for supported machines, including some machines where another endpoint detection product is being used.
Agentless scanning is especially useful when:
- The organization does not want to deploy the Defender for Endpoint sensor.
- A third-party EDR is already installed.
- The machine is a supported Azure virtual machine.
- The organization needs additional visibility without modifying the guest operating system.
Agentless scanning does not eliminate all requirements. The machine must still be supported, within the correct Defender for Servers scope, and accessible through the required Azure or connected-cloud mechanisms.
Microsoft Defender Vulnerability Management
Defender for Servers integrates with Microsoft Defender Vulnerability Management, commonly abbreviated as MDVM.
MDVM helps organizations discover and prioritize weaknesses by using information such as:
- Vulnerable software
- Missing updates
- Software versions
- Known vulnerabilities
- Exposure information
- Security recommendations
- Remediation priorities
The vulnerability data can be surfaced through the Microsoft Defender security experience and Microsoft Defender for Cloud.
The purpose is not simply to produce a list of Common Vulnerabilities and Exposures (CVEs). The broader goal is to help security teams determine:
- Which machines are vulnerable?
- Which applications are affected?
- How serious is the vulnerability?
- Is the vulnerable machine exposed?
- Which remediation should be performed first?
- Has the vulnerability been remediated?
Plan 2 provides access to additional premium Defender Vulnerability Management capabilities in supported scenarios. These may include advanced assessment and prioritization capabilities such as certificate assessment, security-baseline assessment, and other premium vulnerability-management features.
How Agentless Scanning Works
At a high level, the process is:
- Defender for Servers Plan 2 is enabled for the appropriate scope.
- Agentless scanning is enabled or remains enabled by default.
- Defender for Cloud identifies supported machines within that scope.
- Cloud-level assessment mechanisms collect supported machine information.
- Defender Vulnerability Management analyzes the collected information.
- Vulnerabilities and recommendations are displayed in Defender for Cloud and related Defender experiences.
- Administrators remediate the findings.
- The environment is rescanned or reassessed to confirm improvement.
Agentless scanning is an assessment capability. It does not automatically install operating-system updates or repair every vulnerability.
For example, if an agentless scan identifies an outdated version of an application, the scan reports the issue. The organization must still:
- Update the application.
- Remove the application.
- Change the configuration.
- Replace the virtual machine.
- Apply a compensating control.
- Accept or formally mitigate the risk.
Enabling Defender for Servers
Defender for Servers is enabled from the environment settings in Microsoft Defender for Cloud.
A typical portal workflow is:
- Open Microsoft Defender for Cloud.
- Select Environment settings.
- Select the relevant:
- Azure subscription
- AWS account
- GCP project
- Select Defender plans.
- Locate Servers.
- Turn the plan on.
- Select Plan 1 or Plan 2.
- Save the configuration.
The portal may default to a particular plan depending on the current experience. Always verify that the selected plan is the one required by the scenario.
For agentless scanning, the relevant environment must use Defender for Servers Plan 2. Vulnerability assessment is enabled by default when Defender for Servers Plan 1 or Plan 2 is enabled, but the available scanning method depends on the selected plan and environment.
Recommended Scope
Microsoft recommends enabling Defender for Servers at the subscription level when possible.
Subscription-level enablement provides:
- Consistent coverage
- Easier administration
- More predictable licensing
- Centralized policy management
- Fewer accidentally unprotected machines
Resource-level configuration can be used for exceptions, but it should be applied deliberately. Plan 2 cannot generally be enabled at the individual resource level in the same way as Plan 1; resource-level options may allow Plan 2 to be disabled where appropriate.
Configuring Vulnerability Assessment Settings
After enabling Defender for Servers, vulnerability-assessment settings can be configured from the Defender for Cloud environment settings.
A typical configuration path is:
- Open Microsoft Defender for Cloud.
- Select Environment settings.
- Select the subscription or connected environment.
- Open Defender for Servers.
- Locate the monitoring or configuration settings.
- Find Vulnerability assessment for machines.
- Select Edit configuration.
- Choose the required scanning configuration.
- Apply or save the changes.
Agentless scanning is enabled by default in supported Plan 2 scenarios. However, administrators should verify:
- The correct plan is enabled.
- The machine is in scope.
- The operating system is supported.
- The cloud environment is supported.
- Required permissions are available.
- Required connectivity and onboarding prerequisites are satisfied.
- The machine is not excluded by policy or resource-level settings.
Microsoft documentation indicates that agentless scanning is available with Plan 2 and is enabled by default in supported Plan 2 or Defender CSPM scenarios.
Agentless Scanning and Defender CSPM
Agentless scanning can also be available through Defender CSPM, depending on the supported scenario.
Defender CSPM provides cloud security posture management capabilities, while Defender for Servers provides workload protection for servers.
The two services can overlap in certain assessment capabilities. When troubleshooting or designing a solution, determine whether the capability is being provided by:
- Defender for Servers Plan 2
- Defender CSPM
- Defender for Endpoint
- Another integrated vulnerability scanner
Do not assume that enabling one plan automatically provides every feature for every machine type.
What Happens When Both Agent-Based and Agentless Scanning Are Available?
In some environments, a machine may be assessed through more than one method.
When both agent-based and agentless results are available, Defender for Cloud generally prioritizes the agent-based results because they are expected to provide fresher endpoint information.
This is important because an agent-based sensor may have more current knowledge of:
- Installed software
- Running processes
- Software changes
- Endpoint configuration
- Recently remediated vulnerabilities
Agentless results can still be valuable, particularly for machines without a healthy agent or for supported machines where agentless coverage is intentionally used.
The important exam concept is:
Agentless scanning expands coverage, but agent-based results may take precedence when both methods are available.
Using Third-Party Vulnerability Scanners
Organizations may already use a third-party vulnerability-management product, such as Qualys or Rapid7.
Defender for Servers supports certain bring-your-own-license, or BYOL, vulnerability-assessment integrations.
When a third-party scanner is configured:
- The partner scanner may provide the primary vulnerability results.
- Defender for Cloud can display the partner’s findings.
- Agentless scanning may still help assess machines that do not have the partner agent or do not have complete partner findings.
- Results and precedence depend on the configured scanner and supported integration.
Avoid deploying multiple vulnerability scanners without a clear design. Multiple scanners can create:
- Duplicate findings
- Conflicting severity values
- Increased resource consumption
- Confusing remediation ownership
- Unclear source-of-truth decisions
A good design should identify:
- Which scanner is authoritative
- Which machines are covered by each scanner
- How duplicate findings are handled
- Which team owns remediation
- How exceptions are documented
Agentless Scanning in Hybrid and Multicloud Environments
Defender for Servers supports more than Azure virtual machines.
Azure Virtual Machines
Azure VMs can be protected through the Azure subscription where Defender for Servers is enabled.
The VM must be:
- In the correct subscription
- Supported by the selected plan
- Running a supported operating system
- Included in the relevant monitoring scope
AWS and GCP
AWS accounts and GCP projects can be connected to Defender for Cloud.
The recommended approach generally uses Azure Arc-enabled servers to represent and manage connected machines. This provides a consistent Azure control-plane experience for security assessment and management.
The general process is:
- Connect the AWS account or GCP project to Defender for Cloud.
- Enable the required Defender plan.
- Onboard supported machines through the connected-cloud integration.
- Verify that the machines appear in Defender for Cloud.
- Confirm that the required protection and assessment capabilities are active.
On-Premises Servers
For on-premises servers, Azure Arc is recommended when full Defender for Servers functionality is required.
Directly installing Microsoft Defender for Endpoint on an on-premises machine can provide Plan 1-style endpoint protection functionality. However, it does not necessarily provide the complete set of Defender for Servers Plan 2 capabilities.
For example, under certain scenarios, Plan 2 adds premium vulnerability-management features beyond the basic Defender for Endpoint functionality, but the full set of Plan 2 capabilities requires the supported Defender for Cloud and Azure Arc integration.
The key exam distinction is:
Azure Arc is the preferred connection mechanism for obtaining the broadest Defender for Servers capabilities on non-Azure and on-premises servers.
Permissions
Proper permissions are required to configure and view vulnerability assessment.
A common permission distinction is:
- Owner at the resource-group level may be required to deploy or configure the scanner.
- Security Reader can view security findings and recommendations but does not have permission to make configuration changes.
The exact permissions depend on the operation being performed. For example:
- Viewing recommendations
- Enabling a Defender plan
- Changing monitoring settings
- Deploying required extensions
- Configuring a workspace
- Remediating a recommendation
These may require different roles.
Use least privilege rather than assigning Owner broadly to security analysts.
Relationship Between Agentless Scanning and EDR
Agentless scanning and endpoint detection and response serve different purposes.
Agentless Scanning
Agentless scanning focuses on assessment and visibility, such as:
- Vulnerable software
- Machine posture
- Configuration weaknesses
- Missing updates
- Security recommendations
EDR
EDR is provided through Microsoft Defender for Endpoint and focuses on detecting and responding to threats on the endpoint.
EDR capabilities include:
- Suspicious-process detection
- Behavioral detection
- Endpoint alerts
- Investigation
- Threat hunting
- Automated response
- Isolation and containment
- Evidence collection
Agentless scanning does not replace EDR. A machine can have agentless vulnerability assessment and still require an endpoint protection and detection solution.
EDR Configuration Assessment
Defender for Cloud can assess certain endpoint protection and EDR-related configuration conditions in supported Plan 2 scenarios.
Recommendations may identify conditions such as:
- Antivirus protection being disabled
- Antivirus being partially configured
- Outdated security intelligence
- A full or quick scan not having run recently
- Endpoint protection settings that do not meet expected requirements
These recommendations help identify machines that may technically have endpoint protection installed but are not adequately configured.
For example, a machine may have antivirus installed but still be at risk because:
- Real-time protection is disabled.
- Security signatures are outdated.
- A required scan has not run.
- The endpoint sensor is unhealthy.
- The machine is not properly onboarded.
EDR configuration assessment should therefore be treated as a validation and hardening capability, not merely an installation check.
Log Analytics Requirements
Some Defender for Servers Plan 2 capabilities require a Log Analytics workspace or related data-collection configuration.
This is especially important for:
- File Integrity Monitoring
- Certain data-ingestion benefits
- Supported security data collection
- Some assessment and monitoring scenarios
Plan 2 may include a free daily data-ingestion benefit for eligible data, but the benefit is not automatic for every data source. The environment must be configured correctly, including the required workspace and supported collection mechanism.
For example, an organization may enable Plan 2 but still fail to receive the expected benefit because:
- No Log Analytics workspace is configured.
- The machine is not associated with the required workspace.
- Azure Monitor Agent is not configured.
- The required data collection rule is missing.
- The collected data is not eligible for the benefit.
When troubleshooting, distinguish between:
- The Defender plan being enabled.
- The machine being onboarded.
- The required workspace existing.
- The correct agent or collection method being configured.
- The data actually being collected.
Monitoring and Validating Agentless Scanning
After enabling agentless scanning, validate the configuration rather than assuming it is working.
Check the following:
1. Plan Status
Confirm that Defender for Servers Plan 2 is enabled for the correct subscription or connected environment.
2. Machine Coverage
Verify that the target VM appears in Defender for Cloud and is not excluded by:
- Resource-level settings
- Azure Policy
- Subscription configuration
- Unsupported configuration
- Scope filters
3. Operating-System Support
Confirm that the operating system and machine type are supported by the selected scanning method.
4. Scanning Configuration
Verify that agentless scanning is enabled where required.
5. Data Freshness
Check when vulnerability information was last updated. Old results may indicate:
- Scanning has not completed.
- The machine is not reachable through the required mechanism.
- The machine is no longer active.
- The assessment process is delayed.
- The machine is not properly onboarded.
6. Agent Health
If agent-based scanning is also expected, verify the health and onboarding status of the Defender for Endpoint sensor.
7. Findings
Review:
- Vulnerability severity
- Affected software
- Affected machines
- Recommended remediation
- Exposure information
- Whether the finding is current or stale
Common Troubleshooting Scenarios
Scenario 1: The VM Does Not Appear as Protected
Possible causes include:
- Defender for Servers is disabled.
- The wrong subscription was selected.
- The VM is excluded at the resource level.
- The machine is unsupported.
- The connected AWS or GCP environment is not configured correctly.
- Azure Arc onboarding has not completed.
Scenario 2: No Vulnerability Results Are Available
Possible causes include:
- Agentless scanning is not enabled.
- The machine is not supported.
- The machine is not in scope.
- The scan has not completed.
- Required permissions are missing.
- Required connectivity is unavailable.
- A third-party scanner is the configured source of results.
- The Defender for Endpoint sensor is missing or unhealthy.
- The machine is not properly onboarded.
Scenario 3: Agent-Based Results Are Missing
Check:
- Defender for Endpoint onboarding
- Sensor health
- Supported operating system
- Network connectivity
- Licensing and plan configuration
- Whether the machine is reporting to the expected Defender environment
Scenario 4: Agentless Scanning Is Expected but Unavailable
Check:
- Whether Plan 2 is enabled
- Whether the machine is a supported cloud or connected-server scenario
- Whether the machine is connected through the required integration
- Whether resource-level settings override subscription-level settings
- Whether Defender CSPM or another scanner is providing the capability
Scenario 5: File Integrity Monitoring or Data-Ingestion Benefits Are Missing
Check:
- Plan 2 status
- Log Analytics workspace configuration
- Azure Monitor Agent
- Data collection rules
- Machine association with the workspace
- Eligibility of the collected data
Best Practices
Enable at the Correct Scope
Enable Defender for Servers at the subscription level where practical. Use resource-level exceptions only when there is a documented business or technical reason.
Use Azure Arc for Non-Azure Servers
Use Azure Arc to obtain a consistent management and security experience for on-premises, AWS, and GCP servers.
Avoid Unnecessary Scanner Duplication
If a third-party scanner is already deployed, decide whether it will remain authoritative or whether Defender Vulnerability Management will be used as the primary source.
Monitor Coverage Continuously
Do not assume that a one-time successful onboarding means the machine remains protected. Monitor:
- Last-seen time
- Agent health
- Scan freshness
- Coverage status
- Security recommendations
- EDR alerts
Separate Detection From Assessment
Use vulnerability assessment to identify weaknesses and EDR to detect and respond to active threats. Both capabilities may be required.
Use Least Privilege
Give administrators only the permissions required to configure plans, deploy extensions, view findings, or remediate issues.
Prioritize Findings
Prioritize vulnerabilities using more than CVSS severity alone. Consider:
- Internet exposure
- Exploit availability
- Business criticality
- Attack paths
- Privileged access
- Sensitive data
- Compensating controls
- Whether exploitation has been observed
Validate Prerequisites
Before enabling a feature, verify:
- Plan
- Scope
- Supported operating system
- Cloud environment
- Arc status
- Required permissions
- Workspace requirements
- Network connectivity
- Existing scanner integrations
Exam-Focused Summary
Remember these key points:
- Agentless scanning is primarily associated with Defender for Servers Plan 2.
- Agent-based vulnerability scanning through Defender for Endpoint is available with Plan 1 and Plan 2.
- Agentless scanning does not require the same in-guest vulnerability-scanning agent.
- Agentless scanning does not replace EDR.
- Defender for Endpoint provides endpoint detection and response.
- Defender Vulnerability Management provides vulnerability and software assessment.
- Azure Arc is recommended for full Defender for Servers functionality on non-Azure and on-premises servers.
- AWS and GCP environments are connected through Defender for Cloud, generally with Arc-enabled machines.
- When both scanning methods are available, agent-based results may take precedence because they are generally fresher.
- Third-party scanners such as Qualys or Rapid7 may provide the primary vulnerability results when configured.
- Scanning identifies vulnerabilities; it does not automatically patch every machine.
- Plan 2 features may require Log Analytics, Azure Monitor Agent, or other prerequisites.
- Security Reader can view findings, while configuration and deployment operations require additional permissions.
Practice Exam Questions
Question 1
An organization wants to assess supported Azure virtual machines for software vulnerabilities without installing a vulnerability-scanning agent inside the guest operating system. Which Defender for Servers plan should the organization select?
A. Defender for Servers Plan 1
B. Defender for Servers Plan 2
C. Microsoft Defender for Storage
D. Microsoft Defender for APIs
Answer: B
Explanation: Agentless scanning for supported machines is a Defender for Servers Plan 2 capability. Plan 1 provides core server protection and agent-based vulnerability assessment through Defender for Endpoint, but it does not provide the full Plan 2 agentless-scanning capability.
Question 2
A company uses a third-party endpoint detection and response product on its Azure virtual machines. The company wants vulnerability visibility without deploying the Microsoft Defender for Endpoint sensor to every machine. Which approach is most appropriate for supported machines?
A. Enable Defender for Servers Plan 2 and use agentless scanning
B. Enable only Defender for Servers Plan 1
C. Disable all endpoint protection products
D. Install Azure Bastion on every virtual machine
Answer: A
Explanation: Defender for Servers Plan 2 agentless scanning can provide vulnerability and posture visibility for supported machines without relying exclusively on the Microsoft Defender for Endpoint sensor. It does not replace the organization’s EDR solution.
Question 3
Where should an administrator normally begin when enabling Defender for Servers for an Azure subscription?
A. Azure Storage account networking settings
B. Microsoft Sentinel data connectors
C. Microsoft Defender for Cloud Environment settings
D. Microsoft Entra authentication methods
Answer: C
Explanation: Defender for Servers is enabled through Microsoft Defender for Cloud. The administrator selects Environment settings, chooses the subscription or connected environment, opens Defender plans, enables Servers, selects Plan 1 or Plan 2, and saves the configuration.
Question 4
An organization has on-premises Windows and Linux servers and wants the broadest supported Defender for Servers functionality, including cloud-based security management. What should the organization generally use to connect the servers?
A. Azure Bastion
B. Azure Arc-enabled servers
C. Azure Application Gateway
D. Microsoft Entra Domain Services
Answer: B
Explanation: Azure Arc is the recommended connection mechanism for on-premises and other non-Azure servers when the organization wants the broader Defender for Servers experience. Direct Defender for Endpoint onboarding can provide endpoint functionality, but it does not necessarily provide the full Defender for Servers Plan 2 experience.
Question 5
Which statement correctly describes the relationship between agent-based and agentless vulnerability scanning?
A. Agentless scanning always provides more current endpoint data than agent-based scanning
B. Agent-based scanning requires the Defender for Endpoint sensor, while agentless scanning does not require the same in-guest vulnerability-scanning agent
C. Agent-based scanning is available only with Defender for Servers Plan 2
D. Agentless scanning provides full endpoint detection and response
Answer: B
Explanation: Agent-based scanning uses the Defender for Endpoint sensor. Agentless scanning uses supported cloud-level assessment capabilities and does not require the same in-guest vulnerability-scanning agent. Agentless scanning does not provide full EDR functionality.
Question 6
A security administrator enables Defender for Servers Plan 2 but cannot find File Integrity Monitoring data for a VM. Which prerequisite should the administrator check first?
A. Whether the VM has an Azure public IP address
B. Whether Azure Bastion is deployed
C. Whether the VM is assigned a Microsoft Entra user
D. Whether the required Log Analytics workspace and data-collection configuration are present
Answer: D
Explanation: File Integrity Monitoring and certain Plan 2 data-ingestion capabilities require appropriate Log Analytics and data-collection configuration. The administrator should verify the workspace, Azure Monitor Agent, data collection rules, and machine association.
Question 7
An organization has configured a supported third-party vulnerability scanner through a bring-your-own-license integration. What should administrators expect?
A. The third-party scanner may provide the primary vulnerability results
B. Defender for Servers automatically disables all third-party scanner results
C. Agentless scanning is available only with Plan 1
D. EDR alerts are converted into storage-account recommendations
Answer: A
Explanation: Supported third-party scanners, such as Qualys or Rapid7, may provide the primary vulnerability results when configured. Agentless scanning may still help cover supported machines without the partner agent or without complete partner findings.
Question 8
A security analyst needs to view vulnerability findings and recommendations but should not be able to change Defender for Servers configuration. Which role is most appropriate?
A. Owner
B. Contributor
C. Security Reader
D. Global Administrator
Answer: C
Explanation: Security Reader is intended for viewing security information, including recommendations and findings. Configuration and deployment operations generally require more permissions, such as Owner or another appropriately scoped administrative role.
Question 9
Defender for Cloud reports that a VM has an EDR configuration issue. Which condition could produce this type of recommendation?
A. The VM has no attached data disk
B. Antivirus protection is disabled or security signatures are outdated
C. The VM is located in a virtual network with a subnet
D. The VM has an Azure resource tag
Answer: B
Explanation: EDR and endpoint-protection configuration assessments can identify conditions such as disabled or partially configured antivirus protection, outdated signatures, or scans that have not run recently. These recommendations help identify machines that may have endpoint protection installed but are not adequately configured.
Question 10
A VM has both agent-based and agentless vulnerability results available. Which result is generally given precedence when both methods provide data?
A. Agent-based results, because they generally provide fresher endpoint information
B. Agentless results, because they always replace agent-based results
C. Results from Azure Bastion
D. Results from Microsoft Sentinel only
Answer: A
Explanation: When both methods are available, agent-based results are generally shown because they are expected to provide fresher endpoint information. Agentless scanning remains useful for expanding coverage and assessing supported machines that do not have a healthy or compatible agent.
Go to the SC-500 Exam Prep Hub main page
