QuestionQ131

Design security solutions for infrastructure

You need to recommend a solution that resolves the virtual machine issue.

What should you include in the recommendation?

  • A Enable the Qualys scanner in Defender for Cloud.
  • B Onboard the virtual machines to Microsoft Defender for Endpoint.
  • C Create a device compliance policy in Microsoft Endpoint Manager.
  • D Onboard the virtual machines to Azure Arc.
Explanation

The virtual machine issue is the Defender for Cloud recommendation "Machines should have a vulnerability assessment solution," and the environment uses Qualys as its standard scanner. Because the VMs already surface in Defender for Cloud (the recommendation is generated against them), they are already connected and do not need Azure Arc onboarding; you simply enable the integrated Qualys vulnerability scanner in Defender for Cloud to remediate the recommendation and bring the machines into compliance. Azure Arc (D) is only needed for non-Azure/on-premises servers that are not yet visible in Defender for Cloud. (The integrated Qualys scanner has since been replaced by Microsoft Defender Vulnerability Management, but the concept of enabling the built-in VA solution is unchanged.)

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!