SC-100 - Design Security Solutions for Infrastructure - Section 3.2

Specify requirements for securing server and client endpoints across platforms, mobile, IoT, and operational technology.

Specify security requirements for server and client endpoints by applying endpoint baselines, Windows Local Administrator Password Solution (Windows LAPS) for local account credential rotation, and mobile device hardening policies. Extend requirements to operational technology (OT) and industrial control systems (ICS), IoT, and embedded systems using Microsoft Defender for IoT.

server and client endpoint baselinesMicrosoft Defender for IoToperational technology (OT) and industrial control systems (ICS)Windows Local Administrator Password Solution (Windows LAPS)mobile device hardeningembedded systems

Practice question for this objective

Free sampleDesign Security Solutions for Infrastructuremedium

A media company's estate spans Windows and Linux server virtual machines running across Azure and Amazon Web Services, alongside a client fleet of Windows, macOS, and Linux laptops used by staff. Leadership wants threat detection and vulnerability assessment for the server workloads delivered through the same multicloud plane that feeds posture scoring, and a single cross-platform endpoint detection and response capability with a unified incident view for the client laptops. The architect must protect both endpoint classes with the right Microsoft capability for each. Which two design choices together meet these requirements? Select TWO.

  • AEnable Microsoft Defender for Servers from Microsoft Defender for Cloud on the Windows and Linux virtual machines, so the multicloud plane delivers threat detection and vulnerability assessment on those server workloads and feeds their posture into Secure Score. Correct
  • BOnboard the Windows, macOS, and Linux client laptops to Microsoft Defender for Endpoint, so the cross-platform endpoint sensor delivers consistent behavioural detection, endpoint detection and response, and a unified incident view across all three operating systems. Correct
  • CDeploy Microsoft Defender for IoT network sensors across the subnets that host the server virtual machines and the client laptops, so passive traffic monitoring discovers and baselines those endpoints and raises anomaly alerts for both classes from mirrored traffic.
  • DConfigure Microsoft Defender for Office 365 to extend its protection over the server virtual machines and the client laptops, so its detonation and threat detection cover both endpoint classes alongside the organisation's email and collaboration content.
Server workloads use Defender for Servers through Defender for Cloud while cross-platform client endpoints use Defender for Endpoint, not Defender for IoT or Defender for Office 365. The two endpoint classes need different Microsoft capabilities. Server virtual machines across Azure and Amazon Web Services belong on Defender for Servers, the Defender for Cloud workload protection plan that delivers threat detection and vulnerability assessment and feeds the multicloud Secure Score. The Windows, macOS, and Linux client laptops belong on Defender for Endpoint, the cross-platform endpoint detection and response sensor that gives one consistent behavioural detection and a unified incident view across all three operating systems. Defender for IoT covers agentless operational technology and IoT devices, not managed servers or clients, and Defender for Office 365 protects email and collaboration content, so neither fits either endpoint class here.

Why A is correct: Defender for Servers is the Defender for Cloud workload protection plan purpose-built for server virtual machines across Azure and Amazon Web Services, delivering the threat detection and vulnerability assessment for the server tier and feeding their posture into the same multicloud Secure Score the requirement names.

Why B is correct: Defender for Endpoint provides one cross-platform endpoint detection and response sensor for Windows, macOS, and Linux clients with a single incident view, which is precisely the unified client-endpoint capability the requirement asks for rather than a separate product per operating system.

Why C is wrong: Defender for IoT passive sensors are the right tool for agentless operational technology and unmanaged IoT devices, and the mention of discovery sounds broad, but they do not protect managed servers or client laptops, which are full endpoints that take an agent rather than agentless network monitoring.

Why D is wrong: Defender for Office 365 secures email and collaboration content and is tempting because it shares the Defender brand and does threat detection, but it protects messaging workloads and provides no endpoint or server workload protection, so it fits neither endpoint class in this requirement.

See more SC-100 practice questions, answers explained.

More in this domain

Back to all Design Security Solutions for Infrastructure objectives, or the SC-100 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.