SC-100 - Design Security Solutions for Infrastructure (27% of the exam) - Section 3.1

Design solutions for security posture management in hybrid and multicloud environments.

Use Microsoft Defender for Cloud and the Microsoft cloud security benchmark (MCSB) to assess and harden hybrid and multicloud workloads, extending coverage to on-premises servers and non-Azure clouds via Azure Arc. Combine Microsoft Secure Score, Microsoft Defender External Attack Surface Management (Defender EASM), and Microsoft Security Exposure Management to reduce attack surface.

Microsoft Defender for CloudMicrosoft cloud security benchmark (MCSB)Microsoft Secure ScoreAzure ArcMicrosoft Defender External Attack Surface Management (Defender EASM)Microsoft Security Exposure Managementcloud workload protection

Practice question for this objective

Free sampleDesign Security Solutions for Infrastructurehard

A healthcare group runs hundreds of Windows and Linux servers in its own datacentre and in a third-party cloud, and the architect must design posture management so these non-Azure servers appear in Microsoft Defender for Cloud inventory, are scored by Secure Score, and can have a workload protection plan enabled on them as if they were Azure resources, while keeping a single consistent benchmark baseline across the whole hybrid estate. Which design sequence best satisfies this hybrid posture requirement?

  • AOnboard each server to Azure Arc so it is projected as an Arc-enabled machine, then in Microsoft Defender for Cloud assess the estate against the Microsoft cloud security benchmark and enable the relevant workload protection plan on the Arc-enabled servers. Correct
  • BEstablish ExpressRoute to the datacentre and the third-party cloud so the servers gain private reachability, after which Microsoft Defender for Cloud discovers them over the network and scores them against the Microsoft cloud security benchmark.
  • CConfigure Azure Lighthouse delegated resource management across the datacentre and third-party cloud so Microsoft Defender for Cloud manages the servers cross-tenant and scores them against the Microsoft cloud security benchmark as Azure resources.
  • DStream each server's configuration and event logs into Microsoft Sentinel and build analytics rules that compare the settings to the Microsoft cloud security benchmark, so the workspace becomes the hybrid posture and plan-enablement console.
Use Azure Arc to project non-Azure servers into Azure so Defender for Cloud can inventory, benchmark-score, and enable workload protection on them consistently. Defender for Cloud governs only resources represented in Azure Resource Manager. Azure Arc onboards datacentre and other-cloud servers as Arc-enabled machines, giving them an ARM identity so the same Microsoft cloud security benchmark scoring and workload protection plans apply across the hybrid estate, which connectivity, cross-tenant delegation, or a SIEM cannot achieve.

Why A is correct: Azure Arc projects on-premises and other-cloud servers into Azure Resource Manager as Arc-enabled machines, which is precisely what lets Defender for Cloud inventory them, apply the benchmark, score them, and enable a plan such as Defender for Servers consistently.

Why B is wrong: Private connectivity is tempting as a hybrid enabler, but network reachability alone does not register the servers as Azure resources, so Defender for Cloud has nothing to inventory, score, or enable a plan against.

Why C is wrong: Lighthouse is appealing because it crosses management boundaries, but it delegates management of existing Azure resources across tenants and cannot project non-Azure physical or virtual servers into Azure for Defender for Cloud to govern.

Why D is wrong: Sentinel is tempting because it ingests logs from anywhere, but it is a SIEM for detection and investigation and neither registers servers as Azure resources nor enables per-resource workload protection plans against a benchmark.

See more SC-100 practice questions, answers explained.

Exam traps in Design Security Solutions for Infrastructure

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-100 bank for this domain.

  • Stream every cloud's audit and configuration logs into Microsoft Sentinel and build analytics rules that flag misconfigurations, so the security operations workspace becomes the single multicloud posture assessment console.

    Why it is wrong: Sentinel is tempting because it ingests signals from every cloud, but it is a SIEM for detection and investigation and does not continuously assess resource configuration against a control baseline the way a posture management product does.

  • Configure Azure Lighthouse delegated resource management for the datacentre and third-party cloud so Microsoft Defender for Cloud can reach across tenants and manage the servers as Azure resources.

    Why it is wrong: Lighthouse is tempting because it crosses management boundaries, but it delegates management of existing Azure resources across tenants and does not project non-Azure physical or virtual servers into Azure for Defender for Cloud to govern.

  • Microsoft Defender for Cloud agentless scanning to inventory exposed resources, paired with Microsoft Sentinel analytics rules that correlate logs so chained weaknesses to the bank's critical assets are ranked into a single prioritised attack-path view.

    Why it is wrong: Agentless scanning and Sentinel are tempting because both touch exposure, but agentless scanning only sees already-connected subscriptions and Sentinel is a SIEM that correlates telemetry rather than discovering forgotten external assets or modelling attack paths.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.