Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Microsoft Certified: Cloud and AI Security Engineer Associate SC-500 Question # 20 Topic 3 Discussion

Microsoft Certified: Cloud and AI Security Engineer Associate SC-500 Question # 20 Topic 3 Discussion

SC-500 Exam Topic 3 Question 20 Discussion:
Question #: 20
Topic #: 3

You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.

Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.

Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.

You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.

You need to ensure that agentless scanning can analyze the virtual machines.

What should you do?


A.

Assign each virtual machine managed identity the Key Vault Reader role for KV1.


B.

Assign the scanning service the Key Vault Secrets User role for KV1.


C.

Enable Microsoft Defender for Key Vault for Sub1.


D.

Enable just-in-time (JIT) VM access for the affected virtual machines.


E.

Assign the scanning service the Key Vault Crypto Service Encryption User role for KV1


Get Premium SC-500 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.