You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.
Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.
You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.
What should you use?
Suggested Answer: E
Explanation:
Vulnerability assessment on virtual machines is the feature that scans machines for known security flaws and misconfigurations. Attack path analysis correlates risk paths after findings exist; it is not the scanner itself. Cloud Security Explorer is an investigation query experience, and MCSB is a security benchmark framework. JIT VM access limits management exposure, not vulnerability discovery. The VM vulnerability assessment capability satisfies the automated scanning requirement. The compute domain tests whether protection is applied before deployment, during runtime, or through posture assessment. The selected answer matches the phase described in the requirement. Detection-only tools are not acceptable when the requirement says prevent, and local installation methods are inferior when Defender for Cloud, Azure Policy, or Azure Machine Configuration can enforce the control centrally. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Defender for Servers settings; Microsoft Learn > vulnerability assessment for machines.
==============================================================