Given the requirements that internet-facing virtual machines must be protected by network security groups and all virtual machines must have disk encryption enabled, what is the minimum number of Microsoft Defender for Cloud security policies required?
Choose an answer
Tap an option to check your answer.
Correct answer: 2.
Why this is the answer
The correct answer is 2. You need two separate Microsoft Defender for Cloud security policies to meet the given requirements. 1. Network Security Group (NSG) Policy: One policy is required to enforce the use of Network Security Groups for internet-facing virtual machines. This policy would specifically target VMs exposed to the internet and ensure NSGs are associated with them to control inbound/outbound traffic. 2. Disk Encryption Policy: A second, distinct policy is needed to mandate disk encryption for all virtual machines. This policy would apply broadly across all VMs in the scope to ensure their disks are encrypted, regardless of their internet exposure. You cannot combine these into a single policy because they address different security controls and have different scopes (internet-facing vs. all VMs). While Defender for Cloud offers many built-in policies, these two distinct requirements necessitate separate policy assignments for proper enforcement and auditing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed