You have 100 virtual machines with Azure Defender enabled and plan to deploy the vulnerability scanner extension to each VM using an Azure Resource Manager template. Which two values should you include in the deployment code? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: the workspace ID, the system-assigned managed identity.
Why this is the answer
To deploy the vulnerability scanner extension using an ARM template, you need to specify the workspaceId to link the extension's data to a Log Analytics workspace for centralized monitoring and analysis. The system-assigned managed identity is also required because it grants the extension the necessary permissions to interact with other Azure services securely without needing to manage credentials manually. The user-assigned managed identity is incorrect because, while it's a valid managed identity type, the vulnerability scanner extension typically uses a system-assigned identity for its operations. The Azure AD ID, Key Vault managed storage account key, and primary shared key are not directly used for deploying or configuring the vulnerability scanner extension itself; these are related to other Azure security or storage configurations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed