You manage 350 servers (Azure VMs and Azure Arc–connected on‑premises). All are already onboarded to Microsoft Defender for Endpoint. Due to strict change control, you must avoid deploying additional VM extensions while getting vulnerability findings surfaced in Microsoft Defender for Cloud. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: In Defender for Cloud, set the vulnerability assessment provider to Microsoft Defender for Endpoint (Defender Vulnerability Management) so the existing MDE agent collects findings; do not deploy the Qualys extension..
Why this is the answer
The correct answer is to set the vulnerability assessment provider to Microsoft Defender for Endpoint (Defender Vulnerability Management) in Defender for Cloud. This leverages the existing Microsoft Defender for Endpoint agent already deployed on all servers (Azure VMs and Azure Arc-connected) to collect vulnerability findings without requiring any additional VM extensions, adhering to the strict change control requirement. Deploying the Qualys agent extension would violate the "avoid deploying additional VM extensions" constraint. Azure Update Manager focuses on missing updates, not comprehensive vulnerability assessment findings. The Guest Configuration initiative does not report vulnerabilities without agents; it primarily audits and enforces configuration settings. Installing a Windows Admin Center extension is not the native or recommended method for integrating vulnerability data into Defender for Cloud from a large, hybrid server estate.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed