You need endpoint detection and response for your Windows and Linux servers with alerting in Microsoft Defender for Cloud. You do not require just‑in‑time VM access, file integrity monitoring, adaptive controls, or integrated vulnerability assessment. Which plan should you enable to meet requirements at the lowest cost?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Microsoft Defender for Servers Plan 1..
Why this is the answer
Microsoft Defender for Servers Plan 1 provides Endpoint Detection and Response (EDR) capabilities for Windows and Linux servers, including alerting in Microsoft Defender for Cloud, at a lower cost than Plan 2. Plan 2 includes additional features like just-in-time VM access, file integrity monitoring, adaptive application controls, and integrated vulnerability assessment, which the scenario explicitly states are not required. The free tier of Microsoft Defender for Cloud offers basic security posture management but lacks EDR. Installing only the Azure Monitor Agent and collecting Security baseline data would provide monitoring but not the advanced EDR and alerting features of Defender for Cloud. Microsoft Sentinel is a Security Information and Event Management (SIEM) solution that can ingest data from Defender for Cloud, but it doesn't provide the EDR functionality itself and would be an additional cost.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed