Your Windows Server 2022 Azure Virtual Desktop session hosts appear in Microsoft Defender for Cloud with the recommendation "A vulnerability assessment solution should be enabled on your virtual machines." You want to clear this recommendation at scale with minimal manual steps and without replacing the VMs. Which two actions would satisfy the recommendation? Each correct answer presents a complete solution.
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Microsoft Defender for Servers Plan 2 on the subscriptions and set the vulnerability assessment provider to Microsoft Defender for Endpoint with auto-provisioning., Deploy the Qualys vulnerability assessment extension to the session hosts using a policy assignment..
Why this is the answer
The recommendation "A vulnerability assessment solution should be enabled on your virtual machines" requires a vulnerability scanner. Enabling Microsoft Defender for Servers Plan 2 and setting the vulnerability assessment provider to Microsoft Defender for Endpoint with auto-provisioning integrates Defender for Endpoint's vulnerability management capabilities, which satisfies the recommendation at scale. Deploying the Qualys vulnerability assessment extension via a policy assignment also directly addresses the recommendation by installing a recognized vulnerability assessment solution across your session hosts. Manually installing Windows updates and configuring Windows Update for Business is important for security but does not provide a vulnerability assessment solution. Enabling Azure Disk Encryption protects data at rest but is not a vulnerability assessment. Enabling Azure AD sign-in logs collection is for monitoring authentication, not for assessing VM vulnerabilities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed