Exam SC-200 Topic 2 Question 83 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 83
Topic #: 2
You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud.
You have an Azure DevOps organization named AzDO1.
You need to integrate Sub! and AzDO1. The solution must meet the following requirements:
* Detect secrets exposed in pipelines by using Defender for Cloud.
* Minimize administrative effort.

Suggested Answer:


Explanation:

To integrate Microsoft Defender for Cloud with Azure DevOps (AzDO1) for detecting secrets exposed in pipelines, you must connect the two platforms using Microsoft's built-in integration flow that enables Defender for Cloud to scan repositories and pipelines for vulnerabilities and sensitive data exposure.
Here's the correct configuration process:
In the Defender for Cloud portal, you first need to add an environment that represents your Azure DevOps organization.
This step connects Defender for Cloud to the DevOps service, allowing it to monitor repositories, build pipelines, and artifacts.
* Navigate to Defender for Cloud # Environment settings # Add environment # Azure DevOps.
* You'll then authenticate your Azure DevOps organization (AzDO1) to allow Defender for Cloud to scan your pipelines.
This setup enables Defender for DevOps, a capability within Defender for Cloud, to detect exposed secrets, insecure dependencies, and misconfigurations directly from pipeline activities.
Next, within Azure DevOps (AzDO1), install the Microsoft Defender for DevOps Security Scanner extension from the Azure DevOps Marketplace.
This extension integrates the Defender for Cloud scanning engine into the Azure DevOps pipeline process and enables automatic scanning for:
* Hardcoded secrets in YAML pipelines,
* Vulnerability findings in open-source dependencies, and
* Infrastructure-as-code misconfigurations (for example, ARM, Terraform).
Once installed, the extension automatically works with Defender for Cloud, and any detected secret exposure or security issue is surfaced in Defender for Cloud's "DevOps Security" dashboard.
* Configure workflow automation: Applies to automated incident responses, not DevOps integration.
* Enable a plan: Refers to enabling Defender plans for specific Azure resource types, not connecting DevOps.
* Configure OAuth / Configure security policies: Required for custom integration scenarios, but not for standard Defender-DevOps onboarding.
# Final Correct answer:
* In Defender for Cloud: Add an environment
* In AzDO1: Install an extension

by Lou at Sep 17, 2026, 05:13 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10