Plant virtual machines cannot take another agent, yet auditors require machine scanning for secrets and vulnerabilities. What should the Azure security engineer enable?
Select an answer to reveal the explanation.
Short Explanation
No room for another agent on the plant boxes? Plan 2 agentless scanning snapshots the disks—AMA is not the ticket for that feature. That’s the path when the guest can’t take more weight.
Full Explanation
Agentless machine scanning in Microsoft Defender for Servers uses snapshot-based analysis and is available with Plan 2; Azure Monitor Agent is not required for that scan feature per official guidance that agentless plus Defender for Endpoint replaced older agent dependencies for most Servers features. Plan 1 is not the usual path for the full agentless set, and requiring only a third-party guest agent misses the agentless Servers skill. Do not confuse CSPM posture scanning with this Servers threat-protection capability.