AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You have an Azure subscription that contains 100 virtual machines. You need to monitor the virtual machines for security vulnerabilities and receive recommendations. What should you use?
⚠ Common exam trap
It's easy for candidates to confuse Azure Monitor (which monitors performance and availability) with security monitoring, or assume Microsoft Sentinel (a SIEM) is the correct tool for vulnerability scanning, when in fact Defender for Cloud is the dedicated service for security posture management and vulnerability assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud
Microsoft Defender for Cloud (formerly Azure Security Center) provides unified security management and advanced threat protection across hybrid cloud workloads. It continuously assesses your virtual machines for security vulnerabilities, misconfigurations, and missing updates, then delivers actionable recommendations and a secure score to prioritize remediation. This directly matches the requirement to monitor VMs for vulnerabilities and receive recommendations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Cloud
Why this is correct
Microsoft Defender for Cloud is the correct choice because it natively provides continuous vulnerability assessment for Azure VMs via its built-in Qualys scanner or the integrated Microsoft Defender for Servers plan. It identifies missing patches, misconfigurations, and potential security issues, then offers actionable remediation recommendations and hardening guidance. Beyond vulnerability scanning, it also delivers compliance assessments. Its recommendations are directly generated from resource configuration analysis and threat signals, making it the only listed service designed for cloud security posture management and vulnerability detection.
- ✗
Azure Monitor
Why it's wrong here
Azure Monitor is incorrect because it is a platform for collecting, analyzing, and acting on telemetry from Azure resources, such as performance metrics, logs, and diagnostic data. While it can ingest security-related event logs and create alerts, it does not perform vulnerability scanning, evaluate patch levels, or compare VM configurations against security baselines. Azure Monitor answers 'what is happening' operationally, not 'where am I vulnerable' from a security hardening perspective. Vulnerability assessment requires specialized scanning engines that Azure Monitor does not provide.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is incorrect because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automated Response) solution. Its role is to aggregate security logs from across the environment, detect threats through analytics rules, and enable incident investigation and response. Sentinel consumes vulnerability data from other sources like Microsoft Defender for Cloud, but it does not actively scan VMs for vulnerabilities or generate hardening recommendations. It provides detection and response to threats, not vulnerability assessment or configuration posture analysis.
- ✗
Microsoft Defender XDR
Why it's wrong here
Microsoft Defender XDR is incorrect for this scenario because it is an enterprise detection and response suite covering endpoints, email, identities, and applications, primarily for Microsoft 365 workloads. Although it includes Microsoft Defender for Endpoint, which can flag endpoint threats and some device vulnerabilities, it is not the Azure-native tool that assesses cloud VMs across your entire subscription for security misconfigurations and missing patches. Defender XDR focuses on correlating incidents across domains after compromise attempts, not on proactively auditing Azure resource configurations. For subscription-wide VM vulnerability assessment in Azure, Defender for Cloud is the appropriate service.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.