Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

A company has enabled Microsoft Defender for Cloud on all subscriptions. The security team wants to ensure that all virtual machines have vulnerability assessment solutions installed. What should they configure?

⚠ Common exam trap

Many candidates confuse 'auditing' (Option C) with 'remediation' — an Azure Policy audit only checks compliance, but the question asks to ensure the solution is installed, which requires enabling the built-in Defender for Cloud vulnerability assessment solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Vulnerability Assessment solution in Defender for Cloud and set it to 'On'

Microsoft Defender for Cloud provides a built-in Vulnerability Assessment solution that can be enabled at the subscription level. When set to 'On', it automatically deploys the Qualys or Microsoft threat and vulnerability management agent to all supported Azure VMs, ensuring continuous vulnerability scanning without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Azure Update Management for all VMs

    Why it's wrong here

    Azure Update Management is an Azure Automation solution that schedules and applies OS updates to keep VMs patched. However, it does not perform vulnerability scanning or report on Common Vulnerabilities and Exposures (CVEs). Since the requirement is to enable vulnerability detection rather than patch enforcement, this option does not satisfy the need for a vulnerability assessment solution.

  • ✓

    Enable the Vulnerability Assessment solution in Defender for Cloud and set it to 'On'

    Why this is correct

    The Vulnerability Assessment solution in Microsoft Defender for Cloud, when set to 'On', auto-provisions a built-in scanner (Qualys or Microsoft Defender Vulnerability Management) to supported machines. This continuously scans for known CVEs, misconfigurations, and security weaknesses, and surfaces findings in the Defender for Cloud recommendations and Secure Score. It is the native, integrated way to meet the requirement of vulnerability assessment across all VMs.

  • ✗

    Create an Azure Policy to audit VMs without vulnerability assessment

    Why it's wrong here

    Creating an Azure Policy with an audit effect evaluates each VM's compliance and reports that some machines lack a vulnerability assessment extension. But an audit policy is read-only: it never installs, enables, or configures the vulnerability assessment solution on non-compliant VMs. To actually deploy the solution, you would need a DeployIfNotExists policy or a manual remediation task, so this option only identifies the problem rather than solving it.

  • ✗

    Use Azure Automation to run a script that installs a vulnerability scanner

    Why it's wrong here

    Using Azure Automation to run a custom script that installs a vulnerability scanner relies on ad-hoc deployment and does not integrate with Defender for Cloud's vulnerability management. A script may install a scanner but without the built-in provider's centralized reporting, remediation recommendations, and secure score calculation. Additionally, it requires managing credentials, error handling, and ongoing maintenance, whereas Defender for Cloud offers a fully managed, preintegrated solution.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.