Courseiva
Manage identity and access →mediumMultiple Select

AZ-500 Manage identity and access Practice Question

A company uses Defender for Servers Plan 2. Which two capabilities are included compared with a basic posture-only configuration?

⚠ Common exam trap

Many exam-takers confuse basic posture-only features (like vulnerability assessment and secure score) with advanced capabilities like FIM and EDR, assuming all Defender for Servers tiers include endpoint detection, when only Plan 2 adds these specific protections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

File integrity monitoring or equivalent advanced server protection capabilities

Defender for Servers Plan 2 includes advanced server protection capabilities such as file integrity monitoring (FIM), which tracks changes to critical system files and registry keys, and endpoint detection and response (EDR) integration through Microsoft Defender for Endpoint. These capabilities go beyond the basic posture-only configuration, which only provides vulnerability assessment and security recommendations without real-time threat detection or file change monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Cost Management budget alerts

    Why it's wrong here

    Azure Cost Management budget alerts are a financial governance tool that monitors subscription-level or resource-group-level spend against defined thresholds and sends notifications when spending approaches or exceeds a budget. They are delivered through the Cost Management + Billing portal and are in no way a component of Microsoft Defender for Servers Plan 2. Even though Defender for Servers Plan 2 also carries data-transfer allowances for each server, budget alerts do not provide any security or workload-protection capability, so this option does not answer the question.

  • ✓

    File integrity monitoring or equivalent advanced server protection capabilities

    Why this is correct

    File integrity monitoring (FIM) is included in Defender for Servers Plan 2 and watches critical system files, registry entries, and configuration settings for unauthorized changes by comparing them to a baseline. When a change is detected, the response is enriched with details about the change and the user or process responsible so security teams can determine if it indicates compromise. This advanced server protection capability satisfies the stated requirement, making the option correct.

  • ✓

    Endpoint detection and response integration through Microsoft Defender for Endpoint

    Why this is correct

    Endpoint detection and response (EDR) integration through Microsoft Defender for Endpoint is the foundation of Defender for Servers Plan 2, connecting the server workload to attack signal, automated investigation, and response actions. Enrolling a server in Plan 2 provisions the Defender for Endpoint sensor, which provides kernel-level behavioral telemetry, continuous machine learning detections, and rich incident details. This is one of the two requested capabilities because the plan's server protection experience is built around that EDR integration.

  • ✗

    Microsoft 365 message trace

    Why it's wrong here

    Microsoft 365 message trace is a mail-flow diagnostic tool within Exchange Online that lets administrators track messages as they traverse the transport pipeline and verify how spam filters or mail-flow rules handled them. It belongs to Microsoft 365 email protection, not OS-level server hardening, and Defender for Servers Plan 2 does not consume or expose message trace data. Choosing this option would be incorrect because it confuses email routing with server workload protection.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.