AZ-500 Manage identity and access Practice Question
A company uses Microsoft Defender for Cloud. They have assigned a custom regulatory compliance initiative that includes policies to enforce encryption on storage accounts and SQL databases. They want to automatically remediate any non-compliant resources that are discovered, without manual intervention. Which feature should they configure?
⚠ Common exam trap
A common mix-up: candidates confuse 'Auto provisioning' (which installs agents for data collection) with automatic remediation of compliance policies, or they assume 'Workflow automation' directly fixes non-compliance when it only triggers a notification or custom action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Remediation' for each policy assignment in the custom initiative
The 'Remediation' setting on a policy assignment in Azure Policy (used by Defender for Cloud custom initiatives) creates a managed identity and a remediation task that automatically applies the required encryption configuration to non-compliant resources. This ensures that when a storage account or SQL database is found without encryption, the policy engine triggers a deployment to enforce encryption without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Auto provisioning' for the relevant extensions
Why it's wrong here
Auto provisioning in Microsoft Defender for Cloud installs extensions such as the Log Analytics agent or Azure Policy guest configuration agent onto supported resources. While this configuration collects security data and enables visibility, it does not alter the resource's configuration to satisfy policies like disk encryption requirements. Enabling auto provisioning only adds the agent; it does not create DeployIfNotExists deployments that actually enable encryption on the VM disks. Therefore, it cannot automatically bring non-compliant resources into compliance.
- ✓
Enable 'Remediation' for each policy assignment in the custom initiative
Why this is correct
Azure Policy's remediation feature is the native mechanism for automatically fixing resources that are non-compliant with policies that use the DeployIfNotExists or Modify effects. When you assign a custom initiative, you can enable remediation for each assignment, which creates a managed identity and allows the policy engine to run remediation tasks during evaluation cycles. These tasks deploy the required template or modify the resource configuration—such as enabling disk encryption—directly, without manual intervention. This is the correct option because it uses the built-in, continuously-running remediation engine tied to policy assignments.
- ✗
Enable 'Just-in-time (JIT) VM access'
Why it's wrong here
Just-in-time (JIT) VM access is a security feature in Microsoft Defender for Cloud that controls inbound network traffic to VMs by opening specified ports only for approved time windows. It reduces the attack surface against brute-force attacks but does not evaluate or change the VM's internal configuration, such as encryption settings. JIT does not interact with Azure Policy or custom initiatives, so it cannot perform compliance remediation. Enabling JIT would not address non-compliant resources described by the custom policy initiative.
- ✗
Enable 'Workflow automation' to trigger a Logic App when non-compliance is detected
Why it's wrong here
Workflow automation in Defender for Cloud lets you trigger Logic Apps in response to events such as security alerts or changes in regulatory compliance. However, this is an event-driven notification and orchestration layer, not the continuous remediation engine that Azure Policy provides. While a Logic App could theoretically run a script to fix a non-compliant resource, you would have to build and manage that logic manually, and it is not automatically invoked by each policy evaluation cycle. Unlike the built-in remediation feature, it does not directly create the deployment tasks required by DeployIfNotExists policies to enforce disk encryption.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.