AZ-500 Manage identity and access Practice Question
A company uses Microsoft Defender for Cloud to manage security posture. The security team wants to receive alerts when a virtual machine has a vulnerability rated as 'Critical' by the integrated vulnerability assessment solution. Which Defender for Cloud plan must be enabled for the subscription to receive these alerts?
⚠ Common exam trap
It's easy for candidates to assume Defender for Servers Plan 1 is sufficient because it provides basic threat alerts, but they overlook that the integrated vulnerability assessment (Qualys) and its critical vulnerability alerts are exclusive to Plan 2.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for Servers Plan 2
Defender for Servers Plan 2 is required because it includes the integrated Qualys-based vulnerability assessment solution that automatically scans VMs and generates security alerts for critical vulnerabilities. Plan 1 only provides basic threat detection and does not include the vulnerability assessment engine or the corresponding alerting capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defender for Servers Plan 1
Why it's wrong here
Plan 1 includes endpoint detection and response (EDR) and threat detection, but it does not include the integrated vulnerability assessment. Without Defender Vulnerability Management, the service cannot enumerate missing patches, CVEs, or misconfigurations on the VM's OS. Consequently, alerts for critical vulnerabilities are not generated, leaving the server security posture incomplete.
- ✓
Defender for Servers Plan 2
Why this is correct
Defender for Servers Plan 2 builds on Plan 1 by adding integrated vulnerability assessment (Defender Vulnerability Management), just-in-time VM access, and allowlisting. This tier continuously scans Azure VMs for missing security updates, known CVEs, and OS misconfigurations, then raises security alerts and recommendations. For a company using Defender for Cloud to manage server security, Plan 2 is the correct choice to generate alerts for critical vulnerabilities.
- ✗
Defender for Storage
Why it's wrong here
Defender for Storage is designed for Azure Blob Storage, Azure Files, and Azure Data Lake Storage, detecting threats like malware uploads, anomalous access, and credential exposure. This plan operates at the data plane of storage accounts, not on compute resources or virtual machines. It has no mechanism to scan the VM's operating system or generate vulnerability alerts for server patches, so it cannot fulfill the requirement.
- ✗
Defender for Databases
Why it's wrong here
Defender for Databases protects PaaS database services, including Azure SQL Database, SQL Managed Instance, and Azure Synapse SQL, by identifying SQL injection, brute-force attacks, and unusual query patterns. This plan is scoped to the database engine and its access patterns, not to the underlying VM host OS or installed software. As a result, it does not provide OS-level vulnerability scanning or alerting for CVEs on virtual machines, making it unrelated to this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.