Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A company uses Microsoft Defender for Cloud to monitor security alerts. They receive an alert about a compromised virtual machine and want to automatically execute a playbook that isolates the VM by modifying the network security group. Which Defender for Cloud feature should they use to create this automated response?

⚠ Common exam trap

Many candidates confuse 'Continuous export' (which sends data to external systems) with 'Workflow automation' (which executes a playbook), assuming any export can trigger a response, but Continuous export only streams data and does not invoke Logic Apps directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Workflow automation

Workflow automation in Microsoft Defender for Cloud allows you to define automated responses to security alerts by triggering Azure Logic Apps. In this scenario, you would create a Logic App that modifies the network security group (NSG) to isolate the compromised VM, and then configure a workflow automation rule to run that Logic App whenever the specific alert is triggered. This provides a no-code, event-driven remediation without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Workflow automation

    Why this is correct

    Workflow automation is the correct answer because it directly enables an automated response to a security alert. In Microsoft Defender for Cloud, you can create a workflow automation rule that triggers an Azure Logic App when a specific security alert is generated. The Logic App can then execute an automatic isolation action on the affected Virtual Machine, for instance by using an Azure SQL or Resource Manager connector to modify network security groups or apply an Azure Policy. This is the only option that provides a built-in event-driven mechanism to take a protective action without human intervention.

  • ✗

    Security policy

    Why it's wrong here

    Security policy in Microsoft Defender for Cloud is grounded in Azure Policy, which enforces configuration and compliance requirements across resources, such as requiring encryption or specific security settings. These policies are evaluated continuously to produce recommendations and compliance scores, but they are not triggered by individual security alert events. They lack any logic to react to an alert's metadata or severity, so they cannot initiate an isolation workflow. A security policy might define the desired end-state, but it does not provide a runtime response to an active threat.

  • ✗

    Alert suppression

    Why it's wrong here

    Alert suppression rules in Microsoft Defender for Cloud are designed to reduce alert fatigue by hiding alerts that match specified conditions, such as a particular alert name or entity, based on a suppression rule like a category or security issue. However, they operate solely as a filtering mechanism on the alert stream; they do not initiate any response or action. Suppressed alerts never appear in the dashboard or feed into automation, so a compromised VM would remain unaffected and unisolated. This is fundamentally different from workflow automation, which actively invokes a Logic App to perform remediation.

  • ✗

    Continuous export

    Why it's wrong here

    Continuous export is a feature that forwards security alerts, recommendations, and other data from Microsoft Defender for Cloud to a Log Analytics workspace or an Event Hub for further processing and storage. It is a unidirectional data streaming mechanism, not a control channel for remediation actions. While you could build a custom downstream solution, such as an Azure Function that listens to the Event Hub and isolates a VM, the continuous export feature itself never triggers a Logic App or performs an action. Therefore, it does not automate the isolation directly, only makes the data available for potential external automation.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.