AZ-500 Manage identity and access Practice Question
A Defender for Cloud recommendation is valid for most subscriptions but not for a legacy subscription with an approved exception. The team wants secure score to reflect the exception without disabling the recommendation everywhere. What should they do?
⚠ Common exam trap
Many exam-takers confuse 'exemption' with 'disabling' or 'removing' the policy, leading them to choose options that either globally disable the recommendation (A or D) or incorrectly assume severity changes can create exceptions (B), when in fact Azure Policy exemptions are the precise mechanism to exclude a specific scope while preserving the policy for all others.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an exemption for the affected scope with a justification
Azure Policy exemptions allow you to exclude a specific scope (e.g., a subscription or resource group) from a policy or initiative effect while still having the policy enforced elsewhere. By creating an exemption for the legacy subscription with a justification, the Defender for Cloud recommendation remains active for all other subscriptions, and the secure score calculation will correctly reflect the exception without disabling the recommendation globally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the built-in initiative from the management group
Why it's wrong here
Deleting the built-in initiative from the management group is invalid because built-in (recommendation) initiatives are Microsoft-managed and cannot be removed from the hierarchy. Even if it were possible, doing so would strip all child subscriptions of that initiative's security controls, broadly impacting environment-wide compliance rather than addressing the single legacy subscription. The proper scoped action is to create an exemption for the affected scope, not to modify the overarching initiative.
- ✗
Change the recommendation severity to Low
Why it's wrong here
Changing the recommendation's severity to Low does not suppress the recommendation for the legacy subscription; it merely reclassifies its risk rating, which can mislead security teams and is often not permitted on built-in recommendations. Severity is a global property of the recommendation definition, so altering it would change how the issue is prioritized across all subscriptions. This action fails to address the specific 'valid for most' scenario because the legacy subscription would still show the recommendation, just with a lower severity.
- ✓
Create an exemption for the affected scope with a justification
Why this is correct
Creating an exemption for the affected scope with a justification is the correct approach because Microsoft Defender for Cloud natively supports exemptions to exclude a specific scope from a recommendation while leaving the initiative intact. You can target the exact subscription (or resource group) and provide a reason, such as 'legacy system' or 'not applicable,' and optionally set an expiration date. This directly addresses the requirement by suppressing the recommendation only where it's not valid, while preserving security monitoring and compliance for all other scopes.
- ✗
Disable Defender for Cloud on the legacy subscription
Why it's wrong here
Disabling Defender for Cloud on the legacy subscription is far too broad because it turns off the entire security service, including threat detection, security alerts, and other compliance recommendations, leaving that subscription unprotected. The requirement is only that one recommendation is 'valid for most,' implying you still need security coverage on the legacy subscription but want to dismiss that specific item. An exemption is the intended, granular control; disabling the service would create a critical security gap and is not a valid method for handling a single recommendation.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.