Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A DevOps team wants Defender for Cloud to identify secrets exposed in GitHub repositories. What should be configured?

⚠ Common exam trap

Many candidates confuse the Defender for Cloud DevOps Security connector with GitHub's own secret scanning (which requires GitHub Advanced Security), but the question specifically asks for a Defender for Cloud configuration, making the connector the correct choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defender for Cloud DevOps Security connector

Defender for Cloud's DevOps Security connector integrates with GitHub to scan repositories for exposed secrets (e.g., API keys, tokens) using Microsoft's secret scanning engine. This connector enables Defender for Cloud to monitor commits and pull requests, alerting on secrets detected in code. It is the correct solution because it directly addresses the requirement to identify secrets in GitHub repositories within the Defender for Cloud ecosystem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Bastion native client

    Why it's wrong here

    Azure Bastion native client is a PaaS service that provides secure, TLS-based RDP/SSH access to Azure VMs without exposing public IPs. While it improves jump-host-less remote administration, it has no scanning capability for code repositories, pipelines, or secret material. It does not feed findings to Defender for Cloud's DevOps security engine and therefore cannot identify leaked credentials.

  • ✓

    Defender for Cloud DevOps Security connector

    Why this is correct

    The Defender for Cloud DevOps Security connector connects Azure DevOps and GitHub organizations to Defender for Cloud, enabling security assessments of repositories, builds, and release pipelines. Once connected during the enablement of Defender CSPM, it runs secret scanning, code scanning, and dependency scanning, surfacing exposed credentials as recommendations. This connector is the direct mechanism by which a DevOps team's secrets are identified and remediated in the portal.

  • ✗

    Sentinel Syslog connector

    Why it's wrong here

    Microsoft Sentinel Syslog connector ingests security events from on-premises and network devices using the common Syslog protocol into a Log Analytics workspace. Its purpose is SIEM correlation, threat hunting, and incident response, not repository or pipeline inspection. Since it does not scan source code or continuous integration/continuous delivery (CI/CD) systems, enabling it cannot surface secrets from DevOps artifacts to Defender for Cloud.

  • ✗

    Azure Storage lifecycle management

    Why it's wrong here

    Azure Storage lifecycle management lets you define policies to move blobs to cooler access tiers or delete them based on age or last modification. It operates on data lifecycle and storage cost optimization, independent of content inspection or secret detection. It neither queries code repositories nor performs credential scanning, so it cannot help Defender for Cloud identify secrets in a DevOps workflow.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.