AZ-500 Manage identity and access Practice Question
A DevOps team wants Defender for Cloud to identify secrets exposed in GitHub repositories. What should be configured?
⚠ Common exam trap
Many candidates confuse the Defender for Cloud DevOps Security connector with GitHub's own secret scanning (which requires GitHub Advanced Security), but the question specifically asks for a Defender for Cloud configuration, making the connector the correct choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for Cloud DevOps Security connector
Defender for Cloud's DevOps Security connector integrates with GitHub to scan repositories for exposed secrets (e.g., API keys, tokens) using Microsoft's secret scanning engine. This connector enables Defender for Cloud to monitor commits and pull requests, alerting on secrets detected in code. It is the correct solution because it directly addresses the requirement to identify secrets in GitHub repositories within the Defender for Cloud ecosystem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Bastion native client
Why it's wrong here
Azure Bastion native client is a PaaS service that provides secure, TLS-based RDP/SSH access to Azure VMs without exposing public IPs. While it improves jump-host-less remote administration, it has no scanning capability for code repositories, pipelines, or secret material. It does not feed findings to Defender for Cloud's DevOps security engine and therefore cannot identify leaked credentials.
- ✓
Defender for Cloud DevOps Security connector
Why this is correct
The Defender for Cloud DevOps Security connector connects Azure DevOps and GitHub organizations to Defender for Cloud, enabling security assessments of repositories, builds, and release pipelines. Once connected during the enablement of Defender CSPM, it runs secret scanning, code scanning, and dependency scanning, surfacing exposed credentials as recommendations. This connector is the direct mechanism by which a DevOps team's secrets are identified and remediated in the portal.
- ✗
Sentinel Syslog connector
Why it's wrong here
Microsoft Sentinel Syslog connector ingests security events from on-premises and network devices using the common Syslog protocol into a Log Analytics workspace. Its purpose is SIEM correlation, threat hunting, and incident response, not repository or pipeline inspection. Since it does not scan source code or continuous integration/continuous delivery (CI/CD) systems, enabling it cannot surface secrets from DevOps artifacts to Defender for Cloud.
- ✗
Azure Storage lifecycle management
Why it's wrong here
Azure Storage lifecycle management lets you define policies to move blobs to cooler access tiers or delete them based on age or last modification. It operates on data lifecycle and storage cost optimization, independent of content inspection or secret detection. It neither queries code repositories nor performs credential scanning, so it cannot help Defender for Cloud identify secrets in a DevOps workflow.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.