Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security engineer connects Azure virtual machines to Microsoft Defender for Cloud. The team wants vulnerability findings without installing a vulnerability scanner extension on each VM. Which capability should be enabled?

⚠ Common exam trap

Many candidates assume vulnerability scanning always requires an agent or extension, but Microsoft Defender for Cloud offers an agentless option that uses cloud-native APIs and OS-level data to perform assessments without any local software.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Agentless vulnerability assessment for machines in Defender for Servers

Agentless vulnerability assessment for machines in Defender for Servers is the correct capability because it uses Microsoft Defender for Cloud's built-in scanning engine to assess VMs for vulnerabilities without requiring any agent or extension installation. This feature leverages the VM's existing configuration and cloud APIs to perform scans, meeting the team's requirement to avoid installing a vulnerability scanner extension on each VM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Agentless vulnerability assessment for machines in Defender for Servers

    Why this is correct

    Agentless vulnerability assessment in Defender for Servers scans Azure VM operating system and installed software against the Microsoft Defender Vulnerability Management knowledge base without deploying any agent or extension on the machine. It leverages Azure-native metadata and managed disk snapshots to identify missing security updates and misconfigurations, directly satisfying the requirement to find vulnerabilities without agent installation. This makes it the correct solution for the scenario.

  • ✗

    Microsoft Sentinel User and Entity Behavior Analytics

    Why it's wrong here

    Microsoft Sentinel UEBA analyzes behavioral patterns for users, devices, and resources to detect anomalous activities such as impossible travel or account misuse. While it can enrich security investigations, it does not perform software vulnerability scanning or evaluate the patch status of an Azure VM. Therefore, it is not appropriate when the explicit goal is agentless vulnerability assessment for machines.

  • ✗

    Azure Firewall threat intelligence mode

    Why it's wrong here

    Azure Firewall threat intelligence mode enables the firewall to block traffic from known malicious IP addresses or domains based on Microsoft threat intelligence feeds. It is a network-layer security control that protects east-west and north-south traffic, but it does not enumerate missing patches or software vulnerabilities on a specific VM. This option fails to meet the requirement because vulnerability assessment requires inspecting the operating system and installed applications, not filtering network traffic.

  • ✗

    Microsoft Entra Identity Protection sign-in risk

    Why it's wrong here

    Microsoft Entra Identity Protection sign-in risk evaluates identity signals, such as unfamiliar sign-in properties, leaked credentials, or malicious IP addresses, to assign a risk level to authentication events. It helps secure user accounts and enforce conditional access, but it has no visibility into the software inventory or state of a virtual machine. Thus, it does not provide agentless vulnerability assessment for Azure VMs.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.