AZ-500 Manage identity and access Practice Question
A security engineer connects Azure virtual machines to Microsoft Defender for Cloud. The team wants vulnerability findings without installing a vulnerability scanner extension on each VM. Which capability should be enabled?
⚠ Common exam trap
Many candidates assume vulnerability scanning always requires an agent or extension, but Microsoft Defender for Cloud offers an agentless option that uses cloud-native APIs and OS-level data to perform assessments without any local software.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Agentless vulnerability assessment for machines in Defender for Servers
Agentless vulnerability assessment for machines in Defender for Servers is the correct capability because it uses Microsoft Defender for Cloud's built-in scanning engine to assess VMs for vulnerabilities without requiring any agent or extension installation. This feature leverages the VM's existing configuration and cloud APIs to perform scans, meeting the team's requirement to avoid installing a vulnerability scanner extension on each VM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Agentless vulnerability assessment for machines in Defender for Servers
Why this is correct
Agentless vulnerability assessment in Defender for Servers scans Azure VM operating system and installed software against the Microsoft Defender Vulnerability Management knowledge base without deploying any agent or extension on the machine. It leverages Azure-native metadata and managed disk snapshots to identify missing security updates and misconfigurations, directly satisfying the requirement to find vulnerabilities without agent installation. This makes it the correct solution for the scenario.
- ✗
Microsoft Sentinel User and Entity Behavior Analytics
Why it's wrong here
Microsoft Sentinel UEBA analyzes behavioral patterns for users, devices, and resources to detect anomalous activities such as impossible travel or account misuse. While it can enrich security investigations, it does not perform software vulnerability scanning or evaluate the patch status of an Azure VM. Therefore, it is not appropriate when the explicit goal is agentless vulnerability assessment for machines.
- ✗
Azure Firewall threat intelligence mode
Why it's wrong here
Azure Firewall threat intelligence mode enables the firewall to block traffic from known malicious IP addresses or domains based on Microsoft threat intelligence feeds. It is a network-layer security control that protects east-west and north-south traffic, but it does not enumerate missing patches or software vulnerabilities on a specific VM. This option fails to meet the requirement because vulnerability assessment requires inspecting the operating system and installed applications, not filtering network traffic.
- ✗
Microsoft Entra Identity Protection sign-in risk
Why it's wrong here
Microsoft Entra Identity Protection sign-in risk evaluates identity signals, such as unfamiliar sign-in properties, leaked credentials, or malicious IP addresses, to assign a risk level to authentication events. It helps secure user accounts and enforce conditional access, but it has no visibility into the software inventory or state of a virtual machine. Thus, it does not provide agentless vulnerability assessment for Azure VMs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.