Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security team uses Microsoft Defender for Cloud to monitor Azure virtual machines. They want to automatically install a specific endpoint protection solution on all Windows VMs that are currently missing it, without manual intervention. The solution is not integrated natively with Defender for Cloud. Which feature should they use?

⚠ Common exam trap

Many candidates assume Defender for Cloud's 'Fix' option can deploy any endpoint protection solution, but it only supports solutions that are natively integrated and listed in the Defender for Cloud dashboard.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Azure Policy 'DeployIfNotExists' assignment that installs the endpoint protection extension on VMs missing it

Azure Policy's 'DeployIfNotExists' effect can automatically deploy a custom endpoint protection extension to Windows VMs that are missing it, even if the solution is not natively integrated with Defender for Cloud. This allows the security team to enforce compliance by installing the specific third-party endpoint protection agent via a policy assignment, without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the 'Endpoint protection' recommendation and use the 'Fix' option

    Why it's wrong here

    Defender for Cloud's 'Endpoint protection should be installed on machines' recommendation is a monitoring control, not an installer. The 'Fix' action (quick remediation) is only available for built-in recommendations that have a native remediation script and are natively integrated with Defender for Cloud. Because a third-party endpoint protection solution is not natively integrated, there is no remediation task behind the recommendation, so clicking Fix would do nothing or fail. Enabling the recommendation alone only flags non-compliant VMs; it never deploys the missing agent.

  • ✓

    Create an Azure Policy 'DeployIfNotExists' assignment that installs the endpoint protection extension on VMs missing it

    Why this is correct

    Create an Azure Policy definition using the DeployIfNotExists effect that targets VMs (or VM extensions) where the specific endpoint protection extension is absent. When the policy evaluates a VM and the condition is true, it deploys a linked ARM template, which installs the vendor's protection extension using the assignment's managed identity. This approach works for non-native, third-party solutions because you provide the extension template, and it can be used both for automatic evaluation of new VMs and for a remediation task to cover already-running VMs. The policy assignment must have a managed identity with Contributor (or equivalent) permissions on the target scope.

  • ✗

    Configure adaptive application controls to allow the endpoint protection software

    Why it's wrong here

    Adaptive application controls (AAC) build an allowlist of known-safe executables and block unknown binaries; they do not perform installation or deployment of software. Allowing the endpoint protection software in AAC would only prevent it from being blocked after it is already installed; it would not place the missing agent onto non-compliant VMs. AAC is fundamentally a runtime host-hardening control, not a configuration-remediation mechanism like DeployIfNotExists, so it leaves the underlying compliance gap unresolved.

  • ✗

    Enable just-in-time VM access for the VMs

    Why it's wrong here

    Just-in-time (JIT) VM access manages inbound network traffic by opening specific ports (e.g., 3389/22) in the NSG for a limited time and then closing them; it has no capability to deploy software or install extensions on a VM. Even if you enable JIT, the VM remains without the endpoint protection agent, so the security recommendation continues to be non-compliant. JIT reduces exposure of management ports but is orthogonal to endpoint protection deployment.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.