AZ-500 Manage identity and access Practice Question
A security team uses Microsoft Defender for Cloud to protect Azure virtual machines. They want to implement application allowlisting to prevent execution of unauthorized software on a set of Windows Server VMs. They need to create a baseline of allowed applications and then enforce the allowlist. Which Defender for Cloud feature should they enable?
⚠ Common exam trap
It's easy for candidates to confuse adaptive application controls with file integrity monitoring, thinking both prevent unauthorized software, but FIM only detects changes after the fact and does not block execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adaptive application controls
Adaptive application controls (AAC) in Microsoft Defender for Cloud is the correct feature because it specifically provides application allowlisting for Azure VMs. AAC uses machine learning to analyze processes running on a VM, generate a baseline of allowed applications, and then enforce that allowlist by blocking execution of any unauthorized software. This directly meets the requirement to create a baseline and enforce it on Windows Server VMs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adaptive application controls
Why this is correct
Adaptive application controls is correct because Defender for Cloud builds a machine-learning baseline of known-good executables, scripts, and installation processes running on your VMs, then lets you enforce an allowlist that prevents unknown or untrusted binaries from launching. It can run in audit mode to detect suspicious execution or enforce mode to actively block it, making it the only option here that governs application execution itself.
- ✗
Just-in-time VM access
Why it's wrong here
Just-in-time (JIT) VM access is incorrect because it only controls network access to management ports such as RDP and SSH by opening them temporarily through network security group rules. It never inspects or restricts which applications run after a user signs in, so a malicious executable can still execute on the VM. JIT is a network-layer attack-surface control, not an application execution control.
- ✗
File integrity monitoring
Why it's wrong here
File integrity monitoring (FIM) is incorrect because it is a detective control that hashes and compares critical files, registry keys, and certificates against a clean baseline to detect changes. It raises alerts when legitimate or malicious modifications occur, but it does not block unapproved applications from running. FIM supports forensic analysis and compliance, but it cannot enforce an application allowlist.
- ✗
Adaptive network hardening
Why it's wrong here
Adaptive network hardening is incorrect because it analyzes traffic patterns and recommends narrowed network security group rules, primarily tightening allowed source IPs and ports such as RDP and SSH. Those recommendations are applied at the network layer and do not affect the execution behavior of processes inside the operating system. While it reduces network exposure, it cannot stop a script or executable from launching on the server.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.