AZ-500 Manage identity and access Practice Question
A team enables Microsoft Defender for Storage. Which two threats can the plan help detect?
⚠ Common exam trap
Candidates often confuse Defender for Storage with broader Defender for Cloud capabilities, incorrectly assuming it monitors identity or networking threats outside the storage data plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access from suspicious IP addresses to storage accounts
Microsoft Defender for Storage detects anomalous activities that could indicate threats to storage accounts. Option A is correct because the service analyzes incoming requests to identify access from suspicious IP addresses, such as known malicious IPs or Tor exit nodes, using threat intelligence feeds. Option D is correct because when malware scanning is enabled, Defender for Storage can detect malware uploaded to Blob Storage by scanning files for known malicious signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Access from suspicious IP addresses to storage accounts
Why this is correct
Microsoft Defender for Storage flags access to storage accounts from suspicious IP addresses by matching request metadata—such as source IP, TLS version, and API behavior—against global threat intelligence and Microsoft's cybercrime attribution data. This is a core detection capability that identifies potential credential compromise or unauthorized access attempts directly on the storage data plane, making it correct for a threat detection requirement.
- ✗
Expired Microsoft Entra PIM role assignments
Why it's wrong here
Expired Microsoft Entra PIM role assignments are an identity lifecycle and access governance issue, not a storage-specific security event. Defender for Storage monitors the data plane of storage accounts—blob, file, queue, and table operations—and does not ingest PIM activity or role expiration telemetry. While this may be a compliance risk, it is not a threat that Defender for Storage can detect, so it fails the stated requirement.
- ✗
Public IP address creation on virtual machines
Why it's wrong here
Public IP address creation on virtual machines is an Azure Resource Manager control-plane operation tracked by Azure Activity Log, not a storage data plane event. Defender for Storage analyzes telemetry from storage services, such as authentication attempts, blob uploads, and queries, and does not monitor VM networking actions; moreover, creating a public IP is not inherently malicious and would at most trigger a Defender for Cloud recommendation, not a storage threat alert.
- ✓
Malware uploaded to Blob Storage when malware scanning is enabled
Why this is correct
Malware uploaded to Blob Storage is detected by Microsoft Defender for Storage when the optional malware scanning feature is enabled at the storage account level. This feature performs near-instant, content-based scanning of uploaded blobs using Microsoft antimalware engines and raises an alert when malicious payloads are found, directly addressing the requirement to detect file-based threats as well as access anomalies.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.