Enable AKS Threat Detection with Microsoft Defender for Containers
You are using Microsoft Defender for Cloud to protect Azure Kubernetes Service (AKS) clusters. You need to receive alerts about suspicious activities within the cluster, such as privilege escalations. What should you enable?
Quick Answer
The answer is Microsoft Defender for Containers. This is the correct choice because it is the dedicated plan within Microsoft Defender for Cloud that provides threat detection for Azure Kubernetes Service (AKS) clusters, specifically monitoring for suspicious activities like privilege escalations, runtime threats, and anomalous behavior at the host and cluster level. On the Microsoft Azure Security Engineer Associate AZ-500 exam, this question tests your understanding of which Defender plan directly enables AKS threat detection alerts, versus tools like Azure Policy (which enforces configurations but does not generate alerts) or Microsoft Sentinel (a separate SIEM for log ingestion). A common trap is confusing Azure Policy for AKS with a detection tool, but remember: policy enforces, Defender detects. For a quick memory tip, think “Containers need a Defender” — the word “Containers” in the plan name directly ties to container workload protection, making it the go-to for AKS alerting.
⚠ Common exam trap
Many exam-takers confuse Microsoft Sentinel (a SIEM) with Microsoft Defender for Cloud (a cloud security posture management and threat detection tool), assuming that ingesting AKS logs into Sentinel provides the same built-in threat detection alerts as Defender for Containers, but Sentinel requires custom analytics rules to generate alerts, whereas Defender for Containers provides out-of-the-box detection for privilege escalations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Containers
Microsoft Defender for Containers is the correct solution because it provides threat detection for AKS clusters, including alerts for privilege escalations, suspicious process execution, and other runtime threats. It integrates directly with Defender for Cloud to monitor the Kubernetes audit logs and container workloads without requiring additional data connectors or agents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Containers
Why this is correct
Microsoft Defender for Containers provides Kubernetes-aware threat detection, monitoring control plane audit logs and node-level runtime activity to surface suspicious events such as privilege escalation inside AKS clusters. Enabling it satisfies the stem's requirement for cluster activity alerts, which generic Defender for Cloud plans or standalone Microsoft Entra ID controls cannot deliver.
- ✗
Microsoft Sentinel with AKS data connector
Why it's wrong here
Microsoft Sentinel is a SIEM/SOAR platform requiring its own data connectors and analytics rules; it does not surface Defender for Cloud's AKS threat alerts by itself. Sentinel is the right choice when centralised correlation across many sources is the requirement.
- ✗
Azure Policy for AKS
Why it's wrong here
Azure Policy for AKS enforces configuration and compliance guardrails, such as restricting privileged containers or image sources; it audits and remediates resource state rather than detecting runtime behaviour. Defender for Cloud's Kubernetes threat detection, fed by runtime sensors, generates the privilege-escalation alerts. Azure Policy would be right for governance baselines, not behavioural alerting.
- ✗
Azure Security Center (classic)
Why it's wrong here
Azure Security Center (classic) is the retired predecessor of Microsoft Defender for Cloud and cannot be enabled alongside it to generate these alerts. It would have been relevant before migration to Defender for Cloud, not for current AKS threat detection.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are configuring Microsoft Defender for Cloud to protect an Azure Kubernetes Service (AKS) cluster. The cluster runs sensitive workloads. You need to enable threat detection and vulnerability assessment for the AKS environment. Which THREE of the following should you enable?
hard- ✓ A.Microsoft Defender for Containers plan
- B.Microsoft Defender for Servers plan
- ✓ C.Vulnerability assessment for container images in Defender for Cloud
- ✓ D.Continuous export of security alerts to Log Analytics
- E.Azure Policy add-on for AKS
Why A: Option A (Microsoft Defender for Containers plan) is correct because it is the specific Defender for Cloud plan that provides threat detection for AKS clusters, including control-plane audit log analysis, runtime workload protection, and Kubernetes-native alerting. Option C (Vulnerability assessment for container images in Defender for Cloud) is correct because it scans images in Azure Container Registry and running containers for known CVEs, which is required for vulnerability assessment of the AKS environment. Option D (Continuous export of security alerts to Log Analytics) is correct because continuous export streams Defender for Cloud alerts and recommendations to a Log Analytics workspace, enabling centralized retention, correlation, and investigation of AKS threat detections. Option B (Microsoft Defender for Servers plan) is not required here because it protects VMs and servers, not the AKS control plane or container workloads specifically. Option E (Azure Policy add-on for AKS) is not a Defender for Cloud threat detection or vulnerability assessment feature; it enforces governance and policy compliance on the cluster.
Variation 2. You need to enable Microsoft Defender for Cloud's workload protection for Azure Kubernetes Service (AKS) clusters. Which Defender plan should you enable?
easy- A.Enable the foundational Cloud Security Posture Management (CSPM) plan.
- B.Enable Defender for SQL.
- ✓ C.Enable Defender for Containers.
- D.Enable Defender for Servers.
Why C: To enable workload protection for Azure Kubernetes Service (AKS) clusters in Microsoft Defender for Cloud, you must enable the Defender for Containers plan. This plan provides runtime threat detection, vulnerability assessment, and compliance monitoring specifically for containerized environments, including AKS, Azure Container Registry (ACR), and Azure Container Instances (ACI). It covers Kubernetes audit logs, host-level security, and container image scanning, which are essential for securing AKS workloads.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.