Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A team wants to automatically deploy Defender for Cloud settings across new subscriptions under a management group. Which Azure capability should they use?

⚠ Common exam trap

Many exam-takers confuse Azure Policy with Azure Blueprints or think that Defender for Cloud settings can only be configured per subscription manually, missing that Policy initiatives at the management group level provide automatic, scalable enforcement for new subscriptions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy initiative assignment

Azure Policy initiative assignments allow you to bundle multiple policy definitions (such as those for Defender for Cloud) and assign them at the management group scope. This ensures that all new subscriptions under that management group automatically inherit and enforce the Defender for Cloud settings, including enabling security monitoring and threat detection. This is the correct approach because Azure Policy provides continuous compliance evaluation and remediation at scale across the entire resource hierarchy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application security groups

    Why it's wrong here

    Application security groups (ASGs) are a network security construct used to group virtual machines by workload so that network security group (NSG) rules can be applied consistently to those groups. ASGs have no role in configuring or deploying Defender for Cloud settings, such as enabling security plans, data collection, or auto-provisioning agents. While they can help segment traffic, they do not implement governance or policy-based deployment across subscriptions, so they fail to meet the requirement of automatically applying Defender for Cloud settings to new subscriptions.

  • ✗

    Conditional Access templates

    Why it's wrong here

    Conditional Access templates are a feature of Microsoft Entra ID (formerly Azure AD) used to define identity-driven access policies, such as requiring multi-factor authentication (MFA) or blocking sign-ins from risky locations. These templates govern authentication and session conditions, not the configuration of a security monitoring service like Defender for Cloud. They have no mechanism to deploy or enforce Defender for Cloud settings across new subscriptions, making them an incorrect choice for this scenario.

  • ✗

    Sentinel workbooks

    Why it's wrong here

    Microsoft Sentinel workbooks are interactive dashboards that visualize security data collected into the Sentinel workspace, providing insights into trends, alerts, and incidents. Workbooks are purely analytical and reporting tools; they cannot deploy, configure, or enforce security settings like Defender for Cloud plans or data collection rules. Since they lack any provisioning or policy assignment capability, they cannot automatically apply Defender for Cloud settings to newly created subscriptions.

  • ✓

    Azure Policy initiative assignment

    Why this is correct

    An Azure Policy initiative assignment is the correct solution because it allows you to assign a built-in or custom initiative, such as the Microsoft cloud security benchmark, at resource group, subscription, or management group scope. When assigned at a management group, the policy definitions are inherited by all existing and future subscriptions, enabling Defender for Cloud plans and configuring required monitoring settings automatically on new subscriptions. This policy-driven governance ensures consistency and eliminates the need for manual per-subscription configuration.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.