AZ-500 Manage identity and access Practice Question
An organization wants to export Defender for Cloud recommendations and alerts into a central Log Analytics workspace for retention and hunting. Which feature should they use?
⚠ Common exam trap
Many exam-takers confuse 'Continuous export' with 'Azure Monitor autoscale' or 'External Attack Surface Management' because they all involve monitoring or scaling, but only continuous export directly addresses the requirement to export Defender for Cloud data to Log Analytics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Continuous export
Continuous export is the correct feature because it allows you to stream Defender for Cloud security alerts and recommendations to a Log Analytics workspace for long-term retention and custom hunting queries. This feature supports both real-time and scheduled export of security data, enabling centralized monitoring and compliance auditing. It directly addresses the requirement to export Defender for Cloud data into a Log Analytics workspace without additional third-party tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender External Attack Surface Management
Why it's wrong here
Microsoft Defender External Attack Surface Management (EASM) is a security posture product that continuously discovers and inventories externally visible assets like domains, IPs, and web apps. It does not function as a destination to export Defender for Cloud's security alerts and recommendations; rather, it ingests its own discovery data and provides a separate risk assessment view, so it fails the stated export requirement.
- ✓
Continuous export
Why this is correct
Continuous export is the dedicated Defender for Cloud feature that streams security recommendations and alerts to an Azure Log Analytics workspace, Event Hub, or Azure Monitor using diagnostic settings. It supports granular selection of resource types and can be configured via ARM/REST, enabling integration with SIEMs like Microsoft Sentinel. This directly fulfills the requirement, as it is the native mechanism for exporting this data.
- ✗
Microsoft Entra access reviews
Why it's wrong here
Microsoft Entra access reviews are an identity governance control used to certify and recertify user access to groups, applications, and roles through periodic reviews. They operate on identity entitlements rather than security alerts or infrastructure recommendations, and they have no pipeline to receive or export Defender for Cloud's recommendation data. Therefore, they cannot satisfy the export requirement.
- ✗
Azure Monitor autoscale
Why it's wrong here
Azure Monitor autoscale is a scaling capability that adjusts the number of running instances of a service (e.g., VMSS, App Service Plan) based on metrics or a time schedule. It is a resource management feature focused on elasticity and does not consume, process, or export security alerts or recommendations from Defender for Cloud. It entirely lacks data export or integration mechanisms relevant to the stated requirement.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.