Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/06be3959-4f3e-4f6a-8a6d-5f5f5f5f5f5f",
    "parameters": {},
    "scope": "/subscriptions/12345678-1234-1234-1234-123456789012",
    "notScopes": []
  }
}
```

Refer to the exhibit. You are assigning a built-in Azure Policy definition to a subscription using Azure CLI. The policy is 'Audit VMs that do not use managed disks'. After assignment, you check in Microsoft Defender for Cloud and see that the policy is not generating any recommendations. What is the most likely reason?

⚠ Common exam trap

A common mix-up: candidates assume any Azure Policy with an 'Audit' effect will automatically generate a recommendation in Defender for Cloud, but in reality, only policies that are part of a Defender for Cloud security initiative are surfaced as recommendations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy is not part of a Defender for Cloud security initiative.

Microsoft Defender for Cloud only generates security recommendations from policies that are part of a built-in or custom security initiative (such as the 'Microsoft cloud security benchmark' initiative). A standalone policy assignment, even if it has the 'Audit' effect, will not appear as a recommendation in Defender for Cloud unless it is included in an initiative that Defender for Cloud monitors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy effect is set to 'Audit', but it should be 'Deny' to generate recommendations.

    Why it's wrong here

    The Audit effect does not prevent a policy from generating recommendations; in fact, Audit is the only effect that allows you to see compliance results without blocking resource creation. Defender for Cloud surfaces recommendations only for policies that are part of an assigned security initiative, regardless of whether the effect is Audit or Deny. Therefore, switching to Deny would not make the policy appear as a recommendation—it would only change enforcement behavior.

  • ✗

    The policy requires a managed identity to run.

    Why it's wrong here

    A managed identity is required only for policies with the deployIfNotExists or modify effects, because those effects need to perform remediation actions on noncompliant resources. Audit policies simply evaluate and report compliance status, so they do not require a managed identity to run. Since the policy is in Audit mode, the lack of a managed identity is not a reason why its recommendations are missing.

  • ✓

    The policy is not part of a Defender for Cloud security initiative.

    Why this is correct

    Defender for Cloud does not display recommendations for every individual policy assigned in the environment; it only generates recommendations from policies that belong to a security initiative, such as the Azure Security Benchmark, that is assigned to the subscription or management group. A standalone policy assigned directly to the subscription will produce compliance results in Azure Policy but will not appear as a security recommendation in Defender for Cloud. Therefore, the missing initiative membership explains why this policy's recommendations are not visible.

  • ✗

    The policy is assigned to the wrong subscription.

    Why it's wrong here

    The policy's scope appears to be the correct subscription, as evidenced by the resource it is intended to evaluate. Even if the scope were correct, a standalone policy without an initiative wrapper would still fail to show up in Defender for Cloud because recommendations are tied to initiative membership, not just assignment location. The wrong subscription issue would also likely cause no compliance data for that subscription, which is not the case here.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.