AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Exhibit
{
"properties": {
"pricingTier": "Standard",
"autoProvision": true
}
}Refer to the exhibit. You are reviewing the Microsoft Defender for Cloud settings for a subscription. The JSON shows that 'autoProvision' is set to true. What does this mean?
⚠ Common exam trap
It's easy for candidates to confuse 'autoProvision' (agent installation) with 'auto enablement of Defender plans' (pricing tier), leading them to incorrectly select Option A, even though enabling plans requires explicit configuration under 'Environment settings' > 'Defender plans'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Log Analytics agent is automatically installed on new Azure VMs
When 'autoProvision' is set to true in Microsoft Defender for Cloud, it means the Log Analytics agent (formerly Microsoft Monitoring Agent) is automatically installed on all existing and new Azure VMs in the subscription. This agent collects security-related telemetry and sends it to the Log Analytics workspace associated with Defender for Cloud, enabling threat detection and security monitoring. The setting does not enable any Defender plans or policies—it only controls agent deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All Microsoft Defender plans are automatically enabled for new resources
Why it's wrong here
Auto-provisioning in Microsoft Defender for Cloud only deploys the Log Analytics agent (or Azure Monitor Agent) to Azure VMs for data collection. It does not enable any Microsoft Defender plan, such as Defender for Servers or Defender for SQL. Defender plans must be explicitly enabled at the subscription level, and each plan has its own pricing and feature toggles. A new VM inherits the plan state of its subscription, but the plan itself is not automatically activated simply because auto-provisioning is on.
- ✓
The Log Analytics agent is automatically installed on new Azure VMs
Why this is correct
When auto-provisioning is enabled in Microsoft Defender for Cloud, the Log Analytics agent is automatically installed on existing and newly created Azure VMs. For new VMs, the agent extension is deployed as part of the VM provisioning process, ensuring that security data like event logs, performance counters, and audit records are collected without manual intervention. This agent installation is the core behavior of auto-provisioning and is the correct interpretation of the setting in the exhibit. The agent forwards data to the configured Log Analytics workspace for analysis by Defender for Cloud.
- ✗
Security policies are automatically assigned to new resource groups
Why it's wrong here
Auto-provisioning does not create or assign Azure Policy or security policy assignments to new resource groups. Security policies (initiatives) in Defender for Cloud are assigned at the management group or subscription scope, and that assignment applies to resources within those scopes. Creating a new resource group does not generate a new policy assignment; the existing scope-level assignments still govern any resources placed in that group. Auto-provisioning is limited to agent deployment and has no effect on policy assignment lifecycle.
- ✗
Continuous export of security alerts is enabled
Why it's wrong here
Continuous export is a separate feature in Defender for Cloud that streams security alerts and recommendations to an Event Hub or a Log Analytics workspace via diagnostic settings. Enabling auto-provisioning for the Log Analytics agent does not turn on continuous export, nor does it configure any export targets. You must explicitly enable and configure continuous export, choosing which data types and the destination. The exhibit's auto-provisioning setting is unrelated to this alert streaming capability.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.