AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Which THREE of the following are capabilities of Microsoft Defender for Cloud's workload protection plans?
⚠ Common exam trap
It's easy for candidates to confuse Azure DDoS Protection (a separate network-layer service) or Microsoft Purview DLP (a data security solution) as being part of Defender for Cloud's workload protection plans, when in fact they are distinct services with different scopes and integration points.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adaptive application controls
Adaptive application controls (A) are a capability of Microsoft Defender for Cloud's workload protection plans. They use machine learning to analyze processes running on Azure and non-Azure machines, allowing you to define allowlists for known safe applications and generate security alerts when unauthorized applications execute, thus reducing the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adaptive application controls
Why this is correct
Adaptive application controls are a workload-protection capability in Microsoft Defender for Cloud that uses machine learning to establish a baseline of applications permitted to run on a specific set of Azure or non-Azure VMs. In audit mode, it learns typical running processes; in enforce mode, it blocks untrusted executables and generates security alerts. This feature directly protects the workload plane, distinguishing it from network-layer services like DDoS protection.
- ✗
DDoS protection
Why it's wrong here
Azure DDoS Protection is a standalone network-layer mitigation service that safeguards public IP addresses from volumetric, protocol, and application-layer DDoS attacks. Although Microsoft Defender for Cloud can surface a recommendation to enable DDoS Protection, the actual mitigation is executed by the separate DDoS service, not by Defender for Cloud itself. Therefore, DDoS protection is not one of the three built-in workload protection capabilities being asked for here.
- ✗
Data Loss Prevention (DLP)
Why it's wrong here
Data Loss Prevention (DLP) is a policy-based controls suite within Microsoft Purview that identifies, monitors, and automatically protects sensitive information across Microsoft 365 workloads such as Exchange, SharePoint, OneDrive, and Teams. It does not inspect or control Azure infrastructure resources like VMs or containers, nor is it part of Microsoft Defender for Cloud's workload protection pillar. DLP focuses on data plane compliance and information governance, not service-plane security controls.
- ✓
File Integrity Monitoring (FIM)
Why this is correct
File Integrity Monitoring (FIM) in Microsoft Defender for Cloud tracks changes to critical operating system files, registry hives, and software installations to detect unauthorized modifications that could signal an attack or malware. FIM relies on a baseline snapshot of system state and then compares subsequent changes, surfacing them as alerts that can be integrated with Microsoft Sentinel or Defender for Cloud's security console. This is a explicit workload protection feature and is therefore one of the three correct responses.
- ✓
Just-in-time (JIT) VM access
Why this is correct
Just-in-time (JIT) VM access is a security control in Microsoft Defender for Cloud that restricts inbound traffic to management ports such as SSH and RDP, granting access only upon an authorized user request with a time-limited window and an approved source IP range. JIT enforces its rules through Azure Firewall or network security groups, logging every request and access grant for auditing. This is a core workload protection capability, confirming it as one of the correct answers.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.