AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Which TWO features are available in Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) capabilities? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse workload protection features (like JIT VM access and vulnerability assessment) with CSPM capabilities, which are specifically about cloud configuration posture and risk analysis, not runtime or endpoint security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attack path analysis
Attack path analysis is a CSPM capability in Microsoft Defender for Cloud that identifies the most likely sequences of actions an attacker could take to breach critical resources. It uses a graph-based model of your cloud environment to map dependencies and misconfigurations, enabling proactive risk mitigation. This is a core part of the Cloud Security Posture Management (CSPM) pillar, not a workload protection feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attack path analysis
Why this is correct
Attack path analysis is a cloud security posture management (CSPM) capability in Microsoft Defender for Cloud that builds a graph of your cloud resources and identifies chains of misconfigurations, exposed credentials, and weak network controls that could allow an attacker to reach a critical asset. Each path is scored and visualized so security teams can prioritize a small number of fixes that break multiple high-risk attack routes. This feature belongs to the posture-management pillar, not to workload protection.
- ✓
Security governance and compliance scoring
Why this is correct
Security governance and compliance scoring is a CSPM feature in Defender for Cloud that continuously evaluates your Azure, hybrid, and multicloud resources against the Microsoft cloud security benchmark and regulatory standards. It produces a secure score and compliance dashboard that lets you assign remediation ownership, track progress, and enforce governance through target metrics and policy. This is fundamentally different from workload protection because it assesses the configuration and compliance of resources rather than their runtime threat exposure.
- ✗
Just-in-time VM access
Why it's wrong here
Just-in-time (JIT) VM access is a workload protection feature in Microsoft Defender for Cloud, typically associated with Defender for Servers, that controls inbound traffic to management ports such as RDP and SSH by opening them only when an authorized user requests access and only for a specified time window. It reduces the attack surface of a running VM, but it does not evaluate cloud misconfigurations, attack paths, or compliance posture. Therefore, it falls outside the CSPM feature set that this question targets.
- ✗
User and Entity Behavior Analytics (UEBA)
Why it's wrong here
User and Entity Behavior Analytics (UEBA) is an identity and security analytics capability that exists in Microsoft Sentinel and Microsoft Defender for Identity, where it baselines normal user and entity behavior and detects anomalous activities such as account compromise and lateral movement. Defender for Cloud's CSPM engine does not provide UEBA because it is not focused on user behavior; it focuses on resource configuration and posture. This makes UEBA an incorrect choice for a Defender for Cloud CSPM feature.
- ✗
Vulnerability assessment for VMs
Why it's wrong here
Vulnerability assessment for VMs in Defender for Cloud is delivered through the workload protection plan Defender for Servers (via Microsoft Defender Vulnerability Management or Qualys) and continuously scans the guest operating system, installed applications, and missing patches to generate CVE-based findings. Although the findings appear in Defender for Cloud recommendations, the capability is classified as workload protection because it inspects the VM's runtime state rather than cloud control-plane configuration. Thus, it is not part of the CSPM feature set in this question.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.