Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Which TWO security controls are automatically provided by enabling Microsoft Defender for Cloud's foundational CSPM (Cloud Security Posture Management) capabilities? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Continuous assessment of Azure resources against the Microsoft cloud security benchmark.

Option C is correct because the foundational CSPM plan in Microsoft Defender for Cloud continuously assesses Azure resources against the Microsoft cloud security benchmark (MCSB), producing a secure score and compliance view without any additional agent or paid plan. Option D is correct because the same foundational CSPM capabilities generate security recommendations for Azure resources based on those assessments, guiding remediation of misconfigurations. Options A, B, and E are not part of the free foundational CSPM offering: Azure Firewall Manager integration is a separate networking service, just-in-time VM access requires the paid Defender for Servers plan (Plan 2), and vulnerability assessment for VMs is also provided by Defender for Servers rather than by foundational CSPM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Firewall Manager integration.

    Why it's wrong here

    Azure Firewall Manager is a centralized network security management service for deploying and managing Azure Firewall and Web Application Firewall policies across hub-and-spoke architectures. It is not a manifest control of Microsoft Defender for Cloud's foundational CSPM; rather, it is an optional, separately configured service that customers deploy for network segmentation. Foundational CSPM focuses on resource posture assessment, not on orchestrating firewall policies, so this integration is not automatically provided.

  • ✗

    Just-in-time (JIT) VM access.

    Why it's wrong here

    Just-in-time (JIT) VM access is an enhanced Microsoft Defender for Cloud capability that locks down inbound traffic to VMs and gates RDP/SSH access via role-based approvals. This feature is only available after you enable the paid Defender for Servers plan; it is not part of the free foundational CSPM tier. Foundational CSPM delivers continuous assessment and recommendations, not active network hardening like JIT, so it cannot be considered an automatically provided control.

  • ✓

    Continuous assessment of Azure resources against the Microsoft cloud security benchmark.

    Why this is correct

    The foundational cloud security posture management (CSPM) tier in Microsoft Defender for Cloud provides continuous assessment of all supported Azure resources against the Microsoft cloud security benchmark (MCSB), a comprehensive set of security best-practice controls aligned with industry standards. This assessment runs automatically for every onboarded Azure subscription and drives the secure score and compliance dashboards without any additional configuration or licensing. As a built-in, always-on capability, this is a correct answer.

  • ✓

    Security recommendations for Azure resources.

    Why this is correct

    Security recommendations for Azure resources are a core output of Microsoft Defender for Cloud's free CSPM tier, generated from continuous assessment of resource configurations and compliance with the Microsoft cloud security benchmark. These recommendations are automatically produced and presented in the Defender for Cloud portal, with actionable remediation steps, making them an inherent control of foundational CSPM. Since they require no additional paid plan, they qualify as automatically provided security controls.

  • ✗

    Vulnerability assessment for VMs.

    Why it's wrong here

    Vulnerability assessment for VMs—whether using the Qualys-based scanner or Microsoft Defender Vulnerability Management—does not run automatically under the free foundational CSPM tier. It is an add-on capability that requires the Microsoft Defender for Servers plan to be enabled, and even then, it must be explicitly configured and deployed to your VMs. Therefore, it is an enhanced, paid security feature rather than an automatically provided foundational control.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.