AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You administer an Azure environment with Microsoft Defender for Cloud enabled. A security analyst reports that a suspicious process was executed on a virtual machine, but no alert was found in the portal. You need to ensure that Defender for Cloud can detect and alert on suspicious activities on the VM. What should you do?
⚠ Common exam trap
The trap here is assuming that any logging agent or custom alert rule will provide the same depth of threat detection as the built-in Defender for Servers plan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the Microsoft Defender for Servers plan is enabled and that the Azure Monitor Agent is installed on the VM.
To detect suspicious process execution on a VM, Defender for Cloud must have the Defender for Servers plan enabled, which deploys the Azure Monitor Agent and integrates with Microsoft Defender for Endpoint. This combination provides deep endpoint detection and response capabilities, including process-level monitoring. Other options either use outdated agents or focus on network controls, which do not fulfill the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a custom alert rule in Azure Monitor to trigger on specific process creation events.
Why it's wrong here
Azure Monitor custom alert rules can monitor specific events but do not provide the integrated threat intelligence, machine learning, and behavioral detection that Defender for Cloud offers. They would require manual definition of every suspicious process and cannot correlate with other signals. This approach is reactive and lacks the comprehensive security analytics needed for effective threat detection.
- ✗
Enable the Log Analytics agent and configure a data collection rule to forward Security events.
Why it's wrong here
The Log Analytics agent is deprecated for Defender for Cloud and does not provide the deep kernel-level monitoring required for process-level threat detection. While it can forward Security events, it lacks the behavioral sensors needed to detect suspicious process execution. The modern approach is to use the Defender for Servers plan with the Azure Monitor Agent, which includes the necessary extensions for advanced threat detection.
- ✓
Ensure the Microsoft Defender for Servers plan is enabled and that the Azure Monitor Agent is installed on the VM.
Why this is correct
Defender for Servers provides advanced threat detection for VMs, including process-level monitoring and behavioral analytics. The Azure Monitor Agent, when deployed via the plan, installs the required extensions (such as the Defender for Endpoint sensor) to collect and analyze security events. Without this plan and agent, process execution events may not be captured, and alerts will not be generated.
- ✗
Enable just-in-time (JIT) VM access to restrict inbound traffic and log connection attempts.
Why it's wrong here
JIT VM access reduces the attack surface by allowing access only when needed, but it does not detect or alert on suspicious processes running on the VM. It focuses on network access control, not endpoint behavioral monitoring. While it can log connection attempts, it will not provide the process-level telemetry required to identify malicious activity on the operating system.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.