AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are configuring Microsoft Defender for Cloud's 'Workload protections' for a Kubernetes cluster that is already using Azure Kubernetes Service (AKS). The cluster has 'Azure Policy' enabled. You need to enable the 'Microsoft Defender for Containers' plan to protect the cluster. You have already enabled the plan at the subscription level. However, the cluster is not showing as protected in the 'Inventory' blade. You have confirmed that the 'Azure Policy for Kubernetes' add-on is installed. What should you do to ensure the cluster is protected?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the 'Defender profile' on the AKS cluster.
Even with the subscription-level plan enabled, you need to install the 'Defender profile' on the AKS cluster to enable protection. The Defender profile deploys the necessary agents for threat detection. Option A is correct. Option B is incorrect because Azure Policy for Kubernetes is already enabled; it is a separate feature. Option C is incorrect because protection does not automatically apply; you must install the profile. Option D is incorrect because the Log Analytics agent is not required for Defender for Containers; the Defender profile handles agent deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Install the 'Defender profile' on the AKS cluster.
Why this is correct
Installing the Defender profile is the correct action because Microsoft Defender for Cloud’s Defender for Containers plan uses a dedicated DaemonSet on each AKS node to collect security signals such as Kubernetes audit logs, node events, and container runtime telemetry. The profile must be explicitly enabled on the cluster; enabling the plan at the subscription level alone does not protect existing clusters. Without this profile, the cluster remains visible in Defender for Cloud but lacks workload-level threat detection.
- ✗
Enable the 'Azure Policy for Kubernetes' add-on on the cluster.
Why it's wrong here
The Azure Policy for Kubernetes add-on, which is already installed in this scenario, enforces admission control through Gatekeeper and is used for compliance, not for security telemetry. It evaluates requests against policies like 'no privileged containers' but does not monitor running workloads or provide runtime threat detection. Installing or re-enabling this add-on would not replace the Defender profile, as its purpose is policy enforcement, not Defender for Containers protection.
- ✗
Wait for 24 hours for the protection to automatically apply.
Why it's wrong here
Waiting for automatic protection is ineffective because Defender for Cloud's auto-provisioning at the subscription level only applies to newly created AKS clusters, not to existing ones already running. Existing clusters require a manual step to install the Defender profile, regardless of how long you wait, unless you have explicitly configured auto-provisioning for new clusters. Even when auto-provisioning is enabled, it doesn't retroactively protect an existing cluster that was created before the setting was turned on.
- ✗
Install the Log Analytics agent on the cluster nodes.
Why it's wrong here
The Log Analytics agent (Microsoft Monitoring Agent) is not the correct choice for AKS container protection because Defender for Containers uses a dedicated Defender profile and the Azure Monitor Agent to collect node and workload signals. The MMA, while useful for VM log analytics, does not capture Kubernetes-specific security data such as kubernetes.audit events or container runtime anomalies. Moreover, the Defender profile is not equivalent to the MMA, so installing the agent would leave the cluster without the required workload protection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.