AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are evaluating Microsoft Defender for Cloud's cloud security posture management (CSPM) capabilities. You need to identify misconfigurations across your Azure, AWS, and GCP environments. What should you enable?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Sentinel's log ingestion with Defender for Cloud's CSPM capabilities, assuming that any multicloud security requires a SIEM, when in fact Defender for Cloud's native connector provides the required posture management without Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Defender for Cloud' multicloud connector for AWS and GCP.
The Defender for Cloud multicloud connector is specifically designed to ingest security findings and configuration data from AWS and GCP into Microsoft Defender for Cloud's CSPM dashboard. This enables unified visibility and assessment of misconfigurations across Azure, AWS, and GCP environments without requiring agents or log ingestion into Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ingest logs from AWS and GCP into Microsoft Sentinel.
Why it's wrong here
Microsoft Sentinel is Microsoft's cloud-native SIEM (Security Information and Event Management) platform, designed to ingest and correlate log/telemetry data for threat detection, investigation, and response. While connectors exist to pull audit and activity logs from AWS and GCP, Sentinel does not perform continuous security posture assessment—it cannot discover misconfigurations in S3 buckets, GCS storage, IAM policies, or Kubernetes clusters and quantify their compliance against standards like CIS. The question asks for multicloud CSPM, not log analytics, so simply ingesting logs into Sentinel fails to remediate or even surface configuration drift across AWS and GCP services.
- ✗
Create Azure Policy assignments for AWS and GCP resources.
Why it's wrong here
Azure Policy is Azure's native governance control plane, enforcing rules via Azure Resource Manager on resources within Azure subscriptions, resource groups, and management groups. It cannot evaluate resources outside Azure because AWS and GCP resources are not represented as ARM resource types and do not emit Azure-compatible compliance state; AWS has its own AWS Config/Organizations policies and GCP has Organization Policies and Asset Inventory. Creating Azure Policy assignments for AWS and GCP would result in non-evaluatable scopes or complete non-compliance, providing no actual security assessment. Even Azure Arc does not convert cloud services like S3 or GCS into Azure resources, so this approach cannot deliver cross-cloud CSPM.
- ✗
Deploy Azure Arc on VMs in AWS and GCP.
Why it's wrong here
Azure Arc extends the Azure management plane to hybrid and multicloud virtual machines, enabling inventory, patch management, tagging, and policy assignment on server OSs outside Azure. However, Arc is workload-oriented—it governs the VM itself (OS config, installed software, monitoring) but has no visibility into the surrounding cloud platform's managed services, such as AWS S3, RDS, Lambda, GCP Cloud Storage, or IAM role/trust policies. Deploying Arc on AWS and GCP VMs would therefore miss storage misconfigurations, open security groups, overprivileged service accounts, and other cloud-resource-level exposures. Defender for Cloud's multicloud connector natively scans those managed services via cloud APIs, which is the required capability here.
- ✓
Enable the 'Defender for Cloud' multicloud connector for AWS and GCP.
Why this is correct
Microsoft Defender for Cloud provides multicloud CSPM via its connector feature: in the Azure Portal, you enable the AWS connector (using a CloudFormation template and cross-account role) or GCP connector (using a service account) to on-board your entire cloud environments. Once connected, Defender for Cloud continuously pulls resource configuration and workload telemetry using AWS Config/AWS Security Hub and GCP Cloud Asset Inventory, then applies built-in security standards (e.g., CIS, NIST, Azure Security Benchmark) to generate recommendations and compliance scores across AWS, GCP, and Azure. This native multicloud connector also enables advanced threat protection features such as attack path analysis and cloud security explorer, making it the only listed option that fulfills multicloud CSPM.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.