AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are the security engineer for a multinational company that uses Azure to host critical workloads. The company has deployed Microsoft Defender for Cloud with the enhanced security features enabled on all subscriptions. Recently, a security audit revealed that several virtual machines (VMs) in the production environment are missing critical security updates. The audit report indicates that the VMs are not being assessed for missing updates by Defender for Cloud. You need to ensure that all VMs are automatically assessed for missing OS updates using Defender for Cloud's vulnerability assessment capabilities. The solution must minimize administrative overhead and should not require manual installation of agents on existing VMs. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Servers' plan in Defender for Cloud and ensure that the 'Vulnerability assessment for machines' setting is turned on.
The key concept is that Defender for Cloud's 'Servers' plan (Defender for Servers) bundles a built-in vulnerability assessment engine, Microsoft Defender Vulnerability Management (MDVM), which can be enabled with the 'Vulnerability assessment for machines' toggle. This setting configures automatic, continuous scanning of Azure and hybrid machines for missing operating system updates, application vulnerabilities, and misconfigurations. A subtle but critical detail is that the Microsoft VA engine does not require an additional agent on the VM; it uses the Defender for Cloud agent infrastructure, and the 'vulnerability assessment for machines' policy can auto-install necessary extensions. This contrasts with the legacy approach of deploying a separate Qualys/Rapid7 solution, which requires manual lifecycle management. A common misconception is that the 'SQL servers on machines' plan covers OS-level assessment; it actually only addresses SQL Server-specific security issues. Real-world implications include the fact that enabling the toggle at the subscription level automatically remediates gaps across all connected machines, substantially reducing operational effort compared to third-party scanners.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the 'SQL servers on machines' plan in Defender for Cloud.
Why it's wrong here
The 'SQL servers on machines' plan in Defender for Cloud is scoped specifically to SQL Server instances running on Azure VMs, on-premises machines, and other cloud platforms. Its purpose is to surface SQL-specific vulnerabilities, misconfigurations, and threat detections such as brute force attacks or suspicious SQL activity. It does not perform Windows or Linux operating system-level missing update assessment, so it would not address the stated requirement of identifying OS-level missing updates on the VMs.
- ✓
Enable the 'Servers' plan in Defender for Cloud and ensure that the 'Vulnerability assessment for machines' setting is turned on.
Why this is correct
Enabling the 'Servers' plan (Microsoft Defender for Servers) and turning on the 'Vulnerability assessment for machines' setting activates the built-in Microsoft Defender Vulnerability Management (MDVM) scanning capability. This integration automatically discovers installed software, missing OS patches, and configuration vulnerabilities across Azure and hybrid VMs without requiring you to manually deploy a separate VA scanner on each machine. The resulting recommendations are surfaced in Defender for Cloud, directly satisfying the requirement to assess VMs for missing updates with minimal administrative overhead.
- ✗
Configure a vulnerability assessment solution from the Azure Marketplace and assign it to the VMs.
Why it's wrong here
Choosing a third-party vulnerability assessment solution from the Azure Marketplace, such as Qualys or Rapid7, would require you to manually create the solution, deploy agents to every VM, manage credentials, and maintain a separate console for scanning and reporting. These extra steps increase administrative overhead and often duplicate the scanning and dashboard capabilities already provided by Defender for Cloud's native VA integration. While such a solution could technically detect missing updates, it is not the simplest or most integrated way to meet the requirement.
- ✗
Deploy the Log Analytics agent to all VMs using Azure Policy.
Why it's wrong here
Deploying the Log Analytics agent (or Azure Monitor agent) to all VMs via Azure Policy ensures that telemetry, performance counters, and event logs are forwarded to a Log Analytics workspace, but the agent itself is not a vulnerability scanner. Without an accompanying vulnerability assessment solution such as Microsoft Defender Vulnerability Management, Qualys, or Rapid7, the agent cannot generate the missing-update inventory or patch-state data that would inform security recommendations. Therefore, this action alone would leave your OS update assessment requirement unmet.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company has a hybrid environment with on-premises servers and Azure VMs. All resources are onboarded to Microsoft Defender for Cloud. You need to receive alerts when a critical vulnerability is detected on any server. The security team wants to minimize false positives. What should you configure?
medium- ✓ A.Enable vulnerability assessment for servers via the integrated VA solution.
- B.Configure just-in-time VM access to reduce attack surface.
- C.Enable adaptive application controls to detect unapproved software.
- D.Enable file integrity monitoring on critical files.
Why A: Microsoft Defender for Cloud's integrated vulnerability assessment (VA) solution, powered by Qualys or Microsoft Defender Vulnerability Management, continuously scans servers for known CVEs and generates security alerts when critical vulnerabilities are found. This directly meets the requirement to receive alerts on critical vulnerabilities while minimizing false positives, as the VA solution uses curated, verified vulnerability data rather than heuristic or behavioral detections that might produce noise.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.