Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You need to enable Microsoft Defender for Cloud's workload protection for Azure Kubernetes Service (AKS) clusters. Which Defender plan should you enable?

⚠ Common exam trap

Test-takers frequently confuse the foundational CSPM plan (which provides basic security recommendations) with the workload-specific Defender plans, mistakenly thinking CSPM alone can protect AKS workloads when it only offers posture visibility without runtime threat detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Defender for Containers.

To enable workload protection for Azure Kubernetes Service (AKS) clusters in Microsoft Defender for Cloud, you must enable the Defender for Containers plan. This plan provides runtime threat detection, vulnerability assessment, and compliance monitoring specifically for containerized environments, including AKS, Azure Container Registry (ACR), and Azure Container Instances (ACI). It covers Kubernetes audit logs, host-level security, and container image scanning, which are essential for securing AKS workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the foundational Cloud Security Posture Management (CSPM) plan.

    Why it's wrong here

    The foundational CSPM plan is always available as the free tier in Microsoft Defender for Cloud and focuses on continuous assessment of your environment’s security posture through recommendations, secure score, and compliance checks. It does not turn on any of the paid Defender plans that deliver runtime workload protection, nor does it produce the Kubernetes-specific threat detections needed for AKS. Enabling CSPM alone therefore leaves a container workload without agent-based or control-plane threat monitoring.

  • ✗

    Enable Defender for SQL.

    Why it's wrong here

    Defender for SQL is a separate Defender plan scoped exclusively to Azure SQL Database, Azure SQL Managed Instance, and SQL Server on machines. Its threat protection, vulnerability assessment, and data-discovery features are directed at the database engine and nothing else. Enabling it does nothing for an AKS cluster's control plane, nodes, or running containers, so it cannot satisfy the need for container workload protection.

  • ✓

    Enable Defender for Containers.

    Why this is correct

    Enabling Defender for Containers is the appropriate plan because it is specifically architected for Kubernetes and AKS, integrating Kubernetes audit logs, control-plane insight, runtime threat detection for workloads, and image vulnerability assessment. At the cluster level it monitors the Kubelet, etcd, and API server while also analyzing behaviors in running containers via the Defender agent (or Azure Arc for hybrid clusters). This single plan provides the runtime protection for container workloads that the scenario requires.

  • ✗

    Enable Defender for Servers.

    Why it's wrong here

    Defender for Servers is designed to protect infrastructure VMs and hosts through Microsoft Defender for Endpoint integration, file integrity monitoring, and OS-level threat detection. While AKS node virtual machines receive some OS visibility if this plan is enabled, it does not monitor the Kubernetes control plane, pod-to-pod traffic, container runtime activity, or image registries. Container-specific telemetry is only gathered by Defender for Containers, so this option is insufficient for the stated workload.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.