AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You need to ensure that all Azure subscriptions in your tenant are automatically assessed for security misconfigurations and compliance against Microsoft cloud security benchmark. What should you configure?
⚠ Common exam trap
The trap is confusing Azure Policy initiatives (which enforce compliance) with Defender for Cloud's continuous export (which streams assessment data). The benchmark assessment is triggered by assigning the built-in Azure Policy initiative, not by continuous export.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign an initiative via Azure Policy to all subscriptions
The Microsoft cloud security benchmark is a built-in initiative in Azure Policy. By assigning this initiative to all subscriptions, you automatically assess them for security misconfigurations and compliance. Defender for Cloud uses these policies, but ensuring the assessment requires the initiative assignment. Option C is incorrect because enabling continuous export only streams completed assessment data; it does not trigger the assessment itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Microsoft Sentinel with automatic data connectors
Why it's wrong here
Deploying Microsoft Sentinel with automatic data connectors ingests security logs from Azure services and third-party sources into a SIEM for threat detection, hunting, and incident response. However, Sentinel does not evaluate Azure resources against the Microsoft cloud security benchmark; it does not execute configuration audits nor produce compliance scores for subscriptions. At best, Sentinel can consume recommendations exported from Defender for Cloud, making it a downstream consumer of compliance data rather than the mechanism that ensures assessment.
- ✓
Assign an initiative via Azure Policy to all subscriptions
Why this is correct
Assigning the built-in Microsoft cloud security benchmark initiative through Azure Policy to all subscriptions is the correct and native way to ensure ongoing assessment. This initiative bundles dozens of policy definitions that audit and enforce security controls, such as encryption, network security, and identity management, and Azure Policy continuously evaluates resources against these rules without additional deployment. Assigning the initiative at the subscription scope triggers immediate compliance assessment and produces a compliance report that can be monitored in Defender for Cloud.
- ✗
Enable continuous export in Microsoft Defender for Cloud
Why it's wrong here
Enabling continuous export in Microsoft Defender for Cloud configures streaming of security findings, alerts, and recommendations to a Log Analytics workspace or Event Hub. This setting merely forwards assessment results that already exist; it does not generate or trigger the underlying configuration assessments. To evaluate subscriptions against the Microsoft cloud security benchmark, you must first enable the relevant Defender plans or assign the built-in policy initiative, after which continuous export can be used to feed downstream automation like SIEM integration.
- ✗
Create a blueprint definition and assign it to management group
Why it's wrong here
Creating a blueprint definition and assigning it to a management group orchestrates the deployment of ARM templates, roles, and resource groups, but it does not by itself perform ongoing compliance assessment. Azure Blueprints is a packaging and deployment service, not an evaluation engine; without explicitly including a policy initiative in the blueprint, no automatic audit of subscription resources occurs. Furthermore, blueprint assignment is a one-time action that does not continuously re-evaluate resources the way Azure Policy does.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.