Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your company, Contoso Ltd., has a hybrid environment with 500 on-premises Windows servers and 200 Azure VMs. The Azure VMs are spread across multiple subscriptions. You need to implement a centralized security monitoring solution using Microsoft Sentinel. The requirements are: - Collect security events from all on-premises servers. - Collect Azure activity logs and VM logs from all Azure subscriptions. - Detect and respond to threats using built-in and custom analytics. - Automatically remediate common threats such as disabling compromised user accounts. - Ensure compliance with regulatory standards (e.g., NIST 800-53). - Minimize administrative overhead and cost.

What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Azure Arc on all on-premises servers. Use Azure Monitor Agent with Data Collection Rules to collect security events. Enable Microsoft Sentinel on a Log Analytics workspace. Configure analytics rules and automation rules with playbooks for remediation.

It uses Azure Arc to onboard the 500 on-premises Windows servers into Azure, then Azure Monitor Agent (AMA) with Data Collection Rules (DCRs) to collect Windows security events into a Log Analytics workspace where Microsoft Sentinel is enabled; Sentinel's analytics rules provide built-in and custom threat detection, and automation rules with playbooks (Logic Apps) deliver automated remediation such as disabling compromised accounts, while Sentinel's compliance workbook and built-in NIST 800-53 content address regulatory requirements. This approach centralizes monitoring across all subscriptions and on-premises servers with minimal administrative overhead. Option A is outdated because the Microsoft Monitoring Agent (MMA) is deprecated in favor of AMA, and it lacks the Arc-based onboarding and DCR-based collection needed for modern hybrid coverage. Option B does not meet the requirement for Microsoft Sentinel, since it forwards logs to a third-party SIEM instead. Option C relies on manual remediation and the Sentinel Free tier, which has limited data ingestion and retention, so it does not satisfy automated remediation or compliance needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install Microsoft Monitoring Agent on on-premises servers and connect to a Log Analytics workspace. Enable Sentinel. Use Azure Automation runbooks for remediation.

    Why it's wrong here

    The Microsoft Monitoring Agent (MMA) is deprecated and does not support Data Collection Rules; the legacy Log Analytics agent cannot deliver the DCR-based, table-specific security event collection required by Sentinel. Azure Automation runbooks are not integrated with Sentinel's incident management pipeline, whereas automation rules and playbooks provide native SOAR capabilities. This option also omits Azure Arc, so on-premises servers remain unrepresented as Azure resources for unified identity, policy, and Defender for Cloud posture.

  • ✗

    Enable Microsoft Defender for Cloud on all subscriptions and install Defender for Endpoint on all servers. Forward logs to a third-party SIEM.

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform, not a SIEM. It provides recommendations, vulnerability assessments, and Defender plans, but lacks Sentinel's KQL analytics rules, incident management, UEBA, and threat-hunting capabilities. Installing Defender for Endpoint alone secures endpoints but does not collect and normalize security events from all sources for correlation. Forwarding logs to a third-party SIEM adds licensing, infrastructure, and operational overhead while bypassing Sentinel's native threat intelligence and automation connectors.

  • ✗

    Create a Log Analytics workspace and enable Sentinel on the Free tier. Use KQL queries for detection and manual remediation.

    Why it's wrong here

    This approach is invalid because Microsoft Sentinel does not support the legacy Free tier of Log Analytics; Sentinel requires a paid workspace to enable analytics rules, automation, retention, and full feature availability. Even if the Free tier were somehow used, the associated data ingestion caps and limited retention would make continuous, compliant security monitoring impractical. Manual KQL queries without automation rules or playbooks mean incidents will only be triaged and remediated manually, which fails to meet the automated detection and response requirements of a modern SOC.

  • ✓

    Deploy Azure Arc on all on-premises servers. Use Azure Monitor Agent with Data Collection Rules to collect security events. Enable Microsoft Sentinel on a Log Analytics workspace. Configure analytics rules and automation rules with playbooks for remediation.

    Why this is correct

    Deploying Azure Arc gives on-premises servers an Azure Resource Manager identity, allowing them to be governed with Azure Policy, Defender for Cloud, and Data Collection Rules just like Azure VMs. Azure Monitor Agent, configured via Data Collection Rules, efficiently collects Windows and Linux security events and forwards them to a Log Analytics workspace where Microsoft Sentinel ingests and analyzes them. Sentinel analytics rules detect threats and generate incidents, while automation rules trigger Azure Logic Apps playbooks for consistent, automated remediation. This is the current, fully supported hybrid SIEM/SOAR design that unifies on-premises and cloud security operations.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.