Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your company has a hybrid environment with on-premises servers and Azure VMs. All resources are onboarded to Microsoft Defender for Cloud. You need to receive alerts when a critical vulnerability is detected on any server. The security team wants to minimize false positives. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse vulnerability detection (finding CVEs) with other security controls like access restriction (JIT), application whitelisting (AAC), or change monitoring (FIM), all of which address different threat vectors and do not directly alert on critical vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable vulnerability assessment for servers via the integrated VA solution.

Microsoft Defender for Cloud's integrated vulnerability assessment (VA) solution, powered by Qualys or Microsoft Defender Vulnerability Management, continuously scans servers for known CVEs and generates security alerts when critical vulnerabilities are found. This directly meets the requirement to receive alerts on critical vulnerabilities while minimizing false positives, as the VA solution uses curated, verified vulnerability data rather than heuristic or behavioral detections that might produce noise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable vulnerability assessment for servers via the integrated VA solution.

    Why this is correct

    The integrated vulnerability assessment (VA) solution in Microsoft Defender for Cloud, powered by Qualys, performs agent-based scans of the OS and installed software to identify missing patches, insecure configurations, and known Common Vulnerabilities and Exposures (CVEs). It surfaces these findings as security recommendations and can generate alerts when discovered vulnerabilities align with known attack vectors. For on-premises and hybrid servers, you must first onboard them to Azure Arc and enable the Defender for Servers plan so the VA scanner can report to the cloud workload-protection dashboard.

  • ✗

    Configure just-in-time VM access to reduce attack surface.

    Why it's wrong here

    Just-in-time (JIT) VM access reduces the attack surface by locking down management-port (e.g., RDP/SSH) network access with time-boxed NSG allow rules, so ports stay closed until an authorized request opens them. While this lowers exposure to network-based attacks, it does not inspect the server for any pre-existing vulnerabilities or generate vulnerability assessment findings. The JIT feature is a network control, not a detection/assessment capability, so it cannot satisfy a requirement to identify vulnerabilities on servers.

  • ✗

    Enable adaptive application controls to detect unapproved software.

    Why it's wrong here

    Adaptive application controls (AAC) use machine learning to build an allowlist of trusted executables and enforce it, blocking unapproved applications, scripts, and installers from running. This is a host-based application control or whitelisting measure that helps prevent malware execution, but it does not scan for known vulnerabilities or missing patches. Because AAC is about controlling which binaries can execute rather than assessing the system's security state, it is not a vulnerability-assessment tool.

  • ✗

    Enable file integrity monitoring on critical files.

    Why it's wrong here

    File integrity monitoring (FIM) watches critical system files, registry keys, and configuration files for modifications, comparing current state against a clean baseline and raising alerts when unauthorized changes occur. It answers 'did someone change something important?', not 'what weaknesses or missing patches exist?'. FIM is therefore a compliance and attack-detection aid, not a vulnerability scanner, so it cannot detect the absence of security fixes.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.