AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your company has multiple Azure subscriptions and wants to use Microsoft Sentinel as a SIEM. You need to collect security events from all Azure VMs, including existing and future ones. What should you use?
⚠ Common exam trap
A common mix-up: candidates confuse manual or automation-based agent installation (options A, B, C) with the policy-driven, at-scale deployment that Azure Policy provides, which is the only method that automatically covers both existing and future resources without ongoing manual effort.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Policy assignment to deploy the Log Analytics agent.
Azure Policy can automatically deploy the Log Analytics agent to all existing and future Azure VMs via the 'Deploy Log Analytics agent for Windows/Linux VMs' built-in policy. This ensures consistent security event collection for Microsoft Sentinel without manual intervention, scaling across multiple subscriptions and VM lifecycles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Azure portal to enable 'Security Center' on each VM.
Why it's wrong here
Enabling Security Center (now Microsoft Defender for Cloud) from the Azure portal is a manual, per-subscription or per-resource action; it does not automatically deploy the Log Analytics agent to each VM. To collect security telemetry, the agent must still be installed separately or via a policy, and portal steps cannot be scaled across hundreds of VMs or future resources without additional automation.
- ✗
Use Azure Automation Desired State Configuration (DSC) to push the agent.
Why it's wrong here
Azure Automation DSC can use a configuration script to install the Log Analytics agent, but it requires each VM to be onboarded as a DSC node and does not automatically apply the configuration to new VMs created after the solution is deployed. For an environment with many VMs across multiple subscriptions, DSC would require targeting individual machines and managing node configurations, making it less comprehensive and more operationally burdensome than a built-in Azure Policy with a deployIfNotExists effect.
- ✗
Manually install the Log Analytics agent on each VM.
Why it's wrong here
Manually installing the Log Analytics agent on every VM is a one-time, ad-hoc operation that is not repeatable or auditable at scale. It creates no governance control: if any VM is created later, it will be missed, and there is no mechanism to monitor compliance or remediate missing agents. Manual installation also provides no consistent workspace connectivity or configuration drift detection across heterogeneous environments.
- ✓
Create an Azure Policy assignment to deploy the Log Analytics agent.
Why this is correct
Creating an Azure Policy assignment using a built-in definition such as 'Deploy Log Analytics agent to Windows VMs' automatically installs the agent on both existing and future VMs in the assigned scope via a deployIfNotExists effect. This approach centralizes governance at the subscription or management group level, requires only a Log Analytics workspace ID as a parameter, and continuously enforces compliance without human intervention.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.