Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your company uses Microsoft Defender for Cloud's 'Vulnerability Assessment' solution for Azure VMs. You have enabled the 'Microsoft Defender for Servers' plan and deployed the integrated Qualys agent. You need to view the vulnerability assessment findings for all VMs in a single dashboard in Microsoft Defender for Cloud. Which blade in the Defender for Cloud portal should you navigate to?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Recommendations

The correct option is D, Recommendations. In Microsoft Defender for Cloud, vulnerability assessment findings from the integrated Qualys agent (part of the Defender for Servers plan) are surfaced as security recommendations, so navigating to the Recommendations blade lets you view and filter findings such as 'Vulnerabilities in your virtual machines should be remediated' across all VMs in one place. The Inventory blade only lists resources and their security posture, not aggregated vulnerability findings. Security alerts shows active threat detections rather than vulnerability assessment results. Regulatory compliance maps controls to standards and does not present the raw vulnerability findings dashboard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inventory

    Why it's wrong here

    The Inventory blade in Microsoft Defender for Cloud provides a resource-centric view listing all monitored resources and their metadata, such as resource group, subscription, and cloud. It does not expose the underlying vulnerability assessment details like CVE IDs or patch status, because those are stored as health findings attached to specific recommendations. Consequently, users cannot see vulnerability data in Inventory; it only helps locate resources for security context.

  • ✗

    Security alerts

    Why it's wrong here

    Security alerts in Defender for Cloud are generated by the cloud workload protection layer when runtime threat signals are detected, such as suspicious PowerShell or anomalous network traffic. Vulnerability assessment findings, by contrast, come from scheduled queries/agents that scan installed software and report missing patches; they are not threat detections. Alerts include incident triage details and MITRE ATT&CK techniques, whereas vulnerability findings are CVE-based and appear as recommendation health results.

  • ✗

    Regulatory compliance

    Why it's wrong here

    The Regulatory Compliance dashboard maps compliance controls to standards like CIS and NIST, showing pass/fail status at a policy level. It aggregates assessments into compliance findings, but it does not display the individual vulnerability artifacts—like specific affected packages and remediation steps—that make up those assessment results. Its purpose is posture against standards, not detailed vulnerability remediation data.

  • ✓

    Recommendations

    Why this is correct

    In Defender for Cloud, every vulnerability assessment result is represented as a recommendation; the 'Remediate vulnerabilities' recommendation contains all discovered findings across your machines. When you open it, you see affected resources, CVE IDs, severity scores, and remediation guidance, and the findings update as scans complete. This is the dedicated location where vulnerability data is surfaced for action.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.