AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your company uses Microsoft Defender for Cloud's 'Vulnerability Assessment' solution for Azure VMs. You have enabled the 'Microsoft Defender for Servers' plan and deployed the integrated Qualys agent. You need to view the vulnerability assessment findings for all VMs in a single dashboard in Microsoft Defender for Cloud. Which blade in the Defender for Cloud portal should you navigate to?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recommendations
The correct option is D, Recommendations. In Microsoft Defender for Cloud, vulnerability assessment findings from the integrated Qualys agent (part of the Defender for Servers plan) are surfaced as security recommendations, so navigating to the Recommendations blade lets you view and filter findings such as 'Vulnerabilities in your virtual machines should be remediated' across all VMs in one place. The Inventory blade only lists resources and their security posture, not aggregated vulnerability findings. Security alerts shows active threat detections rather than vulnerability assessment results. Regulatory compliance maps controls to standards and does not present the raw vulnerability findings dashboard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inventory
Why it's wrong here
The Inventory blade in Microsoft Defender for Cloud provides a resource-centric view listing all monitored resources and their metadata, such as resource group, subscription, and cloud. It does not expose the underlying vulnerability assessment details like CVE IDs or patch status, because those are stored as health findings attached to specific recommendations. Consequently, users cannot see vulnerability data in Inventory; it only helps locate resources for security context.
- ✗
Security alerts
Why it's wrong here
Security alerts in Defender for Cloud are generated by the cloud workload protection layer when runtime threat signals are detected, such as suspicious PowerShell or anomalous network traffic. Vulnerability assessment findings, by contrast, come from scheduled queries/agents that scan installed software and report missing patches; they are not threat detections. Alerts include incident triage details and MITRE ATT&CK techniques, whereas vulnerability findings are CVE-based and appear as recommendation health results.
- ✗
Regulatory compliance
Why it's wrong here
The Regulatory Compliance dashboard maps compliance controls to standards like CIS and NIST, showing pass/fail status at a policy level. It aggregates assessments into compliance findings, but it does not display the individual vulnerability artifacts—like specific affected packages and remediation steps—that make up those assessment results. Its purpose is posture against standards, not detailed vulnerability remediation data.
- ✓
Recommendations
Why this is correct
In Defender for Cloud, every vulnerability assessment result is represented as a recommendation; the 'Remediate vulnerabilities' recommendation contains all discovered findings across your machines. When you open it, you see affected resources, CVE IDs, severity scores, and remediation guidance, and the findings update as scans complete. This is the dedicated location where vulnerability data is surfaced for action.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.