Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your company uses Microsoft Defender for Cloud to assess the security posture of Azure subscriptions. The security team receives an alert about a critical vulnerability in an Azure VM that was remediated two weeks ago. What is the most likely reason the alert is still active?

⚠ Common exam trap

A common mix-up: candidates assume remediation automatically clears the alert, but Microsoft Defender for Cloud requires a rescan to update the vulnerability state, and the alert will persist until the next scan cycle or manual rescan.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VM has not been rescanned after the remediation was applied.

The alert remains active because Microsoft Defender for Cloud relies on periodic vulnerability scans to update the security findings. Remediating the vulnerability on the VM does not automatically trigger a rescan; the alert status is only updated after the next scheduled scan or a manual rescan is initiated. Until the VM is rescanned, Defender for Cloud continues to display the previous vulnerable state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The VM has not been rescanned after the remediation was applied.

    Why this is correct

    Defender for Cloud evaluates VMs against the last completed vulnerability scan, not in real time. Applying a patch or configuration change does not automatically clear the finding; the VM must be rescanned (via the 'Rescan' action or the next scheduled scan) for the vulnerability status to refresh. Without that rescan, the vulnerability management dashboard continues to show the VM as vulnerable, even though the remediation actually succeeded.

  • ✗

    The alert is a false positive due to a known issue in the vulnerability assessment engine.

    Why it's wrong here

    False positives are rare for Microsoft Defender for Cloud's vulnerability assessment because the scanner cross-checks the actual software inventory against known CVEs. A known engine bug would be publicly documented and would not persist after a fresh scan. To reject a finding as a false positive, you'd still need to prove the vulnerability is not present, which requires a new scan of the VM to validate the remediation.

  • ✗

    The alert has a 30-day retention period and cannot be dismissed before that.

    Why it's wrong here

    There is no 30-day retention rule that prevents you from manually dismissing a security finding in Defender for Cloud. You can dismiss an alert or recommendation at any time, and it will reappear after the next scan if the underlying issue remains. A fixed retention period would conflict with the operational need to triage critical alerts promptly; retention limits apply to audit logs, not to the actionable state of vulnerability findings.

  • ✗

    Silent Remediation was enabled, preventing the alert from being dismissed.

    Why it's wrong here

    Silent Remediation in Defender for Cloud automatically applies a remediation step (such as a Azure Policy deployIfNotExist template) and suppresses notifications; it does not prevent an alert from being dismissed. On the contrary, after a successful silent remediation, the finding is cleared once the VM is rescanned and the vulnerability no longer exists. Enabling Silent Remediation would reduce, not prolong, the visibility of active alerts.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.