AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your company uses Microsoft Defender for Cloud to protect Azure resources. You notice that some Azure VMs are not showing any security recommendations. You verify that the VMs are running and have network connectivity. What is the most likely cause?
⚠ Common exam trap
Many exam-takers assume network connectivity or VM running status is sufficient for Defender for Cloud to generate recommendations, but they overlook the critical dependency on the Log Analytics agent for data collection and policy evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Log Analytics agent is not installed on the VMs
Microsoft Defender for Cloud relies on the Log Analytics agent (or Azure Monitor Agent) to collect security-relevant data from Azure VMs, such as configuration settings, event logs, and vulnerability signals. Without this agent installed, Defender for Cloud cannot assess the VM's security posture, and therefore no security recommendations will be generated for that VM, even if the VM is running and has network connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Log Analytics agent is not installed on the VMs
Why this is correct
Defender for Cloud relies on the Log Analytics agent (Microsoft Monitoring Agent) on each VM to collect telemetry such as installed patches, endpoint protection status, and audit logs; without it, the VM cannot be assessed and often appears as 'Not monitored' or missing data. The agent sends data to a Log Analytics workspace where the security engine evaluates the configuration and generates recommendations. Therefore, the absence of the agent directly explains why Defender for Cloud shows no or incomplete recommendations for these VMs.
- ✗
The VMs are in a resource group that lacks the required Azure RBAC role
Why it's wrong here
Azure RBAC determines what actions a user can perform on resources, not how Defender for Cloud scans them. A resource group lacking a specific RBAC role would only prevent a user from viewing or managing security recommendations if they lack permissions like 'Security Reader'; it does not stop data collection or assessment from occurring. Even with no RBAC role on the VM's resource group, the Log Analytics agent still operates and the VMs would still produce recommendations for authorized users.
- ✗
The VMs have a resource lock preventing policy evaluation
Why it's wrong here
Resource locks are designed to prevent accidental delete or modification of a resource, and they do not interfere with policy evaluation or Defender for Cloud's data collection. Azure Policy evaluation reads the current state of the resource, which is unaffected by a lock; furthermore, the Log Analytics agent runs in the guest OS and continues to send operational data unless the VM itself is stopped. A ReadOnly lock might block an extension installation, but it would not prevent the policy compliance scan or the assessment itself, so this is not the cause of missing recommendations.
- ✗
The VMs are in the Free tier of Defender for Cloud
Why it's wrong here
The free tier of Defender for Cloud (formerly 'Defender for Cloud' foundational security) already provides continuous security assessments and core recommendations for Azure VMs, such as missing system updates, OS vulnerabilities, and endpoint protection. Being on the free tier only excludes the enhanced paid protections like just-in-time VM access, adaptive application controls, and file integrity monitoring, but it still generates the same foundational recommendations. Therefore, tier placement cannot explain the absence of recommendations; the agent installation is the determining factor.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.