Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your organization has a complex Azure environment with multiple subscriptions, each containing hundreds of VMs and PaaS services. You are responsible for ensuring that all resources are monitored for security threats using Microsoft Defender for Cloud. The environment includes: - Subscription A: Production workloads, requires the highest security posture. - Subscription B: Development environment, has a lower security budget. - Subscription C: Shared services (e.g., DNS, Active Directory). You need to implement the most cost-effective security monitoring solution that meets the following requirements: - All subscriptions must be covered by Defender for Cloud. - Production subscription must have vulnerability assessment for VMs. - Development subscription does not need vulnerability assessment but must have basic CSPM. - Shared services subscription must have advanced threat protection for Azure SQL databases. - You must minimize administrative overhead and ensure that security policies are centrally managed. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the 'Defender Cloud Security Posture Management' (CSPM) plan on the management group that contains all subscriptions. Then, on Subscription A, enable the 'Defender for Servers' plan with vulnerability assessment. On Subscription C, enable the 'Defender for Azure SQL' plan. Leave Subscription B with only the CSPM plan.

Option B is correct because enabling the Defender Cloud Security Posture Management (CSPM) plan at the management group scope centrally covers all subscriptions with basic CSPM at no/low cost, while selectively enabling Defender for Servers with vulnerability assessment only on Subscription A and Defender for Azure SQL only on Subscription C matches each subscription's specific requirement and minimizes cost and administrative overhead. This scoped approach avoids paying for unnecessary plans on Subscription B, which only needs basic CSPM. Option A is wrong because enabling all Defender plans on the management group would incur costs for plans not required (e.g., vulnerability assessment on Subscription B) and then require extra policy work to disable them. Option C is wrong because disabling Defender for Cloud on Subscription B violates the requirement that all subscriptions be covered and that B have basic CSPM. Option D is wrong because the free tier does not provide the required vulnerability assessment for VMs or advanced threat protection for Azure SQL, and manual configuration increases administrative overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable all Defender plans on the management group to cover all subscriptions, then disable vulnerability assessment on Subscription B via policy.

    Why it's wrong here

    Enabling every Defender plan at the management-group level forces all subscriptions—including the dev environment that only needs posture assessment—to pay for unnecessary workload protections (e.g., Defender for Servers, Defender for SQL). Even if you later use Azure Policy to disable plan components on Subscription B, you still incur the cost and management overhead of licensing those plans and handling exemptions for a scope that never needed them. The correct pattern is to enable only the foundational CSPM plan at the root and add per-subscription plans targeted to actual workloads, avoiding both over-provisioning and administrative complexity.

  • ✓

    Enable the 'Defender Cloud Security Posture Management' (CSPM) plan on the management group that contains all subscriptions. Then, on Subscription A, enable the 'Defender for Servers' plan with vulnerability assessment. On Subscription C, enable the 'Defender for Azure SQL' plan. Leave Subscription B with only the CSPM plan.

    Why this is correct

    This option correctly treats Microsoft Defender for Cloud's plans as modular components: the CSPM plan at the management group gives every subscription a baseline of continuous security posture assessment, attack-path analysis, and regulatory compliance scoring. Then, workload-specific plans are scoped precisely—Defender for Servers on Subscription A delivers built-in vulnerability assessment (via Microsoft Defender for Endpoint or Qualys) and host-level endpoint detection, while Defender for Azure SQL on Subscription C provides SQL injection protection and anomalous access detection. Leaving Subscription B on CSPM alone is cost-effective and appropriate for a non-production environment that requires monitoring but not those advanced workload-specific defenses.

  • ✗

    Enable the 'Defender for Servers' plan on Subscription A, 'Defender for Azure SQL' on Subscription C, and disable Defender for Cloud on Subscription B.

    Why it's wrong here

    This configuration omits the foundational Defender CSPM plan entirely, so Subscription B is left with no security monitoring at all—a serious governance gap because new vulnerabilities, misconfigurations, or regulatory drift in the dev environment would go undetected. Additionally, even on Subscriptions A and C, the absence of the CSPM plan weakens the overall program: workload plans like Defender for Servers do not supply the continuous cloud security graph, attack-path analysis, or compliance dashboards that a strong posture requires. Disabling Defender for Cloud on a subscription is not a 'savings' measure; it removes all recommendations and visibility, which is especially dangerous for a development environment where issues frequently appear first.

  • ✗

    Enable only the free tier of Defender for Cloud on all subscriptions, then manually configure vulnerability assessment for VMs in Subscription A and advanced threat protection for SQL in Subscription C.

    Why it's wrong here

    The free tier of Defender for Cloud only aggregates Azure resource security recommendations and offers basic hygiene checks; it does not include built-in vulnerability assessment for VMs nor does it surface advanced-threat-protection capabilities for Azure SQL. Manually configuring VA on Subscription A and ATP on Subscription C requires third-party tool integrations or per-resource settings, which is brittle, lacks centralized policy enforcement, and leaves gaps for unmonitored resources. Without the paid Defender for Servers and Defender for Azure SQL plans, you also miss automated agent-based scanning, threat-intelligence-based detection, and the seamless patching/recommendation loop, so this manual approach is incomplete and fails to meet the required security posture.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.