Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your organization has multiple Azure subscriptions managed by Microsoft Defender for Cloud. You need to ensure that all subscriptions have the same security policies applied, and that any new subscription automatically inherits these policies. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse Azure Blueprints with management group policy assignments, thinking Blueprints provide automatic inheritance, when in fact Blueprints require explicit assignment per scope and do not dynamically apply to new subscriptions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign a policy initiative at the management group level

Assigning a policy initiative at the management group level ensures that all subscriptions within that management group inherit the same security policies. When a new subscription is added to the management group, it automatically receives the assigned initiative, meeting the requirement for consistent and automatic inheritance. This is the most efficient and scalable approach for managing multiple subscriptions in Microsoft Defender for Cloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an Azure Blueprint and assign it to each subscription

    Why it's wrong here

    Azure Blueprints are deprecated in favor of Azure Policy, so this approach is obsolete. Even when it was available, blueprint assignments were created per subscription individually, meaning any newly added subscription would need a separate assignment and would not inherit configurations automatically. Additionally, Blueprints lacked the fine-grained inheritance model that management groups provide, so they do not offer a durable, centrally managed governance solution.

  • ✗

    Assign a policy initiative to a resource group and then move subscriptions into that group

    Why it's wrong here

    Resource groups do not contain subscriptions in the Azure hierarchy—subscriptions are nested inside management groups, not inside resource groups—so moving a subscription into a resource group is an invalid operation. A policy initiative assigned to a resource group only applies to resources directly in that group; it does not affect the subscription or other resource groups. This option fundamentally misunderstands the scope hierarchy, where subscription-level governance must be assigned at or above the subscription scope.

  • ✗

    Assign a policy initiative to each subscription individually

    Why it's wrong here

    While assigning a policy initiative to each subscription individually will enforce the initiative, it is operationally inefficient and error-prone because each assignment must be created manually and duplicated across every subscription. It also does not automatically cover newly created subscriptions, so governance gaps appear whenever a team adds a subscription. This approach forfeits the benefits of centralized management, making it unsuitable for organizations with multiple subscriptions requiring consistent compliance.

  • ✓

    Assign a policy initiative at the management group level

    Why this is correct

    Assigning a policy initiative at the management group scope is the correct centralized approach because all subscriptions and resource groups under that management group inherit the policy assignment automatically. This includes future subscriptions added later, which become compliant without any additional assignment effort. Management group assignments also provide a single point to manage exclusions, remediation, and compliance reporting across the entire organizational hierarchy.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.