Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your organization is migrating to Azure and needs to protect against advanced threats like fileless malware. You must use a solution that provides real-time protection and integrates with Microsoft Defender for Cloud. What should you deploy on Azure VMs?

⚠ Common exam trap

Many exam-takers confuse Microsoft Antimalware for Azure (a legacy, signature-based solution) with modern endpoint detection and response (EDR) capabilities, mistakenly believing it can handle fileless malware when it cannot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint (Microsoft Defender XDR)

Microsoft Defender for Endpoint (part of Microsoft Defender XDR) provides next-generation protection, including behavior-based, real-time detection of fileless malware and other advanced threats. It integrates natively with Microsoft Defender for Cloud to deliver unified security management and automated response for Azure VMs, meeting the requirement for real-time protection against sophisticated attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Antimalware for Azure

    Why it's wrong here

    Microsoft Antimalware for Azure is a signature- and heuristic-based agent for IaaS VMs that only scans files for known malware patterns. It does not perform memory-level inspection or behavioral monitoring, so fileless attacks that execute in-process via PowerShell or WMI bypass it entirely. It is not an EDR solution and offers no response or containment capabilities.

  • ✓

    Microsoft Defender for Endpoint (Microsoft Defender XDR)

    Why this is correct

    Microsoft Defender for Endpoint, integrated into Microsoft Defender XDR, provides true endpoint detection and response with continuous memory scanning, kernel-level behavioral monitoring, and cloud-driven machine learning. It identifies fileless malware by correlating anomalous process activity, script execution, and in-memory indicators, then automatically contains the host. This capability is precisely why it, not any agent-based scanner, defeats fileless attacks.

  • ✗

    Azure Monitor Agent (AMA)

    Why it's wrong here

    Azure Monitor Agent is a telemetry pipeline component that collects logs and performance counters from VMs and sends them to Log Analytics or Azure Monitor. It has no endpoint protection module, cannot inspect memory or processes, and does not block malicious execution. At best it would provide forensic data after a compromise, so it is irrelevant to preventing fileless malware.

  • ✗

    Azure Security Center (free tier)

    Why it's wrong here

    The free tier of Microsoft Defender for Cloud (formerly Azure Security Center) provides posture assessments, secure score, and policy recommendations, but it does not enable endpoint protection or EDR. Protecting VMs with Defender for Endpoint requires the paid Defender for Cloud plan with the Defender for Servers workload, so the free tier alone cannot detect or respond to fileless threats.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.