Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your organization runs a critical application on an Azure VM that generates sensitive data. You need to ensure that only approved applications can execute on the VM to prevent malware. You have Microsoft Defender for Cloud enabled with the Defender for Servers plan P2. Which feature provides application control without requiring custom rules?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Adaptive application controls in Defender for Cloud.

Adaptive application controls in Microsoft Defender for Cloud (option D) is the correct choice because, with the Defender for Servers P2 plan, it uses machine learning to automatically analyze VM behavior and create a baseline of approved applications, generating allowlist recommendations without requiring you to author custom rules. It then enforces these allowlists to block untrusted executables, directly meeting the requirement to prevent malware execution. AppLocker via Group Policy (A) also provides application control but requires manually defining and maintaining rules, so it does not fit the 'no custom rules' requirement. Just-in-time VM access (B) only restricts inbound network access to management ports and does not control which applications can execute. WDAC (C) is a valid application control mechanism, but it likewise requires you to create and manage policies rather than automatically generating them from Defender for Cloud's adaptive recommendations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure AppLocker via Group Policy.

    Why it's wrong here

    AppLocker via Group Policy is a native Windows application whitelisting tool, but it demands manually defined rules based on file paths, publishers, or hashes. Distributing and managing these rules across Azure VMs via GPO is administrative heavy and prone to drift, and AppLocker lacks the cloud-native, machine-learning-driven baseline generation that Defender for Cloud provides. It also does not automatically adapt to new legitimate software or integrate with security alerts, making it an impractical answer for an environment where Defender for Cloud is expected to manage controls.

  • ✗

    Enable Just-in-time VM access on the VM.

    Why it's wrong here

    Just-in-time (JIT) VM access is a Microsoft Defender for Cloud network security feature that restricts inbound traffic to management ports such as RDP and SSH. It operates at the network layer and has no effect on which applications or processes can execute on the VM. Even with JIT enabled, any malicious executable already present or installed later can run freely, so JIT cannot satisfy the requirement to control application execution.

  • ✗

    Enable Windows Defender Application Control (WDAC) on the VM.

    Why it's wrong here

    Windows Defender Application Control (WDAC) is a powerful application control mechanism, but it requires custom policy creation, code signing, and ongoing policy maintenance. WDAC policies must be generated and deployed manually, often via Intune or GPO, and Defender for Cloud does not automatically enable or manage WDAC for a VM. Enabling WDAC involves planning for allowed drivers and apps, and incorrectly configured policies can lock users out or break legitimate applications, making it a non-answer given the scenario expects an automatically applied, cloud-managed solution.

  • ✓

    Enable Adaptive application controls in Defender for Cloud.

    Why this is correct

    Adaptive application controls in Microsoft Defender for Cloud are the correct solution because they automatically build an allowlist of known-good processes using machine learning and behavioral analysis. Defender for Cloud monitors running processes across the VM, generates a baseline, and applies an application control policy that permits only trusted applications while blocking untrusted executables. It also provides security recommendations and alerts when deviations occur, all managed from the Defender for Cloud portal without the need to manually construct rule sets, making it the only option that meets the requirement for an automatic, centrally managed application control.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.