Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your organization uses Microsoft Defender for Cloud to monitor Azure resources. You need to ensure that security recommendations are automatically remediated for non-compliant resources. Which TWO options can you use to achieve this?

⚠ Common exam trap

Many candidates confuse manual remediation options (like runbooks or scheduled playbooks) with automatic remediation, or they incorrectly assume Sentinel is the primary tool for automatic remediation of Defender for Cloud recommendations, when in fact Azure Policy and Quick Fix! are the direct, built-in mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign an Azure Policy with a DeployIfNotExists effect that deploys the required configuration.

Option B is correct because an Azure Policy with a DeployIfNotExists effect automatically deploys the required configuration to non-compliant resources, which is the standard mechanism Defender for Cloud uses for automatic remediation at scale. Option D is correct because Defender for Cloud's 'Quick Fix!' feature provides one-click, automated remediation for supported recommendations, directly fixing non-compliant resources. Option A is incorrect because a scheduled Logic Apps playbook is not an automatic remediation trigger tied to non-compliance; playbooks in Defender for Cloud are triggered by alerts or recommendations, not schedules. Option C is incorrect because Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response, not the service that remediates Defender for Cloud compliance recommendations. Option E is incorrect because manually running Azure Automation runbooks is not automatic remediation, which the scenario explicitly requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Logic Apps playbook that runs on a schedule.

    Why it's wrong here

    A scheduled Logic Apps playbook executes on a timer, independent of Defender for Cloud's compliance state, so it cannot promptly react when a resource becomes non-compliant. While you could build a polling loop to scan for failing recommendations, that introduces latency and doesn't leverage the native event-driven automation triggers built into Defender for Cloud for immediate remediation. Consequently, this approach lacks the automatic, compliance-state-driven remediation the question requires.

  • ✓

    Assign an Azure Policy with a DeployIfNotExists effect that deploys the required configuration.

    Why this is correct

    Assigning an Azure Policy definition with the DeployIfNotExists effect automatically deploys required settings whenever Azure Resource Manager evaluates a resource that lacks them, both on creation and on each compliance scan. After initial evaluation, the policy generates remediation tasks that actively bring existing non-compliant resources into compliance without manual intervention. This method is native, event-driven, and deeply integrated with Defender for Cloud's regulatory compliance and secure-score dashboards, making it the correct answer.

  • ✗

    Configure Microsoft Sentinel to automatically remediate based on alerts.

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform focused on detecting, investigating, and responding to security incidents and alerts, not on enforcing resource configuration. To remediate a Defender for Cloud recommendation via Sentinel, you would need to build a custom playbook that calls the Azure REST API, which is an indirect, over-engineered workaround. Since Defender for Cloud recommendations aren't automatically surfaced as Sentinel alert logic, this option fails to provide reliable, automatic remediation for compliance findings.

  • ✓

    Enable 'Quick Fix!' for supported recommendations in Defender for Cloud.

    Why this is correct

    Quick Fix! is a built-in Defender for Cloud capability that lets you remediate a supported recommendation across all affected resources with a single click, applying the exact configuration change for you. For many recommendations, you can enable automatic remediation using Quick Fix! when a new resource is created, providing fast, one-click automatic remediation without building any custom logic. Although it supports only a subset of recommendations, it meets the requirement for automatic remediation of supported items and is therefore correct.

  • ✗

    Use Azure Automation runbooks to manually run remediation.

    Why it's wrong here

    Azure Automation runbooks are just scripts — they execute only when explicitly launched, scheduled with custom logic, or triggered by an external hook, so they do not remediate automatically by themselves. The user would have to manually start the runbook to apply changes, making this a manual remediation process rather than an automatic one tied to Defender for Cloud's compliance state. While runbooks can be powerful for complex orchestration, they lack the native, out-of-the-box integration that DeployIfNotExists or Quick Fix! provides for recommendation remediation.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.