AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization uses Microsoft Defender for Cloud to protect Azure workloads. You notice that a critical Azure VM is not covered by any of the Defender for Cloud plans. You need to ensure that the VM is protected by the Defender for Servers plan. What should you do?
⚠ Common exam trap
It's easy for candidates to think Defender for Cloud plans can be enabled per resource (like a VM) or via Azure Policy, when in fact they are subscription-level settings that must be enabled in the Defender for Cloud environment settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Defender for Servers plan in the Defender for Cloud environment settings for the subscription containing the VM.
Defender for Cloud plans are enabled at the subscription level, not per resource. By enabling the Defender for Servers plan in the Defender for Cloud environment settings for the subscription containing the VM, all current and future VMs in that subscription will be automatically protected, including the critical VM in question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a custom Azure Policy to assign the Defender for Servers plan to the VM.
Why it's wrong here
A custom Azure Policy can be authored to audit or deploy configuration (e.g., install Microsoft Defender for Endpoint or enforce a specific Defender for Cloud pricing tier on a scope), but it cannot turn on the Defender for Servers plan itself. Plan enablement is an operation in Defender for Cloud's environment settings that sets the pricing tier (Free/Standard) and resource coverage for the subscription; Azure Policy has no built-in effect that performs this subscription-level plan activation. At best, policy could verify that the subscription's pricing configuration matches your expected tier, but it cannot serve as the mechanism for enabling the plan for a single VM.
- ✓
Enable the Defender for Servers plan in the Defender for Cloud environment settings for the subscription containing the VM.
Why this is correct
Navigate to Defender for Cloud > Environment settings, select the subscription that contains the VM, and under 'Defender plans' toggle the Defender for Servers plan to On. This activation is a subscription-scoped configuration that immediately protects the target VM as well as all other current and future VMs in that subscription (assuming the subscription is the plan's scope). The environment settings blade is the authoritative place for enabling any Defender plan; once enabled, the VM's Defender for Cloud status changes to covered, and you will start accruing per-resource billing according to the plan's pricing model.
- ✗
Enable the Defender for Servers plan directly on the VM's security configuration blade.
Why it's wrong here
The VM's security configuration blade (e.g., the 'Security' or 'Defender for Cloud' link on the virtual machine resource) displays the current protection status and surfaces recommendations, but it is not a control plane for enabling or disabling Defender plans. Plan enablement is scoped to the subscription or, for some plans, the resource group, so attempting to toggle the plan 'per VM' is not possible in the UI or through the VM's REST API. If the subscription hasn't enabled Defender for Servers, the VM blade will simply show the plan as inactive and guide you to the subscription-level environment settings.
- ✗
Ensure the VM is running a supported operating system; the plan is automatically enabled for all VMs.
Why it's wrong here
A supported operating system is a prerequisite for Defender for Servers to provide endpoint detection and response, but simply having a supported OS does not automatically enroll the VM into the Defender for Servers paid plan. The plan's pricing tier remains 'Free' until someone with appropriate permissions explicitly enables Defender for Servers in the subscription's environment settings; after that, supported VMs get the coverage, including agent provisioning if the 'Auto-provision' setting is on. Thus, OS compatibility is necessary but never sufficient for automatic plan activation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.