Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel →easyMultiple ChoiceObjective-mapped
AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization uses Microsoft Defender for Cloud. You need to ensure that all Azure subscriptions have the 'Auto-provisioning' extension enabled for Log Analytics agent on new VMs. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse the Azure Policy-based deployment of the Log Analytics agent (which is a valid method but not the one specified in the question) with Defender for Cloud's native auto-provisioning toggle, leading them to select option D instead of C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Auto-provisioning' in Defender for Cloud's environment settings.
Defender for Cloud's environment settings include a dedicated 'Auto-provisioning' toggle for the Log Analytics agent. When enabled, Defender for Cloud automatically installs the agent on any new Azure VM that is provisioned in the selected subscriptions, ensuring continuous monitoring without manual intervention. This is the native mechanism within Defender for Cloud to enforce agent deployment at scale.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Azure Automation State Configuration to push the agent.
Why it's wrong here
Azure Automation State Configuration (DSC) manages machine state via PowerShell Desired State Configuration, not the installation of monitoring agents for threat detection. While a DSC configuration could theoretically invoke an agent installer, it does not interface with Defender for Cloud's 'Auto-provisioning' toggle and requires each VM to be onboarded to an Automation Account with prerequisites like managed identity, which is not a subscription-wide default. New VMs would not receive the Log Analytics agent automatically unless the DSC configuration was continually assigned, making this a manual, out-of-band management tool rather than Defender for Cloud's native provisioning mechanism.
- ✗
Set up data connectors in Microsoft Sentinel.
Why it's wrong here
Microsoft Sentinel data connectors are designed to bring log sources into a Log Analytics workspace, such as Windows Security Events or Common Event Format, but they assume an agent is already present and do not deploy or provision the Log Analytics agent to VMs. Enabling a Sentinel connector merely creates ingestion rules for telemetry; it has no effect on Defender for Cloud's auto-provisioning setting, which controls extension installation on new VMs. Even if Sentinel is deployed, the Defender for Cloud environment setting must be enabled separately to satisfy the requirement of automatically monitoring all new VMs.
- ✓
Enable 'Auto-provisioning' in Defender for Cloud's environment settings.
Why this is correct
In Defender for Cloud's environment settings, enabling 'Auto-provisioning' deploys the Log Analytics agent extension automatically to new VMs without manual intervention. This satisfies the stem's requirement for a subscription-wide, automated mechanism that ensures all new VMs receive the agent, as opposed to per-VM manual installation or policy-based assignment.
- ✗
Create an Azure Policy assignment to deploy the Log Analytics agent.
Why it's wrong here
An Azure Policy assignment that deploys the Log Analytics agent enforces compliance at resource creation or remediation, but it does not enable the 'Auto-provisioning' extension within Defender for Cloud’s own settings. The stem specifically requires configuring the Defender for Cloud auto-provisioning toggle, which installs the agent automatically on new VMs via the Defender for Cloud agent management blade. This option is tempting because Azure Policy can deploy the agent at scale across subscriptions, and it would be the correct choice if the requirement were to audit or enforce agent installation independently of Defender for Cloud’s built-in provisioning mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.