Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your security team wants to automatically detect and remediate misconfigurations in Azure Storage accounts, such as enabling public access. The solution should use Azure Policy and be centrally managed for multiple subscriptions. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse Azure Blueprints (a deployment orchestration tool) with Azure Policy (a continuous compliance enforcement service), or assume Microsoft Defender for Cloud alone can perform automatic remediation without an underlying policy assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy with a custom initiative for storage security

Azure Policy with a custom initiative allows you to define a set of policies (e.g., 'Audit storage accounts with unrestricted public access') that can be assigned at a management group scope, covering multiple subscriptions. This enables automatic detection and remediation of misconfigurations like enabling public access, using built-in effects such as 'Deny' or 'DeployIfNotExists' to enforce compliance centrally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Blueprints

    Why it's wrong here

    Azure Blueprints is a declarative orchestration service that packages ARM templates, role assignments, and policy assignments into a single 'blueprint' for repeatable, environment-wide deployment. Although a blueprint can include a policy assignment for storage security, it executes only when the blueprint is created or updated; it does not continuously scan existing resources or automatically remediate drift in storage configurations. Blueprints address the 'deploy' need, not the ongoing 'detect and remediate' requirement.

  • ✗

    Azure Resource Graph

    Why it's wrong here

    Azure Resource Graph is a read-only query engine that enables fast, at-scale exploration of Azure resources using a Kusto-like syntax, with support for complex filters and joins across subscriptions. It returns JSON data representing resource properties but has no built-in enforcement or remediation operations—it cannot alter a storage account's configuration, trigger a compliance action, or schedule a fix. Resource Graph is a valuable inventory and visualization tool, but it is not a control plane for automatic security remediation.

  • ✗

    Microsoft Defender for Cloud (formerly Azure Security Center)

    Why it's wrong here

    Microsoft Defender for Cloud is a security posture management solution that aggregates endpoint protection, vulnerability assessment, and compliance recommendations, including Azure Policy's compliance results in its dashboard. It surfaces alerts and can even apply some 'Quick fixes,' but these actions are executed by deploying an Azure Policy initiative (the Microsoft Cloud Security Benchmark) underneath—Defender for Cloud does not have its own native policy engine for creating custom storage security initiatives. For custom, continuous detect-and-remediate logic, you must author and assign Azure Policy definitions directly, making Defender for Cloud a monitoring and management layer rather than the controlling mechanism.

  • ✓

    Azure Policy with a custom initiative for storage security

    Why this is correct

    Azure Policy with a custom initiative is the correct service because it allows you to author an initiative—a grouped set of policy definitions—that targets storage security controls such as secure transfer, encryption, public network access, and shared key auth. With the DeployIfNotExists or Modify effect, Azure Policy triggers remediation tasks to bring non-compliant storage accounts back into compliance, either automatically for new resources or via scheduled/on-demand remediation for existing ones. Scoping the initiative to the subscription or resource group and assigning it ensures continuous compliance evaluation and automatic corrective action, fulfilling the team's requirement.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.