AZ-500 Secure compute, storage, and databases Practice Question
Your security team wants to automatically detect and remediate misconfigurations in Azure Storage accounts, such as enabling public access. The solution should use Azure Policy and be centrally managed for multiple subscriptions. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse Azure Blueprints (a deployment orchestration tool) with Azure Policy (a continuous compliance enforcement service), or assume Microsoft Defender for Cloud alone can perform automatic remediation without an underlying policy assignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy with a custom initiative for storage security
Azure Policy with a custom initiative allows you to define a set of policies (e.g., 'Audit storage accounts with unrestricted public access') that can be assigned at a management group scope, covering multiple subscriptions. This enables automatic detection and remediation of misconfigurations like enabling public access, using built-in effects such as 'Deny' or 'DeployIfNotExists' to enforce compliance centrally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints is a declarative orchestration service that packages ARM templates, role assignments, and policy assignments into a single 'blueprint' for repeatable, environment-wide deployment. Although a blueprint can include a policy assignment for storage security, it executes only when the blueprint is created or updated; it does not continuously scan existing resources or automatically remediate drift in storage configurations. Blueprints address the 'deploy' need, not the ongoing 'detect and remediate' requirement.
- ✗
Azure Resource Graph
Why it's wrong here
Azure Resource Graph is a read-only query engine that enables fast, at-scale exploration of Azure resources using a Kusto-like syntax, with support for complex filters and joins across subscriptions. It returns JSON data representing resource properties but has no built-in enforcement or remediation operations—it cannot alter a storage account's configuration, trigger a compliance action, or schedule a fix. Resource Graph is a valuable inventory and visualization tool, but it is not a control plane for automatic security remediation.
- ✗
Microsoft Defender for Cloud (formerly Azure Security Center)
Why it's wrong here
Microsoft Defender for Cloud is a security posture management solution that aggregates endpoint protection, vulnerability assessment, and compliance recommendations, including Azure Policy's compliance results in its dashboard. It surfaces alerts and can even apply some 'Quick fixes,' but these actions are executed by deploying an Azure Policy initiative (the Microsoft Cloud Security Benchmark) underneath—Defender for Cloud does not have its own native policy engine for creating custom storage security initiatives. For custom, continuous detect-and-remediate logic, you must author and assign Azure Policy definitions directly, making Defender for Cloud a monitoring and management layer rather than the controlling mechanism.
- ✓
Azure Policy with a custom initiative for storage security
Why this is correct
Azure Policy with a custom initiative is the correct service because it allows you to author an initiative—a grouped set of policy definitions—that targets storage security controls such as secure transfer, encryption, public network access, and shared key auth. With the DeployIfNotExists or Modify effect, Azure Policy triggers remediation tasks to bring non-compliant storage accounts back into compliance, either automatically for new resources or via scheduled/on-demand remediation for existing ones. Scoping the initiative to the subscription or resource group and assigning it ensures continuous compliance evaluation and automatic corrective action, fulfilling the team's requirement.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.