AZ-900 Describe Azure architecture and services Practice Question
A company wants to proactively identify Azure resources that are misconfigured and could lead to security vulnerabilities, such as virtual machines with open management ports or unencrypted storage accounts. They also need to get prioritized recommendations for remediating these issues. Which Azure service should the company use?
⚠ Common exam trap
Many exam-takers confuse Azure Advisor's general recommendations with Defender for Cloud's security-specific assessments, but Azure Advisor does not detect misconfigurations like open management ports or unencrypted storage—it focuses on cost, performance, and reliability instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud (formerly Azure Security Center)
Microsoft Defender for Cloud (formerly Azure Security Center) is the correct service because it continuously assesses the security posture of Azure resources, identifies misconfigurations such as open management ports (e.g., RDP/SSH) or unencrypted storage accounts, and provides prioritized, actionable recommendations for remediation. It integrates with Azure Policy to enforce security standards and offers a secure score to track improvement over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Cloud (formerly Azure Security Center)
Why this is correct
Microsoft Defender for Cloud (formerly Azure Security Center) is a Cloud Security Posture Management (CSPM) service that continuously scans Azure resources against built-in security baselines and regulatory standards. It aggregates findings from network configuration, endpoint vulnerabilities, and identity controls into a prioritized list of recommendations, each with a remediation step and a Secure Score impact. Unlike a one-time compliance check, it actively monitors for misconfigurations such as open management ports, deprecated TLS versions, or missing disk encryption, and can trigger automated remediation actions or adaptive hardening rules. It also integrates with Azure Policy for custom enforcement while providing workload-specific threat protection beyond simple compliance evaluation.
- ✗
Azure Advisor
Why it's wrong here
Azure Advisor provides best practice recommendations across cost, performance, reliability, and security. While it does include some security suggestions, it is not the dedicated service for in-depth vulnerability scanning and secure posture management; Microsoft Defender for Cloud is the primary tool for that purpose.
When this WOULD be correct
A company wants to optimize Azure resource usage and costs by receiving personalized recommendations on how to improve performance, reduce costs, and increase reliability. In that scenario, Azure Advisor would be the correct service.
- ✗
Azure Policy
Why it's wrong here
Azure Policy helps enforce organizational standards by applying rules (e.g., 'require encryption on storage accounts'). It can evaluate compliance but does not natively scan for security vulnerabilities or provide a prioritized list of security issues across all resources.
When this WOULD be correct
A company needs to enforce that all storage accounts must have encryption enabled and audit existing resources for compliance with that rule. Azure Policy would be the correct service to define and apply such a policy.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints is a design-time orchestration service that packages reusable Azure resources, such as resource groups, Azure Policy assignments, Role-Based Access Control (RBAC) roles, and ARM templates, into a definable environment blueprint for repeatable deployments. It enables organizations to scaffold a compliant architecture from the outset, but it does not perform ongoing security assessments, vulnerability scanning, or generate prioritized remediation recommendations. Once a blueprint is deployed, its policy and RBAC components can evaluate compliance, yet the service itself does not actively monitor for security misconfigurations or provide a dynamic security posture score. In short, Blueprints establishes an initial governance foundation, not a continuous security monitoring or threat-detection mechanism.
When this WOULD be correct
A company needs to define a repeatable set of Azure resources (e.g., resource groups, policies, role assignments) that must be deployed together to meet compliance or governance requirements. Azure Blueprints would be the correct service to create and manage these blueprints for consistent environment setup.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Defender for Cloud (formerly Azure Security Center)Correct answer▾
Why this is correct
Microsoft Defender for Cloud (formerly Azure Security Center) is a Cloud Security Posture Management (CSPM) service that continuously scans Azure resources against built-in security baselines and regulatory standards. It aggregates findings from network configuration, endpoint vulnerabilities, and identity controls into a prioritized list of recommendations, each with a remediation step and a Secure Score impact. Unlike a one-time compliance check, it actively monitors for misconfigurations such as open management ports, deprecated TLS versions, or missing disk encryption, and can trigger automated remediation actions or adaptive hardening rules. It also integrates with Azure Policy for custom enforcement while providing workload-specific threat protection beyond simple compliance evaluation.
✗Azure AdvisorWrong answer — click to see why▾
Why this is wrong here
Azure Advisor provides general best practice recommendations for cost, performance, reliability, and security, but it does not proactively identify misconfigurations that could lead to security vulnerabilities or provide prioritized remediation for such issues. Microsoft Defender for Cloud is specifically designed for cloud security posture management and threat detection.
★ When this WOULD be the correct answer
A company wants to optimize Azure resource usage and costs by receiving personalized recommendations on how to improve performance, reduce costs, and increase reliability. In that scenario, Azure Advisor would be the correct service.
Why candidates choose this
Candidates may confuse Azure Advisor's general recommendations with the security-specific recommendations of Microsoft Defender for Cloud, or they may think that 'Advisor' implies proactive security advice.
✗Azure PolicyWrong answer — click to see why▾
Why this is wrong here
Azure Policy enforces and audits compliance rules (e.g., requiring encryption), but it does not proactively identify misconfigurations or provide prioritized remediation recommendations for security vulnerabilities.
★ When this WOULD be the correct answer
A company needs to enforce that all storage accounts must have encryption enabled and audit existing resources for compliance with that rule. Azure Policy would be the correct service to define and apply such a policy.
Why candidates choose this
Candidates may confuse Azure Policy's compliance auditing capabilities with the proactive security assessment and recommendations provided by Defender for Cloud, especially since both deal with configuration standards.
✗Azure BlueprintsWrong answer — click to see why▾
Why this is wrong here
Azure Blueprints is used for defining and deploying repeatable sets of Azure resources that adhere to organizational standards, patterns, and requirements. It does not proactively identify misconfigurations or provide prioritized security recommendations; that is the role of Microsoft Defender for Cloud.
★ When this WOULD be the correct answer
A company needs to define a repeatable set of Azure resources (e.g., resource groups, policies, role assignments) that must be deployed together to meet compliance or governance requirements. Azure Blueprints would be the correct service to create and manage these blueprints for consistent environment setup.
Why candidates choose this
Candidates may confuse Blueprints with security governance because both involve compliance and standards, but Blueprints focuses on deployment templates rather than ongoing monitoring and remediation of misconfigurations.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Regions and Geographies
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.