AZ-500 exam dumps

AZ-500 practice question 130 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 130

Select 2

Your company hosts a container-based microservice in Azure Container Instances (ACIs) that processes sensitive financial data. The security team requires you to gather container logs centrally for auditing and detect suspicious activities in real time. Which two actions should you take to accomplish these monitoring and threat detection goals?

  1. A

    Configure a diagnostic setting on the container group to send logs to an Azure Log Analytics workspace.

  2. B

    Enable Microsoft Defender for Cloud and ensure container threat detection is turned on for the relevant subscription.

  3. C

    Add an ARM template extension to the container group that automatically installs the Microsoft Monitoring Agent.

  4. D

    Use the 'az container logs' command once a day to manually download and inspect logs from the container instance.

  5. E

    Grant the container’s managed identity read access to the Key Vault containing your TLS certificate.

Show answer and explanation

Correct answers: A, B

Explanation

To effectively monitor and secure Azure Container Instances (ACIs), configure diagnostic settings to send container logs to a centralized Log Analytics workspace. This allows for robust querying, analysis, and alerting capabilities. Enabling Microsoft Defender for Cloud on the subscription that hosts the container instances adds continuous threat detection and provides recommendations for hardening deployments. For further reference, consult Microsoft’s documentation on configuring diagnostics for ACIs (https://learn.microsoft.com/azure/container-instances/container-instances-log-analytics) and enabling Microsoft Defender for Cloud for container resources (https://learn.microsoft.com/azure/defender-for-cloud/defender-for-containers-introduction).

  • A. Correct.

    Correct. Configuring a diagnostic setting on the container group to forward logs to Azure Log Analytics is an essential step for ongoing security monitoring. It enables the collection of container logs that can be analyzed, correlated, and archived for auditing or compliance checks.

  • B. Correct.

    Correct. By enabling Microsoft Defender for Cloud (formerly Azure Security Center) and ensuring container threat detection is active, you can receive security alerts and remediation recommendations related to suspicious activities within your Azure Container Instances.

  • C. Incorrect.

    Incorrect. There is no built-in ARM template extension to install the Microsoft Monitoring Agent directly into Azure Container Instances. Diagnostic settings and Azure Defender integration are the supported mechanisms for collecting logs and detecting threats.

  • D. Incorrect.

    Incorrect. Manually downloading logs once a day is neither real-time nor centrally managed. This approach is insufficient for continuous threat detection or timely response, which is best achieved through automated diagnostics and Defender for Cloud.

  • E. Incorrect.

    Incorrect. While granting managed identity access to a Key Vault is a valid security procedure for handling secrets and certificates, it does not address monitoring or threat detection requirements.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam