AZ-500 exam dumps

AZ-500 practice question 135 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 135

Select 2

You are managing a mission-critical microservices application deployed across multiple Azure Container Apps in your production subscription. Your security team requires real-time detection of vulnerabilities and malicious activity at the container level while also centrally collecting logs and metrics. You decide to configure Microsoft Defender for Cloud to meet these requirements. Which two of the following actions are necessary to ensure your Container Apps environments are monitored by Microsoft Defender for Cloud?

  1. A

    Enable Defender for Containers in Microsoft Defender for Cloud for the relevant subscription or resource group.

  2. B

    Enforce a mandatory Azure Policy to scan every container image with a third-party scanning solution.

  3. C

    Connect each Container Apps environment to an Azure Log Analytics workspace for centralized log collection.

  4. D

    Deploy Microsoft Defender for Endpoint as a sidecar container in each Container Apps environment.

Show answer and explanation

Correct answers: A, C

Explanation

To configure security monitoring for Azure Container Apps with Microsoft Defender for Cloud, you must enable Defender for Containers on the subscription or resource group where the Container Apps run and ensure the environment is connected to a Log Analytics workspace. This setup provides vulnerability assessments, real-time threat detection, and centralized logging. For more details, refer to the official Microsoft Defender for Cloud documentation for container security best practices and recommended configurations.

  • A. Correct.

    Enabling Defender for Containers in Microsoft Defender for Cloud is crucial. It allows advanced container-level threat detection features to be turned on, providing the real-time monitoring and alerting needed for your Azure Container Apps environments.

  • B. Incorrect.

    While Azure Policy can help enforce scanning policies or ensure images comply with security requirements, it is not a direct requirement to enable the continuous threat monitoring from Microsoft Defender for Cloud for Container Apps.

  • C. Correct.

    Configuring each Container Apps environment to send logs and metrics to a Log Analytics workspace is essential. Defender for Cloud relies on these logs for deeper analysis, threat detection, and alert generation across your containerized workloads.

  • D. Incorrect.

    Deploying Microsoft Defender for Endpoint as a sidecar container is not required. Microsoft Defender for Cloud integrates with Container Apps environments through its own instrumentation and agent architecture; an external sidecar container is unnecessary for standard container security monitoring.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam