AZ-500 exam dumps

AZ-500 practice question 217 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 217

Single answer

Your organization has several virtual machines (VMs) in Azure reported as missing a vulnerability assessment solution within Microsoft Defender for Cloud. You also want to ensure that any new VMs receive the same protection automatically. Which approach best addresses both immediate remediation and ongoing compliance to improve your Secure Score?

  1. A

    Enable the built-in quick fix for the missing vulnerability assessment recommendation, then configure an Azure Policy to automatically install the vulnerability extension on new VMs.

  2. B

    Ignore the recommendation in Microsoft Defender for Cloud and rely on manual installation of the vulnerability assessment tool as needed.

  3. C

    Mark the recommendation as 'Resolved' in Defender for Cloud to remove it from the Secure Score list without taking any remediation actions.

  4. D

    Deploy the vulnerability assessment agent through a custom script for existing VMs and handle new VMs manually on a case-by-case basis.

Show answer and explanation

Correct answer: A

Explanation

The recommended best practice is to remediate existing security gaps using Defender for Cloud’s guided or quick-fix recommendations and to set up an Azure Policy to ensure future VMs remain compliant. Refer to the official Microsoft Defender for Cloud documentation for guidance on automating VM agent extensions (https://learn.microsoft.com/azure/defender-for-cloud) and creating Azure Policies (https://learn.microsoft.com/azure/governance/policy) to maintain and improve Secure Score over time.

  • A. Correct.

    Correct. Using Defender for Cloud’s built-in quick fix helps you quickly remediate existing VMs. Applying an Azure Policy ensures future VMs automatically have the vulnerability assessment extension installed, maintaining compliance and continuously improving your Secure Score.

  • B. Incorrect.

    Incorrect. Manual installation alone often leads to irregularity in enforcement and incomplete remediation, which undermines ongoing compliance efforts and leaves gaps in security.

  • C. Incorrect.

    Incorrect. Marking the recommendation as 'Resolved' will artificially remove it from the Secure Score list, but it does not address the underlying security risk. This is a common misconception where teams assume removing a recommendation equates to fixing the issue.

  • D. Incorrect.

    Incorrect. Scripts can be useful, but relying on manual scripting and case-by-case handling for new VMs is error-prone and does not leverage Defender for Cloud’s or Azure Policy’s automated capabilities for continuous compliance.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam