AZ-500 exam dumps

AZ-500 practice question 229 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 229

Select 2

Your organization wants to centralize security posture management across Azure, AWS, and GCP using Microsoft Defender for Cloud. You need to ensure that all AWS and GCP workloads are discovered, assessed, and represented in the security portal so they receive recommendations. Which two actions should you take to accomplish this integration?

  1. A

    In Microsoft Defender for Cloud’s Environment settings, add a new AWS connector and deploy the provided CloudFormation template to create a cross-account IAM role with the required read-only permissions.

  2. B

    Enable Azure Arc on all AWS and GCP VM instances to synchronize them directly with Azure Policy for security assessments.

  3. C

    Use the built-in GCP connector in Microsoft Defender for Cloud by creating a service account in GCP with the recommended security monitoring roles and granting it to Microsoft Defender for Cloud.

  4. D

    Create a custom Azure Policy initiative and assign it to both AWS and GCP resources for unified policy management.

  5. E

    Install the Microsoft Monitor agent on all AWS and GCP workloads before they can be onboarded to Microsoft Defender for Cloud.

Show answer and explanation

Correct answers: A, C

Explanation

To onboard AWS and GCP for unified security management in Microsoft Defender for Cloud, you must use the built-in connectors available in Defender for Cloud’s Environment settings. For AWS, Microsoft Defender for Cloud provides a CloudFormation script that sets up a cross-account role with read-only privileges. For GCP, Defender for Cloud relies on a service account with appropriate IAM roles. These connectors conduct continuous discovery and assessment of resources, providing security recommendations that feed into a centralized dashboard. Refer to Microsoft’s official Defender for Cloud documentation (https://learn.microsoft.com/azure/defender-for-cloud/enable-defender-for-cloud-on-multi-cloud) for detailed onboarding steps and permissions requirements.

  • A. Correct.

    Correct: Microsoft Defender for Cloud provides a native AWS connector that uses a CloudFormation template to create and configure a cross-account IAM role. This role grants Defender for Cloud the minimal permissions required to discover and assess AWS resources.

  • B. Incorrect.

    Incorrect: While Azure Arc can onboard servers running outside of Azure, simply enabling Arc on VMs in AWS and GCP does not replace the native connectors required for full security posture management. Azure Arc is primarily used to enable management features like Azure policy and VM extensions, but the recommended approach for AWS and GCP involves the built-in connectors in Defender for Cloud.

  • C. Correct.

    Correct: Microsoft Defender for Cloud can connect to GCP through a native connector by creating a service account with the necessary roles (such as Security Reviewer, Monitoring Viewer, etc.). This allows Defender for Cloud to inventory, scan, and assess GCP resources for security recommendations.

  • D. Incorrect.

    Incorrect: While Azure Policy can be extended to non-Azure environments, it does not replace the onboarding and data-collection requirements for AWS and GCP in Defender for Cloud. A custom Azure Policy initiative alone cannot gather the security data required from AWS and GCP.

  • E. Incorrect.

    Incorrect: Installing the Microsoft Monitor agent on each resource is not mandatory for connecting entire AWS or GCP environments to Defender for Cloud. The platform-native connectors can discover resources without requiring the Monitor agent on every workload.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam