AZ-500 exam dumps

AZ-500 practice question 235 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 235

Select 2

Your organization has multiple Azure subscriptions recently onboarded to Microsoft Defender for Cloud. You have already enabled Microsoft Defender for Servers Plan in these subscriptions and now want to ensure that all existing and newly created Azure virtual machines are automatically protected by Defender's advanced threat detection. Which two actions should you take to meet this requirement?

  1. A

    Enable the Auto Provisioning setting for the Log Analytics agent in Microsoft Defender for Cloud’s Environment settings.

  2. B

    Create and assign an Azure Policy definition to deploy the Microsoft Defender for Endpoint extension to all Azure VMs automatically.

  3. C

    Manually install the Microsoft Defender for Endpoint extension on each new VM using Azure CLI scripts.

  4. D

    Configure Continuous Export in Microsoft Defender for Cloud to forward alerts to a Log Analytics workspace.

Show answer and explanation

Correct answers: A, B

Explanation

To automatically protect all existing and newly created VMs, you must enable the relevant Microsoft Defender plan and configure auto-provisioning of the required agents (e.g., the Log Analytics agent or Azure Monitor Agent and Microsoft Defender for Endpoint extension). Leveraging Azure Policy to deploy extensions ensures newly created VMs are covered without manual steps. For more details, refer to Microsoft Defender for Cloud documentation on enabling threat protection for servers and configuring auto-provisioning (https://learn.microsoft.com/azure/defender-for-cloud/).

  • A. Correct.

    Correct. Enabling Auto Provisioning ensures that the required monitoring agent (Log Analytics or Azure Monitor Agent, depending on your configuration) is automatically installed on any existing or new VM in the selected subscriptions. This is a key step to ensure continuous threat protection for all your machines.

  • B. Correct.

    Correct. Using an Azure Policy definition to deploy the Microsoft Defender for Endpoint extension at scale helps automate security configuration for every VM. When new VMs are spun up, the extension is deployed without manual intervention, ensuring advanced threat detection is consistently enabled.

  • C. Incorrect.

    Incorrect. Manually installing the extension per VM is time-consuming and error-prone. While it can work for a small number of machines, it does not ensure automatic protection at scale for newly created VMs.

  • D. Incorrect.

    Incorrect. Continuous Export sends alerts and recommendation data to a Log Analytics workspace or an Event Hub but does not automatically enable protection on new VMs. It’s a useful feature for monitoring and alert correlation, but it doesn’t fulfill the requirement of auto-provisioning agents for threat protection.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam