AZ-500 exam dumps

AZ-500 practice question 240 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 240

Select 2

You are an Azure Security Engineer at a company with many Windows and Linux virtual machines (VMs) in Azure. You want to enable Microsoft Defender for Cloud’s advanced threat detection for these VMs and ensure that any future VMs are also automatically onboarded. Which two actions should you take to provide complete coverage for your existing and future virtual machines?

  1. A

    Enable Microsoft Defender for Servers in the subscription’s Environment Settings.

  2. B

    Enable auto-provisioning of the Azure Monitor Agent in Microsoft Defender for Cloud.

  3. C

    Manually install a network security group (NSG) on each VM for advanced threat detection.

  4. D

    Tag each VM with the 'Security' tag to automatically onboard it to advanced threat detection.

  5. E

    Manually configure the Log Analytics extension on each VM without enabling auto-provisioning.

Show answer and explanation

Correct answers: A, B

Explanation

To protect all existing and new VMs at scale with Microsoft Defender for Cloud, you must first enable the Microsoft Defender for Servers plan. Then, auto-provision the necessary agent (Azure Monitor Agent) via the Portal or Environment Settings so that both current and future VMs are automatically onboarded. This approach aligns with Microsoft best practices and ensures the required telemetry is collected for advanced threat detection. For more details, refer to the Microsoft Defender for Cloud documentation at https://learn.microsoft.com/azure/defender-for-cloud.

  • A. Correct.

    Option 1: Correct. Enabling Microsoft Defender for Servers in your subscription’s Environment Settings is required to activate the advanced threat detection features for VMs.

  • B. Correct.

    Option 2: Correct. By enabling auto-provisioning of the Azure Monitor Agent (through Microsoft Defender for Cloud’s auto-provisioning settings), you ensure that both current and future VMs receive the necessary agent for advanced threat detection.

  • C. Incorrect.

    Option 3: Incorrect. While NSGs can help control traffic, they do not by themselves enable advanced threat detection. This option addresses network traffic filtering rather than workload protection services.

  • D. Incorrect.

    Option 4: Incorrect. Simply tagging a VM with 'Security' does not automatically onboard it to Defender for Cloud threat detection. Tagging can be useful for organization but does not replace the need to enable or configure Defender for Cloud settings.

  • E. Incorrect.

    Option 5: Incorrect. Manually configuring the Log Analytics extension on each VM without enabling auto-provisioning is not efficient and does not guarantee new VMs will be protected. Auto-provisioning in Defender for Cloud is the recommended approach.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam