AZ-500 exam dumps

AZ-500 practice question 243 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 243

Select 3

You are an Azure security engineer for an e-commerce company running Ubuntu-based VMs on Azure for web applications, Azure SQL databases for transactional data, and Azure Storage accounts for customer files. You have been tasked to enable Microsoft Defender threat detection and vulnerability scanning for these servers, databases, and storage accounts. Which three actions should you perform to ensure that Microsoft Defender protections are properly configured across all these resource types? (Choose three.)

  1. A

    Enable Microsoft Defender for Servers in Microsoft Defender for Cloud and configure the necessary extension or agent on your Azure VMs.

  2. B

    Enable Geo-Redundant Storage (GRS) for all your Azure Storage accounts to activate built-in threat protection.

  3. C

    Enable Microsoft Defender for Databases for your Azure SQL resources in the Environment settings or at the resource level.

  4. D

    Enable Microsoft Defender for Storage for each storage account or at the subscription level.

  5. E

    Create a custom role with the 'Microsoft Threat Protection contributor' permission for all resource groups hosting the VMs, databases, and storage accounts.

Show answer and explanation

Correct answers: A, C, D

Explanation

To fully secure servers, databases, and storage accounts with Microsoft Defender for Cloud, you must enable the respective Microsoft Defender plans (Servers, Databases, and Storage) at the appropriate levels (subscription, workspace, or resource), and ensure VMs have the required agent installed for threat detection telemetry. Geo-Redundancy and custom RBAC roles are not prerequisites to enable Defender threat protection. For more information, refer to Microsoft Defender for Cloud documentation at https://learn.microsoft.com/azure/defender-for-cloud.

  • A. Correct.

    Correct. When you enable Microsoft Defender for Servers, you get real-time threat detection and vulnerability management for your VMs. This also involves installing the Azure Monitor agent or Microsoft Defender extension on each VM to collect security data.

  • B. Incorrect.

    Incorrect. Geo-Redundant Storage (GRS) is a replication strategy, not a requirement for enabling Microsoft Defender threat detection. Threat protection for storage can be enabled regardless of the replication setting.

  • C. Correct.

    Correct. Microsoft Defender for Databases (formerly Azure Defender for SQL) can be enabled in Microsoft Defender for Cloud’s Environment settings or directly within the Azure SQL resource. This provides threat detection, vulnerability assessments, and alerts.

  • D. Correct.

    Correct. Microsoft Defender for Storage offers threat protection for your Azure Storage accounts. You can enable it per storage account or centrally through Microsoft Defender for Cloud.

  • E. Incorrect.

    Incorrect. There is no built-in 'Microsoft Threat Protection contributor' role, and creating a custom role is not a mandatory step for turning on threat detection. Configuring the relevant Defender plans is sufficient to enable security alerts and recommendations.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam