AZ-500 Question 244
Single answerYour organization has recently upgraded multiple Azure subscriptions to Microsoft Defender for Servers Plan 2 to leverage advanced threat protection and reduce agent management overhead. You have several Windows and Linux virtual machines running in Azure, and you want to enable agentless vulnerability assessments for all these VMs. Which of the following steps must you take to ensure agentless scanning is properly configured?
- A
Enable the Qualys extension on each VM through the Azure portal
- B
Grant all VMs the Security Reader role at the subscription level
- C
Enable agentless scanning for each subscription in Microsoft Defender for Cloud’s environment settings
- D
Deploy the Microsoft Defender for Endpoint agent on every VM
Show answer and explanation
Correct answer: C
Explanation
Microsoft Defender for Servers Plan 2 includes agentless vulnerability assessments for Azure virtual machines. After purchasing or enabling Plan 2 coverage, you must go to Microsoft Defender for Cloud, select Environment Settings, choose the appropriate subscription(s), and enable agentless scanning. This eliminates the need to deploy individual extensions or agents for vulnerability scanning. For more details, see Microsoft documentation on configuring Microsoft Defender for Servers and enabling agentless scanning (https://learn.microsoft.com/azure/defender-for-cloud/).
- A. Incorrect.
Option 1 (Incorrect): While Qualys was historically used for vulnerability assessment in Azure, agentless scanning through Microsoft Defender for Servers no longer requires installing the Qualys extension on each machine. This option is an older approach.
- B. Incorrect.
Option 2 (Incorrect): Granting a Security Reader role does not enable agentless scanning. While roles and permissions are important for visibility, they do not activate or configure vulnerability assessments.
- C. Correct.
Option 3 (Correct): To enable agentless scanning, you must have Microsoft Defender for Servers Plan 2 active and then explicitly enable agentless scanning in the environment settings of Microsoft Defender for Cloud for each subscription. This setting ensures relevant VMs are scanned without installing additional agents.
- D. Incorrect.
Option 4 (Incorrect): Deploying the Microsoft Defender for Endpoint agent is typically required for endpoint protection, but agentless vulnerability assessment does not depend on installing this agent on every VM.