AZ-500 exam dumps

AZ-500 practice question 245 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 245

Select 2

You are a security engineer responsible for implementing agentless vulnerability scanning for several Windows and Linux Azure VMs. You already have Microsoft Defender for Cloud enabled, and you need to ensure that vulnerabilities are discovered without installing additional agents on each VM. Which TWO actions should you take to enable agentless scanning?

  1. A

    Enable the Microsoft Defender for Servers plan in each relevant subscription

  2. B

    Toggle on agentless scanning in the Microsoft Defender for Cloud environment settings

  3. C

    Deploy the Microsoft Monitoring Agent extension to each VM

  4. D

    Assign the built-in vulnerability assessment solution from Azure Policy to each VM

Show answer and explanation

Correct answers: A, B

Explanation

To use agentless scanning in Microsoft Defender for Servers, you must have the plan enabled and switch on agentless scanning in Microsoft Defender for Cloud settings. This setup leverages the hypervisor-level scanning provided by Azure, eliminating the need to install or configure agents directly on each VM. For more details on enabling agentless scanning, refer to Microsoft Defender for Cloud documentation at https://learn.microsoft.com/azure/defender-for-cloud/.

  • A. Correct.

    Enabling Microsoft Defender for Servers is required because it provides the licensing and capabilities needed for advanced security features such as agentless scanning. Without it, you cannot leverage agentless vulnerability assessment.

  • B. Correct.

    You must explicitly enable agentless scanning in the environment settings within Microsoft Defender for Cloud. This allows the platform to scan your VMs at the hypervisor level without requiring additional installation inside the guest OS.

  • C. Incorrect.

    Installing the Microsoft Monitoring Agent extension is required for the traditional agent-based approach. However, with agentless scanning, you do not need this extension; scanning is performed outside the VM.

  • D. Incorrect.

    Assigning the built-in Azure Policy for vulnerability assessment is relevant when using agent-based vulnerability assessors like Qualys or others. For agentless scanning, no separate Azure Policy assignment is required.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam