AZ-500 Question 246
Select 2Your organization has 100 Azure virtual machines across multiple subscriptions. You want to reduce overhead by leveraging agentless vulnerability scanning in Microsoft Defender for Servers. You already have Microsoft Defender for Servers (Plan 2) enabled for all relevant subscriptions. Which two actions must you take to ensure agentless scanning is effectively configured for these virtual machines? (Choose two.)
- A
Enable integrated vulnerability assessment with agentless scanning in the Environment settings of Microsoft Defender for Cloud.
- B
Deploy the Log Analytics agent to all virtual machines in order to gather security logs for agentless scanning.
- C
Disable real-time antivirus scanning on each VM to avoid conflicts with the agentless approach.
- D
Ensure that any custom images used for the VMs are based on operating systems supported by agentless scanning.
- E
Assign the Security Admin role to each individual VM before activating agentless vulnerability scanning.
Show answer and explanation
Correct answers: A, D
Explanation
For agentless vulnerability scanning in Microsoft Defender for Servers, you must enable the integrated vulnerability assessment with agentless scanning at the subscription level in Defender for Cloud settings. Additionally, this feature currently supports specific operating systems, so using a supported OS image is crucial. Unlike traditional scanning approaches, you do not need to install or maintain agents (such as the Log Analytics agent), nor do you have to disable standard antivirus or assign dedicated roles to each VM. For detailed requirements and supported OS information, refer to Microsoft Defender for Cloud documentation at https://learn.microsoft.com/azure/defender-for-cloud.
- A. Correct.
Option A is correct. To use agentless vulnerability scanning, you must enable the integrated vulnerability assessment with agentless scanning in Microsoft Defender for Cloud. This setting is found in the Environment settings for each subscription.
- B. Incorrect.
Option B is incorrect. One advantage of agentless scanning is that it does not require agents such as the Log Analytics agent. The scanning process is conducted without installing an agent on the VM.
- C. Incorrect.
Option C is incorrect. Real-time antivirus scanning in the VM does not conflict with agentless vulnerability assessment, and disabling it would reduce your security protection unnecessarily.
- D. Correct.
Option D is correct. Agentless scanning currently has specific OS version requirements. Ensuring that custom images align with supported operating systems is necessary for the scans to work properly.
- E. Incorrect.
Option E is incorrect. You do not need to assign the Security Admin role to each VM individually. Properly configuring Microsoft Defender for Servers (and ensuring you have correct permissions in Defender for Cloud) is sufficient.