AZ-500 exam dumps

AZ-500 practice question 248 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 248

Select 2

You have upgraded to Microsoft Defender for Servers Plan 2 in Microsoft Defender for Cloud and want to enable Microsoft Defender Vulnerability Management to scan several Windows Server 2019 and Ubuntu 20.04 Azure VMs. After waiting 24 hours, you notice that no vulnerabilities are listed in the portal. Which two actions must you take to ensure these VMs are properly scanned by Microsoft Defender Vulnerability Management?

  1. A

    Manually install the Qualys extension on each virtual machine from the Azure Portal under Extensions.

  2. B

    Enable the built-in Microsoft Defender for Endpoint-based vulnerability assessment in the Environment Settings of Microsoft Defender for Cloud.

  3. C

    Verify that each virtual machine is successfully onboarded to Microsoft Defender for Endpoint.

  4. D

    Assign the built-in Security Administrator role to the virtual machines at the subscription scope.

Show answer and explanation

Correct answers: B, C

Explanation

To leverage Microsoft Defender Vulnerability Management for Azure virtual machines, you must first enable MDE-based scanning in the Environment Settings of Microsoft Defender for Cloud and ensure each VM is onboarded to Microsoft Defender for Endpoint. This combination allows Microsoft Defender Vulnerability Management to collect OS- and application-level vulnerability data and surface it in the Defender for Cloud portal. Refer to Microsoft documentation (https://learn.microsoft.com/azure/defender-for-cloud) for more details on configuring the built-in vulnerability assessment using Defender for Endpoint.

  • A. Incorrect.

    Although Qualys was previously a built-in assessment provider in Defender for Cloud, modern deployments often rely on Microsoft Defender for Endpoint-based scanning. Manually installing the Qualys extension is not required if you enable Microsoft Defender for Endpoint integration.

  • B. Correct.

    Enabling the built-in Microsoft Defender for Endpoint-based vulnerability assessment in the Environment Settings is necessary for Microsoft Defender Vulnerability Management to run scans automatically. This activates the MDE integration for vulnerability scanning within your Defender for Cloud environment.

  • C. Correct.

    Each VM must be onboarded to Microsoft Defender for Endpoint so the MDE agent can assess and report vulnerabilities. Without proper onboarding, Defender for Cloud will not receive the needed data from Microsoft Defender Vulnerability Management.

  • D. Incorrect.

    Simply assigning the Security Administrator role at the subscription scope does not enable or configure vulnerability scanning. Role assignments control permissions but do not affect the underlying scanning mechanisms.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam