AZ-500 exam dumps

AZ-500 practice question 249 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 249

Select 2

Your organization has deployed several Windows and Linux Azure Virtual Machines (VMs) and has enabled the built-in vulnerability assessment in Microsoft Defender for Cloud. However, you notice that two Windows VMs do not display any vulnerability assessment results. You verify these VMs are powered on, and they have the requisite licenses. Which two actions should you perform to ensure that these VMs correctly report vulnerability data?

  1. A

    Install and configure the Microsoft Monitoring Agent (MMA) or Azure Monitor Agent (AMA) for data collection on the VMs.

  2. B

    Enable entity behavior analytics (UBA) in Microsoft Defender for Cloud for each Windows VM.

  3. C

    Ensure the vulnerability assessment solution extension is installed and running on the VMs.

  4. D

    Create a custom Azure Policy to audit installed software on the VMs.

  5. E

    Enable Microsoft Defender for Endpoint automatic onboarding for each VM.

Show answer and explanation

Correct answers: A, C

Explanation

Ensuring your Azure VMs report vulnerability data to Microsoft Defender for Cloud requires two key configurations: a supported agent (MMA or AMA) must be installed for data collection, and the Defender for Cloud vulnerability assessment extension must be correctly deployed on each VM. Additional features like entity behavior analytics or automatic endpoint onboarding are beneficial but are not required for the fundamental reporting of OS-level vulnerabilities. Refer to the Microsoft Defender for Cloud documentation for further details on installing agents and enabling vulnerability assessment extensions.

  • A. Correct.

    Option 1: Correct. The Microsoft Monitoring Agent or Azure Monitor Agent is required on VMs to collect vulnerability data and pass it to Defender for Cloud. Without the agent, vulnerability insights will not be reported.

  • B. Incorrect.

    Option 2: Incorrect. Enabling entity behavior analytics (UBA) is not a prerequisite for basic vulnerability assessments. UBA focuses on detecting suspicious account activities rather than collecting OS vulnerabilities.

  • C. Correct.

    Option 3: Correct. The Defender for Cloud vulnerability assessment solution requires the associated extension on each VM. If it's missing or not functioning, vulnerability data will not appear.

  • D. Incorrect.

    Option 4: Incorrect. While auditing installed software might be helpful, simply creating a custom Azure Policy does not fulfill the requirement for vulnerability reporting to Defender for Cloud.

  • E. Incorrect.

    Option 5: Incorrect. Defender for Endpoint integration can enhance threat detection on endpoints, but it is not specifically required for the built-in vulnerability assessment feature to report OS-level vulnerabilities.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam