AZ-500 exam dumps

AZ-500 practice question 250 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 250

Select 2

Your organization hosts its application source code in both GitHub and Azure DevOps repositories. You have been asked to configure Microsoft Defender for Cloud DevOps Security so that pull requests in these repositories are automatically scanned for vulnerabilities, and the scan results appear in Defender for Cloud. Which two steps should you perform to successfully enable and configure this integration?

  1. A

    Enable the DevOps security feature in Microsoft Defender for Cloud, then connect GitHub and Azure DevOps under 'Environment settings', providing the required permissions to read repository data.

  2. B

    Manually configure each CICD pipeline by adding a YAML task that grants Azure Resource Manager access for every new repository.

  3. C

    Install and configure the Microsoft Security DevOps extension for your GitHub or Azure DevOps organization so that code scanning capabilities can be automatically applied to repositories.

  4. D

    Create a new GitHub repository in the same organization named 'DefenderConfig' to store and manage the code scanning policies and results.

Show answer and explanation

Correct answers: A, C

Explanation

To enable Microsoft Defender for Cloud DevOps Security with GitHub or Azure DevOps, you must first connect your repository hosts within the Defender for Cloud portal. Next, installing and configuring the Microsoft Security DevOps extension ensures that code scanning and vulnerability assessments can be performed on pull requests and pushes. Refer to Microsoft’s official documentation on 'Defender for Cloud DevOps Security' for detailed steps and best practices.

  • A. Correct.

    Correct. In the Defender for Cloud portal, under 'Environment settings' > 'DevOps Security', you need to connect your GitHub and Azure DevOps organizations. This integration requires granting permissions so that Defender for Cloud can access and scan the repositories.

  • B. Incorrect.

    Incorrect. Simply granting Azure Resource Manager access within each pipeline via YAML tasks is not how Microsoft Defender for Cloud DevOps Security is integrated. The integration is configured through the Defender for Cloud blade, not solely by pipeline tasks.

  • C. Correct.

    Correct. Installing the Microsoft Security DevOps extension (sometimes referred to as 'Microsoft Defender for DevOps') for your repository host (GitHub or Azure DevOps) allows security scanning tasks to run automatically on code changes, making results visible in Defender for Cloud.

  • D. Incorrect.

    Incorrect. There is no requirement to create a specially named GitHub repository (like 'DefenderConfig') to store scanning policies or results. Configuration and results are managed through the Defender for Cloud portal and the integrated extension.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam