AZ-500 exam dumps

AZ-500 practice question 252 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 252

Select 2

Your organization stores source code in both Azure DevOps and GitHub. You need to configure Microsoft Defender for Cloud DevOps Security to scan all repositories for vulnerabilities and misconfigurations. Which two actions should you take to complete this integration?

  1. A

    A. In Microsoft Defender for Cloud, connect your GitHub organization using an owner or admin account, allowing Microsoft Defender for Cloud to access repositories for scanning.

  2. B

    B. Manually create a webhook in each GitHub repository to track pull requests and commits, then register it with Microsoft Defender for Cloud DevOps Security.

  3. C

    C. In Microsoft Defender for Cloud, navigate to Environment settings, add your Azure DevOps organization, and select relevant projects to onboard repositories.

  4. D

    D. Create a Service Connection within Azure DevOps containing an SSH key and configure it in Microsoft Defender for Cloud under GitHub connections.

Show answer and explanation

Correct answers: A, C

Explanation

To onboard GitHub and Azure DevOps repositories into Microsoft Defender for Cloud DevOps Security, you must grant the proper permissions at the organization level. In GitHub, connect Defender for Cloud to the organization (using an owner/admin account). In Azure DevOps, navigate to Environment settings in Defender for Cloud, link your Azure DevOps organization, and choose the relevant projects or repositories. This ensures the service has adequate permissions to detect and scan for vulnerabilities. For further details, see Microsoft's documentation on integrating Defender for Cloud with Azure DevOps and GitHub.

  • A. Correct.

    Option A is correct. Connecting your GitHub organization at the owner/admin level in the Defender for Cloud DevOps Security section is essential for granting the necessary permissions to scan your repositories.

  • B. Incorrect.

    Option B is incorrect. Microsoft Defender for Cloud does not require you to manually set up webhooks at the repository level. When you connect your GitHub organization through Defender for Cloud, it automatically configures the necessary hooks to scan your repositories.

  • C. Correct.

    Option C is correct. In Environment settings, you can connect your Azure DevOps organization, specify the projects you want to include, and allow Defender for Cloud to scan your repositories automatically.

  • D. Incorrect.

    Option D is incorrect. While Azure DevOps service connections are useful for pipeline deployments, they are not how Microsoft Defender for Cloud integrates. The integration occurs through Environment settings in Defender for Cloud, rather than creating an SSH-based service connection within Azure DevOps.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam