Each week leadership asks which CVEs sit on lock-lab Azure virtual machines. Which named product in Microsoft Defender for Cloud should the Azure security engineer use?
Select an answer to reveal the explanation.
Short Explanation
Weekly CVE roll call on the lock-lab VMs? That’s Microsoft Defender Vulnerability Management inside Defender for Cloud. Skip the random third-party box and the Cloud Apps file-policy detour—MDVM is the named inventory.
Full Explanation
The January 22, 2026 AZ-500 outline names Microsoft Defender Vulnerability Management for Azure virtual machines. Findings appear in Microsoft Defender for Cloud through agentless scanning and/or Microsoft Defender for Endpoint depending on the Servers plan. Third-party scanners, Defender for Cloud Apps, and Security Copilot chat are not the required named MDVM product for this skill, and SC-200-style Defender for Endpoint hunting is out of scope as the first answer.