Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
AZ-500 · 103 questions
- The canal authority wants every new Key Vault in every subscription to have purge protection. Where should you assign the built-in Azure Policy (or initiative that includes it) so child subscriptions inherit?
- Security wants several house rules—HTTPS on storage, no anonymous blobs, and Key Vault firewall—assigned once across the canal estate. Which Azure Policy construct should you use?
- A contractor still creates a public-access storage account after “the policy is on.” Which Azure Policy effect actually blocks that create or update?
- A lock-authority compliance review shows an Azure Policy initiative at 60 percent compliant, and a reviewer treats that figure as Microsoft Defender for Cloud Secure Score. How should the security engineer interpret the initiative percentage?
- A Deny-public-IP Azure Policy assignment at the management group must stay in force, but one lock-lab sandbox resource group needs temporary relief. What should the security engineer create?
- Existing lock-lab Key Vaults remain Non-compliant for diagnostic settings even after a DeployIfNotExists policy assignment is live. What does the security engineer need so already-deployed vaults become compliant?
- After the lock-lab Key Vault firewall is set to Deny by default, a contractor can still change vault networking and access settings from the Azure portal. What should the security engineer conclude about the firewall’s scope?
- Canal-authority secrets in Key Vault must not be reachable from the public Internet. Which configuration best meets that requirement?
- Azure SQL TDE and Storage BYOK fail to unwrap keys after the lock-lab Key Vault firewall is set to Deny all. The services appear on Microsoft’s trusted services list. What else must the security engineer do?
- App-subnet virtual machines must Get secrets from Key Vault while the public Internet must not. Which network setting should the security engineer apply on the vault?
- A lock-lab Key Vault still shows vault access policies, and an engineer also assigned Key Vault Secrets Officer through Azure RBAC. How should the security engineer treat the permission models?
- A subscription Contributor opened the lock-lab Key Vault and added themselves Get, List, and Set through an access policy. Why does Microsoft recommend Azure RBAC over access policies for this risk, and what is the mitigation direction?
- The lock-lab app managed identity only needs to read one secret from Key Vault. Which assignment follows least privilege?
- Help desk needs Get on only the Key Vault secret named lock-operator-pin. Which approach provides that object-level scope?
- An engineer flips the lock-lab Key Vault permission model to Azure role-based access control and every application immediately loses secret access. What order should the security engineer have followed?
- A contractor stores a PFX as a generic Key Vault secret string and pastes a 4096-bit RSA value into another secret. How should the security engineer choose Key Vault object types instead?
- An operator accidentally deletes the Key Vault secret canal-sql-cs. The vault still exists. What should the security engineer do first?
- An insider deletes the lock-lab Key Vault and attempts to purge it the same day. Which control prevents that immediate purge even for a subscription Owner?
- Canal-app password rotation will land a new value in Key Vault. How should the security engineer stage the change?
- An auditor requires lock-lab cryptographic keys in a single-tenant FIPS-validated HSM pool rather than a multi-tenant software-protected key. What should the security engineer recommend?
- The customer-managed key that protects lock-lab SQL TDE has never rotated. What should the security engineer configure in Key Vault?
- A Key Vault certificate and a storage customer-managed key are nearing expiry. How should the security engineer reduce break-glass surprises for callers?
- Estate policy requires every RSA key in Key Vault to be scheduled to rotate within 730 days. Which governance approach should the security engineer use?
- Before deleting or moving a Key Vault key used as a customer-managed key, what backup action should the security engineer take?
- The lock-lab Key Vault is gone, but an encrypted Key Vault backup blob remains. How should the security engineer recover the objects?
- A Key Vault secret was deleted ten minutes ago and the vault still exists. Soft-delete retention has not expired. What should the security engineer do first?
- A reviewer claims weekly Key Vault backups make purge protection optional for the lock-lab vault. How should the security engineer respond?
- A ransomware playbook assumes an attacker who already has Contributor will try to delete Recovery Services vault backup points. Which security controls should the security engineer enable for Azure Backup?
- An auditor requires Recovery Services vault backup points for the lock-lab estate that a compromised admin cannot expire early. Which control best meets that requirement?
- Backup operators on the canal estate were given Owner on the Recovery Services vault and can delete the vault itself. Which change restores least privilege for daily backup work?
- Defender for Cloud Inventory cannot show which lock-lab application owns each virtual machine during incident review. Which asset-management control should the security engineer apply first?
- The production Key Vault and Recovery Services vault for the canal must survive an accidental delete by a privileged operator. Which control should be applied?
- The canal director asks for “the number” that shows how complete the estate’s security recommendations are. What does Microsoft Defender for Cloud Secure Score represent?
- The lock-lab Secure Score is 42 percent. How should the security engineer choose which Defender for Cloud recommendations to remediate first?
- Deallocated lock-lab VMs and a Databricks workspace flood Secure Score with recommendations that do not apply. What should the engineer do instead of treating Secure Score as broken?
- Security leadership asks how many Windows VMs, storage accounts, and Key Vaults are in Defender for Cloud scope for the canal estate. Which feature should the engineer use?
- The lock-lab subscription currently has only the free posture experience. Which distinction is accurate?
- An operator opens a Microsoft Sentinel incident for every Secure Score recommendation on the lock-lab subscription. What is the correct distinction?
- An auditor asks which framework the canal estate’s Defender for Cloud Secure Score primarily uses by default. What should the engineer answer?
- A PCI assessor needs evidence for the cardholder lock-lab subscriptions. Which Defender for Cloud capability should the engineer open first?
- An ISO control shows red on the canal Defender for Cloud regulatory dashboard. What should the engineer do next?
- A GCP project is part of the canal estate, but the ISO regulatory dashboard shows Azure resources only. Why are GCP assessments missing?
- The board adopted CIS Azure Foundations for the lock-lab subscriptions. What should the engineer do in Microsoft Defender for Cloud?
- HIPAA shows roughly 40 percent compliance because someone enabled it on a non-PHI lock-lab subscription. What should the engineer do?
- Only the payments management group must show PCI assessments. How should the engineer scope the standard?
- A reviewer wants to turn off Azure Policy assignments because Defender for Cloud regulatory compliance is enabled. What is the accurate guidance?
- The canal authority has house rules such as no public IPs on lock-lab resource groups and Key Vault purge protection. How should those appear as a Defender for Cloud standard?
- About eighty percent of the canal need is covered by CIS; three house controls remain. What is the preferred approach?
- A custom Defender for Cloud standard exists in the tenant, but lock-lab dashboards stay empty for those controls. What is the most likely missing step?
- Windows servers in the lock house sit on-premises in the plant and must appear in Microsoft Defender for Cloud. What is the correct onboarding path?
- The canal estate also runs EC2 and S3 in AWS and needs Defender for Cloud recommendations on those resources. What should the engineer do?
- The data team’s GCP project with Compute Engine and Cloud SQL must appear in Microsoft Defender for Cloud. Which action is required?
- After the AWS account is connected, operators expect Defender for Servers alerts on every EC2 instance immediately. What should the engineer explain?
- A canal-authority CISO wants one Secure Score and Inventory view after Azure, AWS, GCP, and Arc are already connected. How should the Azure security engineer use Microsoft Defender for Cloud as the multi-cloud posture pane?
- Shadow lock-lab DNS and a forgotten public IP never appear in Defender for Cloud Inventory. Which capability should the Azure security engineer use to discover what the Internet can already see?
- The first Microsoft Defender External Attack Surface Management run for the canal authority is noisy with candidate assets. What should the Azure security engineer configure next at security-engineer depth?
- Microsoft Defender External Attack Surface Management flags an expired TLS certificate on a public marketing site for the lock authority. How should the Azure security engineer classify that finding?
- Microsoft Defender External Attack Surface Management finds a public storage static website that Defender Inventory never listed. What should the Azure security engineer do to close the discover-then-manage loop?
- Canal Secure Score looks healthy, yet there are no malware or storage-threat alerts on the lock estate. What should the Azure security engineer enable so cloud workload threat protection actually runs?
- Only two lock-lab resource groups need Microsoft Defender for Servers, but billing and enablement are subscription-wide. How should the Azure security engineer think about plan enablement scope?
- A consultant wants every Microsoft Defender for Cloud plan enabled “just in case,” including products outside the January 22, 2026 AZ-500 skill list. Which plans should the Azure security engineer prioritize from the lock-lab workload mix?
- An operator remediates the Defender for Cloud recommendation “disk encryption should be enabled” and believes Microsoft Defender for Servers is now on. What distinction should the Azure security engineer make?
- Lock-lab virtual machines need threat detection, and auditors also require agentless secret and vulnerability scanning. Which Microsoft Defender for Servers selection should the Azure security engineer make?
- The canal estate mixes Azure virtual machines and Arc-connected plant servers. Where should the Azure security engineer enable Microsoft Defender for Servers for coverage?
- A stem for the lock-lab estate tempts the engineer to “enable just-in-time VM access on each virtual machine” as the Domain 4 Defender for Servers answer. What is the correct Domain 4 focus instead?
- The canal estate runs Azure SQL Database, SQL Server on an Arc machine, and Azure Database for PostgreSQL. How should the Azure security engineer enable Microsoft Defender for Databases?
- A DBA believes enabling Microsoft Defender for SQL will encrypt the water-quality database at rest. What is the plan actually for?
- Unusual anonymous enumeration and a hash-reputation hit appear on lock-photo blobs. What should the Azure security engineer enable so those storage threat alerts fire?
- Uploads to a public lock-photo container must be scanned for malware on ingest. What should the Azure security engineer configure first?
- Finance wants Microsoft Defender for Storage only on production lock-photo accounts, not on every account in the subscription. How should the Azure security engineer configure that?
- Plant virtual machines cannot take another agent, yet auditors require machine scanning for secrets and vulnerabilities. What should the Azure security engineer enable?
- Security wants exposed connection strings on lock-lab disks without logging into the guest OS. Which agentless results in Microsoft Defender for Cloud should the engineer use?
- Lock-lab virtual machines are deallocated overnight and agentless findings look stale. What limitation should the Azure security engineer account for?
- Each week leadership asks which CVEs sit on lock-lab Azure virtual machines. Which named product in Microsoft Defender for Cloud should the Azure security engineer use?
- A critical CVE sits on IIS on a lock-lab virtual machine and appears as a Microsoft Defender Vulnerability Management recommendation. What should the Azure security engineer do first?
- Some lock-lab virtual machines run Microsoft Defender for Endpoint; others rely on agentless-only coverage under Servers Plan 2. How do Microsoft Defender Vulnerability Management findings reach Defender for Cloud?
- After one critical CVE is patched on a lock-lab virtual machine, the director expects Secure Score to jump immediately. How should the Azure security engineer explain the relationship?
- Lock-lab infrastructure-as-code and application repositories live in GitHub and Azure DevOps. What should the Azure security engineer do to bring them under Microsoft Defender for Cloud DevOps Security?
- A lock-lab CI pipeline is about to apply Terraform that opens a storage account to the Internet. As the Azure security engineer reviewing Microsoft Defender for Cloud DevOps Security, what should you focus on first?
- The canal authority’s DevOps estate includes GitHub, Azure DevOps, GitLab, and Bitbucket. Which platforms does Microsoft Defender for Cloud DevOps Security treat as first-class connectors on the January 22, 2026 AZ-500 outline?
- A consultant enables Microsoft Defender for Cloud Apps “for GitHub” to cover lock-lab repositories. Which product should the Azure security engineer use instead to connect and configure DevOps security findings for those repos?
- The GitHub connector in Microsoft Defender for Cloud DevOps Security shows Connected, but the critical lock-lab repository still has no findings. What should the Azure security engineer do next?
- Microsoft Defender for Cloud raises a High storage-malware alert on the lock-photo storage account. What should the Azure security engineer do first as part of managing the alert?
- An operator dismisses every Medium Microsoft Defender for Cloud alert so the lock-lab blade looks clean. How should the Azure security engineer handle dismissals instead?
- The canal SOC will respond from Microsoft Sentinel rather than living in the Microsoft Defender for Cloud alerts blade. What should the Azure security engineer configure?
- On the same Microsoft Defender for Cloud blade, the lock-lab team sees a “secure transfer required” recommendation and a “crypto-mining on VM” alert. How should the Azure security engineer treat them?
- High Microsoft Defender for Cloud alerts on lock-lab resources must open a ticket and email the on-call engineer. Which automation should the Azure security engineer configure?
- A Defender for Cloud workflow automation is creating ticket storms from Low recommendations across the canal subscriptions. How should the Azure security engineer scope the automation?
- The lock-lab team already runs Microsoft Sentinel playbooks and also needs ticket creation when High alerts appear in Microsoft Defender for Cloud. Which statement correctly separates the two automation controls?
- Security needs Windows Security events and syslog from lock-lab virtual machines in a Log Analytics workspace. What should the Azure security engineer create for Azure Monitor Agent?
- Capacity planning needs CPU counters from canal VMs while the SOC needs failed logon events in the same Log Analytics workspace. How should the Azure security engineer configure collection?
- A new lock-lab virtual machine has Azure Monitor Agent installed, but security events never appear even though a data collection rule already exists. What is the most likely missing step?
- The canal authority is standing up a greenfield Microsoft Sentinel SOC. In which order should the Azure security engineer enable data ingestion?
- Defender for Cloud alerts remain visible only in the Defender for Cloud blade and never become Microsoft Sentinel incidents. What should the Azure security engineer enable?
- The Microsoft Entra ID connector in Microsoft Sentinel stays disconnected for the lock-lab tenant. What should the Azure security engineer verify first?
- Lock-lab workspace cost spiked after every Microsoft Sentinel Content Hub connector was enabled. How should the Azure security engineer choose connectors?
- The SOC wants detections for suspicious resource deployments on lock-lab subscriptions. What should the Azure security engineer do in Microsoft Sentinel?
- A Microsoft Sentinel analytics rule is enabled but never fires for lock-lab activity that should match. What should the Azure security engineer check next?
- An analyst’s on-demand hunting query found repeatable unusual Key Vault access from a new ASN against lock-lab vaults. What should the Azure security engineer do so the pattern pages the SOC going forward?
- One Microsoft Sentinel analytics rule created two hundred lock-lab incidents overnight. What should the Azure security engineer do?
- High-severity Microsoft Sentinel incidents for lock-lab must tag the resource owner and run an isolate-virtual-machine Logic App. What should the Azure security engineer create?
- The isolate-virtual-machine Microsoft Sentinel playbook fails with HTTP 403 when it tries to change a lock-lab VM. What should the Azure security engineer fix?
- Management wants every High Microsoft Defender for Cloud incident in Microsoft Sentinel assigned to the SOC queue automatically. What should the Azure security engineer configure?