Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage a production Azure Kubernetes Service (AKS) cluster. The security team needs automatic detection of suspicious activities such as an unexpected "kubectl exec" into a pod or large-scale enumeration of Kubernetes secrets. They also want any resulting security alerts to flow to Microsoft Sentinel without deploying and maintaining custom agents on every node. Which action should you take first?
Enable Azure Monitor Container insights for the cluster and connect it to a Log Analytics workspace.
Install the Azure Policy add-on for Kubernetes and assign the built-in AKS baseline policy initiative.
Configure Azure RBAC integration with Microsoft Entra ID for the cluster and require multifactor authentication.
Enable Microsoft Defender for Containers for the subscription and apply the AKS protection plan to the cluster.
Enabling Microsoft Defender for Containers with the AKS plan activates runtime threat detection for the cluster. The service automatically deploys a Defender sensor as a DaemonSet on every node, which monitors container and host activities and raises alerts such as "Suspicious kubectl exec activity detected" and "Suspicious Kubernetes secrets enumeration." The sensor is managed by Microsoft, so you do not manually maintain node-level agents. After enabling Defender for Containers, you can configure the Microsoft Defender for Cloud data connector in Microsoft Sentinel to ingest the generated security alerts. Azure Monitor Container insights focuses on performance metrics, the Azure Policy add-on enforces configuration compliance, and Azure RBAC integration governs access; none of these provide native runtime threat detection for AKS workloads.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Defender for Containers in Azure?
Open an interactive chat with Bash
How does Microsoft Defender for Containers communicate with Microsoft Sentinel?
Open an interactive chat with Bash
Why doesn’t Azure Monitor Container insights provide runtime threat detection?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .