Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage security for hundreds of Windows and Linux Azure virtual machines across several production subscriptions. The security team must receive operating-system and software vulnerability findings, but they refuse to allow any new agents, extensions, or scripts to run inside the guest operating systems because of performance and change-control concerns. Which action should you take to satisfy the requirement?
Enable Microsoft Defender for Servers Plan 1 on all subscriptions and deploy the Log Analytics agent to every VM.
Use Defender for Cloud auto-provisioning to install the built-in Qualys vulnerability assessment extension on each VM.
Onboard every VM to Microsoft Defender for Endpoint by applying the onboarding script from the security center.
Enable Microsoft Defender for Servers Plan 2 on all subscriptions and turn on agentless vulnerability assessments for machines.
Agentless vulnerability assessments in Microsoft Defender for Cloud take snapshots of VM disks and use cloud APIs for out-of-band analysis, so no software is installed or executed inside the guest operating system. This capability is available when Microsoft Defender for Servers Plan 2 (which includes Microsoft Defender Vulnerability Management) is enabled. Defender for Servers Plan 1 can also produce vulnerability findings, but only through agent-based methods that install the Log Analytics agent or the Qualys/MDVM extension inside each VM, violating the stated constraint. Likewise, manually installing the Qualys extension or onboarding the machines to Microsoft Defender for Endpoint would place additional agents in the guest OS and therefore do not meet the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Defender for Servers Plan 2?
Open an interactive chat with Bash
How does agentless vulnerability assessment work in Azure?
Open an interactive chat with Bash
What is the difference between Defender for Servers Plan 1 and Plan 2?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .