🛡️ Microsoft Defender for Cloud - AZ-500 Practice Questions

Configure Defender for Cloud including secure score, recommendations, workload protections, and regulatory compliance.

13Questions Available
1Exam Domains

Practice Defender Questions Now

Start a timed practice session focusing on Microsoft Defender for Cloud topics from the AZ-500 question bank.

Start AZ-500 Practice Quiz →

AZ-500 Defender Question Bank (13 Questions)

Browse all 13 practice questions covering Microsoft Defender for Cloud for the AZ-500 certification exam. Answers are intentionally hidden on this page so you can self-test first before checking results in quiz mode.

  1. Question 1Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    You receive a Defender for Cloud recommendation to enable MFA for accounts with owner permissions. Under which Secure Score control does this appear?

    AProtect applications against DDoS attacks
    BEnable MFA
    CApply system updates
    DRemediate vulnerabilities

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  2. Question 2Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Defender for Cloud shows an 'MFA should be enabled for accounts with write permissions' recommendation. Which control category does this recommendation belong to in the Secure Score?

    AProtect workloads
    BEnable MFA security control
    CRemediate vulnerabilities
    DApply system updates

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  3. Question 3Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Which Defender for Cloud feature continuously assesses Azure resources against security benchmarks and provides a single percentage score representing security posture?

    ARegulatory Compliance dashboard
    BSecure Score
    CAsset Inventory
    DSecurity Alerts

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  4. Question 4Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Defender for Cloud shows recommendations for remediating a SQL Server vulnerability. Applying the recommendation would affect production workloads. What should be done to postpone without losing tracking?

    ADismiss the recommendation permanently
    BSnooze the recommendation for a specific period
    CDisable Defender for SQL on the subscription
    DCreate an exemption with a waiver reason

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  5. Question 5Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    A security team wants to add the NIST SP 800-53 compliance standard to Defender for Cloud's regulatory compliance dashboard. Where is this configured?

    ADefender for Cloud Workload Protections settings
    BDefender for Cloud Environment Settings > Security Policies > Add regulatory standard
    CAzure Policy compliance at subscription level
    DMicrosoft Sentinel content hub

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  6. Question 6Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Which Defender for Cloud recommendation would be raised if an Azure Storage account allows access from all networks (no firewall configured)?

    AStorage accounts should have blob public access disabled
    BStorage accounts should restrict network access using VNet rules
    CStorage accounts should use customer-managed keys
    DStorage accounts should have soft delete enabled

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  7. Question 7Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Defender for Cloud shows a container registry recommendation. The registry has images with critical CVEs. Which remediation action is directly available in Defender for Cloud?

    AAutomatically rebuild and push patched images
    BView vulnerability details and patch recommendations to guide manual remediation
    CBlock container deployments from the registry
    DAuto-quarantine vulnerable images

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  8. Question 8Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Microsoft Defender for Cloud has a recommendation to enable MFA for all subscription owners. An owner uses a hardware FIDO2 key for authentication. What is the recommendation status for this user?

    ANon-compliant — FIDO2 is not MFA
    BCompliant — FIDO2 security keys satisfy MFA requirements
    CUnknown — Defender for Cloud cannot detect hardware keys
    DCompliant only if the FIDO2 key is registered in Azure AD

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  9. Question 9Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Defender for Cloud's secure score drops after enabling a new subscription. Which action would most likely restore the score quickly?

    ADisable all Defender plans on the new subscription
    BRemediate the highest-impact recommendations shown in the secure score breakdown
    CAssign an Azure Policy to audit all resources
    DEnable diagnostic settings on all resources

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  10. Question 10Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    A security engineer uses Defender for Cloud to assess Azure resources against the Azure Security Benchmark. Which benchmark version is the default standard in Defender for Cloud as of 2025?

    ACIS Azure Foundations Benchmark v1.4
    BAzure Security Benchmark v3 (now Microsoft Cloud Security Benchmark - MCSB)
    CNIST SP 800-53
    DISO 27001

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  11. Question 11Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Defender for Cloud's Regulatory Compliance dashboard shows a control is 'Failed'. The control maps to 5 assessments. 3 are passing and 2 are failing. What is the control's compliance status?

    APartially compliant — shown as 60% pass rate
    BFailed — a control fails if any mapped assessment is failing
    CPassed — majority of assessments pass
    DNot applicable — mixed results require manual review

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  12. Question 12Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Defender for Cloud shows an 'Apply system updates' recommendation. Automatic updates are managed by a third-party patch management tool and Azure Update Manager is not used. How should this recommendation be handled?

    AEnable Azure Automatic VM Guest Patching to satisfy the recommendation
    BCreate an exemption with 'Waiver' justification explaining the third-party tool handles patching
    CDismiss the recommendation permanently without documentation
    DDisable Defender for Servers on these subscriptions

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz
  13. Question 13Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    An organization wants to onboard a GCP project to Defender for Cloud for CSPM. Which connector type should be used?

    AAzure Arc for GCP instances
    BDefender for Cloud native GCP connector
    CMicrosoft Sentinel GCP data connector
    DAzure Monitor agent on GCP VMs

    Answer hidden for practice.

    Use the interactive quiz to reveal the correct answer and explanation.

    Start AZ-500 Quiz

Key Defender Concepts for AZ-500

defender for cloudsecure scorerecommendationworkload protectioncspmcwppregulatory compliancebenchmark

AZ-500 Defender Exam Tips

Microsoft Defender for Cloud questions in AZ-500 are typically scenario-based. Focus on identity protection, platform hardening, data security, and security operations. Priority concepts: defender for cloud, secure score, recommendation, workload protection, cspm, cwpp.

What AZ-500 Expects

  • Anchor your answer in choose controls that reduce exposure while preserving least-privilege access.
  • Defender scenarios for AZ-500 are frequently mapped to Domain 4 (25-30%), so read the objective carefully before picking controls or architecture.
  • Expect multi-topic scenarios where Defender interacts with identity, networking, governance, or monitoring patterns rather than appearing as an isolated question.
  • When two options are both technically valid, prefer the choice that best aligns with the exam's operational scope (Associate) and vendor best practices.

High-Value Defender Concepts

  • Know the core Defender building blocks cold: defender for cloud, secure score, recommendation, workload protection.
  • Review the edge-case features and limits for cspm, cwpp; these details are commonly used to differentiate answer choices.
  • Practice service-integration reasoning: how Defender pairs with Sentinel, Security Operations in real deployment patterns.
  • For AZ-500, explain why the chosen Defender design meets reliability, security, and cost expectations better than the alternatives.

Common AZ-500 Traps

  • Watch for identity controls that are too broad for the requested scope.
  • Questions in Manage Security Operations often include distractors that look correct for Defender but violate least-privilege, compliance, or availability requirements.
  • Avoid picking options purely by feature name; validate data path, failure handling, and governance impact before answering.
  • If the prompt hints at automation or repeatability, eliminate manual-only operational answers first.

Fast Review Checklist

  • Can you compare at least two Defender implementation paths and justify which one best fits the scenario?
  • Can you map the chosen answer back to Manage Security Operations (25-30%) outcomes for AZ-500?
  • Can you explain security and access boundaries for Defender without relying on default-open assumptions?
  • Can you describe how Defender integrates with Sentinel and Security Operations during failure, scaling, and monitoring events?

Exam Domains Covering Defender

Related Resources

More AZ-500 Study Resources