exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 4 question 97 discussion

Actual exam question from Microsoft's AZ-500
Question #: 97
Topic #: 4
[All AZ-500 Questions]

You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud.

You have the management group hierarchy shown in the following exhibit.



You create the definitions shown in the following table.



You need to use Defender for Cloud to add a security policy.

Which definitions can you use as a security policy?

  • A. Policy1 only
  • B. Policy1 and Initiative1 only
  • C. Initiative1 and Initiative2 only
  • D. Initiative1, Initiative2, and Initiative3 only
  • E. Policy1, Initiative1, Initiative2, and Initiative3
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ppolychron
Highly Voted 1 year, 5 months ago
C, Initiative1, Initiative2 Microsoft Defender for Cloud applies security initiatives to the subscriptions. So when you go to Environment Settings of Defender for Cloud you will be able to assign Initiative1 (inheritied from TRG) and 2 to Sub1. MG1 does not have an Subscription so it wont even be an available option in Environment Settings.
upvoted 17 times
Ofenomeno
1 year, 4 months ago
C is correct (initiatives and not individual policies) and MG1 has no Subs Log in to the Azure Portal. Go to Microsoft Defender for Cloud. Click Environment settings, then select your subscription. In the left-pane menu, click Security policy in the Policy settings section. Under Default initiative, click Assign policy.
upvoted 2 times
...
...
billo79152718
Highly Voted 1 year, 6 months ago
Selected Answer: B
B. Policy1 and Initiative1 only
upvoted 5 times
billo79152718
1 year, 6 months ago
https://learn.microsoft.com/en-us/azure/defender-for-cloud/security-policy-concept
upvoted 3 times
...
...
cassucena
Most Recent 4 days, 8 hours ago
Selected Answer: C
only iniciatives to the subscriptions.
upvoted 1 times
...
TinyTrexArmz
1 month, 3 weeks ago
I've found two documents that say Initiative only: https://learn.microsoft.com/en-us/azure/defender-for-cloud/create-custom-recommendations#create-a-custom-recommendationstandard-legacy https://learn.microsoft.com/en-us/azure/defender-for-cloud/security-policy-concept#security-standards I can find nothing that says an initiative will only show up as an option in D4C in Management Groups where Defender for Cloud is enabled. I have no idea if the correct answer is C or D because the question is worded so poorly. But it's certain that A, B, and E cannot be right.
upvoted 1 times
...
Jimmy500
5 months, 2 weeks ago
C. We can use initiatives with Security Policies with. In this picture MG1 is not cover Sub1 and we can not use Initiative that it has, and we cannot use Policy1. Tenant Root Group has initiative that will be inherited to Sub1, and it can use this as Security Policy in defender for cloud and its own inherited as well. So, the answer will be here C initiative1 and 2.
upvoted 1 times
...
az2022
6 months, 2 weeks ago
It's D
upvoted 2 times
...
KRISTINMERIEANN
8 months, 1 week ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/defender-for-cloud/security-policy-concept
upvoted 1 times
...
hb0011
11 months, 2 weeks ago
Selected Answer: C
It's C
upvoted 1 times
...
[Removed]
11 months, 4 weeks ago
C, Initiative1, Initiative2 Microsoft Defender for Cloud applies security initiatives to the subscriptions. So when you go to Environment Settings of Defender for Cloud you will be able to assign Initiative1 (inheritied from TRG) and 2 to Sub1. Also tested in the lab this is correct
upvoted 2 times
...
OrangeSG
1 year, 2 months ago
Selected Answer: C
B is not correct. Microsoft documentation below imply that Policy cannot be added in Defender. Only initiative. Microsoft Defender for Cloud applies security initiatives to the subscriptions. Defender for Cloud offers the following options for working with security initiatives and policies: - View and edit the built-in default initiative - Add your own custom initiatives - Add regulatory compliance standards as initiatives
upvoted 2 times
...
TheProfessor
1 year, 2 months ago
I think the correct answer will be Initiated2 only. The reason is - An assignment is a policy definition or initiative that has been assigned to a specific scope. This scope could range from a management group to an individual resource. The term scope refers to all the resources, resource groups, subscriptions, or management groups (https://learn.microsoft.com/en-us/azure/governance/policy/overview#resources-covered-by-azure-policy) Microsoft Defender for Cloud applies security initiatives to your subscriptions. (https://learn.microsoft.com/en-us/azure/defender-for-cloud/security-policy-concept) Nowhere in the above links it says initiate can be assigned to Tenant Root Group.
upvoted 1 times
TheProfessor
1 year, 2 months ago
B is not correct as - Microsoft Defender for Cloud applies security initiatives to the subscriptions.
upvoted 1 times
...
...
Ario
1 year, 5 months ago
given answer is correct , Policy used as an individual security policy. It can be applied directly to the subscription and Initiative Initiatives are collections of security policies bundled together. While you can apply initiatives at the subscription level, they are typically used to manage and enforce multiple policies across multiple resources, subscriptions, or management groups. since there is no option for p1,in1andin2 B is the only one
upvoted 1 times
...
kuskumar
1 year, 5 months ago
Selected Answer: C
Policy cannot be added in Defender. Tested. Only initiative
upvoted 2 times
...
Yesvanth1
1 year, 5 months ago
Defender for Cloud is only on Sub1. From Environment Settings, you can add a custom initiative, you can create a new custom initiative with a custom policy from the same definition scope. Initiative 3 is on MG1: I don't think you can use initiatives from a different scope if it is not inheriting. I believe answer is: Policy1, Initiative1, Initiative2
upvoted 2 times
uml55
1 year, 3 months ago
Dude! That is not even an option!
upvoted 2 times
...
...
guchao2000
1 year, 6 months ago
C is correct, only Initiative1 (for TRG) and Initiative2 (for Sub1) Microsoft Defender for Cloud applies security initiatives to your subscriptions. Sub3 is not correct, as Sub 1 is not under MG1
upvoted 2 times
...
liorh
1 year, 6 months ago
what is the correct one?!?
upvoted 3 times
...
ghostme
1 year, 6 months ago
Selected Answer: D
Initiative1, Initiative2, and Initiative3 only
upvoted 4 times
Strive_for_greatness_kc
10 months, 3 weeks ago
Initiative3 should not even be an option here as Sub1 is not under MG1
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago