exam questions

Exam AZ-400 All Questions

View all questions & answers for the AZ-400 exam

Exam AZ-400 topic 3 question 18 discussion

Actual exam question from Microsoft's AZ-400
Question #: 18
Topic #: 3
[All AZ-400 Questions]

Your company uses the following resources:
✑ Windows Server 2019 container images hosted in an Azure Container Registry.
✑ Azure virtual machines that run the latest version of Ubuntu
✑ An Azure Log Analytics workspace
✑ Azure Active Directory (Azure AD)
✑ An Azure key vault
For which two resources can you receive vulnerability assessments in Azure Security Center? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. the Azure Log Analytics workspace
  • B. the Azure key vault
  • C. the Azure virtual machines that run the latest version of Ubuntu
  • D. Azure Active Directory (Azure AD)
  • E. The Windows Server 2019 container images hosted in the Azure Container Registry.
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dollarpo7
Highly Voted 4 years, 5 months ago
https://docs.microsoft.com/en-us/azure/security-center/features-paas C and E
upvoted 42 times
vxl
2 years, 2 months ago
I had it in my exam (febr 2023)
upvoted 7 times
mikk
2 years, 1 month ago
did you also receive any simulation questions in exam?
upvoted 10 times
...
...
Albelev
3 years, 11 months ago
B, C are correct (KeyVault and VM). Windows container images are not supported , only Linux. https://docs.microsoft.com/en-us/azure/security-center/defender-for-container-registries-introduction
upvoted 16 times
warchoon
2 years, 4 months ago
https://learn.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-vm "The Microsoft Defender for Cloud vulnerability assessment extension (powered by Qualys), like other extensions, runs on top of the Azure Virtual Machine agent. So it runs as Local Host on Windows, and Root on Linux."
upvoted 1 times
...
ChauPhan
3 years, 5 months ago
But your link is also correct, so I don't know Supported registries and images: Linux images in ACR registries accessible from the public internet with shell access ACR registries protected with Azure Private Link
upvoted 1 times
...
ChauPhan
3 years, 5 months ago
Check carefully the above link Service Recommendations (Free) Security alerts Vulnerability assessment Azure Key Vault belongs to Recommendation and Security Alerts, not Vulnerability assessment Per my personal opinion, Vulnerability assessment is usually for VMs and Image, not for Vault.
upvoted 6 times
...
...
Quirkafleeg
3 years, 4 months ago
https://docs.microsoft.com/en-us/security/benchmark/azure/security-control-vulnerability-management Section 5.1: "Follow recommendations from Azure Security Center on performing vulnerability assessments on your Azure virtual machines, container images, and SQL servers."
upvoted 5 times
...
...
piyipo3349
Highly Voted 4 years, 4 months ago
Answer: B & C I know, it's weird to agree with the solution provided by exam topics. But why do I agree? 1) create a Keyvault and a VM 2) go to each resource, and search for "security" in the left pane 3) view the security recommendations. Also, note the blue banner on top stating: "Visit Security Center to manage security across your virtual networks, data, apps, and more"
upvoted 14 times
...
yaguitoEC
Most Recent 5 months ago
Selected Answer: CE
I go for C and E
upvoted 1 times
...
Gooldmember
6 months ago
Selected Answer: CE
Microsoft Defender for Cloud has Defender For Servers and Defender for Containers Defender for Servers -> scans the Ubuntu server Defender for Containers has implicit an Vulnerability assessment for Azure as a feature. https://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-vulnerability-assessment-azure In the docs it states: This feature supports scanning of images in the Azure Container Registry (ACR) only. Images that are stored in other container registries should be imported into ACR for coverage. Learn how to import container images to a container registry.
upvoted 1 times
...
Kalaisuran
1 year, 1 month ago
Selected Answer: CE
https://learn.microsoft.com/en-us/security/benchmark/azure/security-control-vulnerability-management Follow recommendations from Azure Security Center on performing vulnerability assessments on your Azure virtual machines, container images, and SQL servers.
upvoted 2 times
...
vsvaid
1 year, 4 months ago
Selected Answer: CE
As per https://learn.microsoft.com/en-us/azure/defender-for-cloud/support-matrix-defender-for-cloud
upvoted 1 times
...
vsvaid
1 year, 4 months ago
Selected Answer: CE
C and E
upvoted 1 times
...
gabo
1 year, 7 months ago
As per : https://learn.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-vm The Vulnerability scanning is only available for virtual machines, Azure SQL databases and ACR images, so the right answer should be C, E
upvoted 3 times
...
WH16
1 year, 7 months ago
Selected Answer: CE
On exam 2023-09-06, selected C and E Score 933
upvoted 5 times
...
krzychu3000
1 year, 8 months ago
Selected Answer: CE
should be C and E
upvoted 3 times
...
yana_b
1 year, 8 months ago
Selected Answer: CE
Correct answer is C&E
upvoted 1 times
...
flafernan
1 year, 9 months ago
B,C and E. The question was poorly worded and there are 3 possible options. Azure Security Center will always look for vulnerabilities in VM (Windows/Linux) and Azure key vault. There is a particular issue regarding the Azure Security Center performing vulnerability assessments on the Azure Container Registry or on images hosted there. In fact, the search for vulnerabilities will occur in the Azure Container Registry as a whole, that is, in the service itself, in the images, in the cluster, nodes and Kubernetes pods.
upvoted 2 times
...
zellck
1 year, 11 months ago
Selected Answer: CE
CE is the answer. https://learn.microsoft.com/en-us/security/benchmark/azure/security-control-vulnerability-management#51-run-automated-vulnerability-scanning-tools Follow recommendations from Azure Security Center on performing vulnerability assessments on your Azure virtual machines, container images, and SQL servers.
upvoted 7 times
...
ShomaV
1 year, 11 months ago
From chatGPT In Azure Security Center, you can receive vulnerability assessments for various resources. Some of the resources for which you can receive vulnerability assessments include: Virtual Machines, Azure App Service,Azure Kubernetes Service (AKS), Azure SQL Database, Azure Functions, Azure Container Registry and Azure Storage accounts. So Answer is C&E
upvoted 1 times
...
Ravindu
2 years ago
correct answers C & E
upvoted 2 times
...
RealRaymond
2 years ago
C,E https://learn.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-defender-vulnerability-management https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-vulnerability-assessment-azure
upvoted 1 times
...
ParkXD
2 years, 1 month ago
From ChatGPT: C. the Azure virtual machines that run the latest version of Ubuntu E. The Windows Server 2019 container images hosted in the Azure Container Registry. Azure Security Center provides vulnerability assessment for a range of resources, including virtual machines, containers, and container registries.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago