nerdexam
Microsoft

AZ-500 · Question #270

You have an Azure subscription that contains the resources shown in the following table. You plan to enable Azure Defender for the subscription. Which resources can be protected by using Azure…

The correct answer is A. VM1, VNET1, storage1, and Vault1. Explanation Option A is correct because Azure Defender (now part of Microsoft Defender for Cloud) provides protection across a wide range of Azure resource types, including Virtual Machines (VM1), Virtual Networks (VNET1), Storage Accounts (storage1), and Key Vaults (Vault1)…

Submitted by ricky.ec· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure subscription that contains the resources shown in the following table. You plan to enable Azure Defender for the subscription. Which resources can be protected by using Azure Defender?

Exhibits

AZ-500 question #270 exhibit 1
AZ-500 question #270 exhibit 2

Options

  • AVM1, VNET1, storage1, and Vault1
  • BVM1, VNET1, and storage1 only
  • CVM1, storage1, and Vault1 only
  • DVM1 and VNET1 only
  • EVM1 and storage1 only

How the community answered

(32 responses)
  • A
    91% (29)
  • B
    6% (2)
  • E
    3% (1)

Explanation

Explanation

Option A is correct because Azure Defender (now part of Microsoft Defender for Cloud) provides protection across a wide range of Azure resource types, including Virtual Machines (VM1), Virtual Networks (VNET1), Storage Accounts (storage1), and Key Vaults (Vault1) - all of which have dedicated Defender plans available.

The distractors are wrong because they each incorrectly exclude one or more resource types that Azure Defender does support: options B, C, D, and E all omit at least one valid resource (e.g., Vault1 or VNET1), suggesting those resources lack coverage, which is false - Azure Defender has specific plans for Key Vault and network-layer protections.

Key insight: Azure Defender offers individual, toggleable plans for many resource types, including VMs, Storage, SQL, Kubernetes, Container Registries, App Service, Key Vault, and DNS/network layers - so when in doubt, assume broader coverage rather than narrower.

Memory tip: Think of Azure Defender as an "umbrella" - it stretches across all major Azure resource categories, not just compute. If you see a core Azure service type (VM, Storage, Key Vault, VNet), assume Defender has a plan for it unless told otherwise.

Topics

#Microsoft Defender for Cloud#Resource protection#Compute security#Storage security

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice