nerdexam
Microsoft

AZ-500 · Question #280

Case Study 3 - Fabrikam, Inc General Overview Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources…

The correct answer is A. Enable Microsoft Defender for Cloud. Explanation Enabling Microsoft Defender for Cloud (formerly Azure Security Center) is the prerequisite step required before you can deploy a security policy (SecPol1), because Security Center must be active and configured in the subscription before any security policies or…

Submitted by viktor_hu· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

Case Study 3 - Fabrikam, Inc General Overview Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments. Existing Environment Network Environment Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1. The network contains an on-premises Active Directory domain named Fabrikam.com. The domain contains two organizational units (OUs) named OU1 and OU2. Azure AD Connect cloud sync syncs only OU1. The Azure resources hierarchy is shown in the following exhibit. The Azure Active Directory (Azure AD) tenant contains the users shown in the following table. Azure AD contains the resources shown in the following table. Subscription1 Resources Subscription1 contains the virtual networks shown in the following table. Subscription1 contains the network security groups (NSGs) shown in the following table. Subscription1 contains the virtual machines shown in the following table. Subscription1 contains the Azure key vaults shown in the following table. Subscription1 contains a storage account named storage1 in the West US Azure region. Planned Changes and Requirements Planned Changes Fabrikam plans to implement the following changes: Create two application security groups as shown in the following table. Associate the network interface of VM1 to ASG1. Deploy SecPol1 by using Azure Security Center. Deploy a third-party app named App1. A version of App1 exists for all available operating systems. Create a resource group named RG2. Sync OU2 to Azure AD. Add User1 to Group1. Technical Requirements Fabrikam identifies the following technical requirements: The finance department users must reauthenticate after three hours when they access SharePoint Online. Storage1 must be encrypted by using customer-managed keys and automatic key rotation. From Sentinel1, you must ensure that the following notebooks can be launched: - Entity Explorer - Account - Entity Explorer - Windows Host - Guided Investigation Process Alerts VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption. Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled. App1 must use a secure connection string stored in KeyVault1. KeyVault1 traffic must NOT travel over the internet. From Azure Security Center, you need to deploy SecPol1. What should you do first?

Exhibits

AZ-500 question #280 exhibit 1
AZ-500 question #280 exhibit 2
AZ-500 question #280 exhibit 3
AZ-500 question #280 exhibit 4
AZ-500 question #280 exhibit 5
AZ-500 question #280 exhibit 6
AZ-500 question #280 exhibit 7
AZ-500 question #280 exhibit 8
AZ-500 question #280 exhibit 9
AZ-500 question #280 exhibit 10
AZ-500 question #280 exhibit 11
AZ-500 question #280 exhibit 12

Options

  • AEnable Microsoft Defender for Cloud.
  • BCreate an Azure Management group.
  • CCreate an initiative.
  • DConfigure continuous export.

How the community answered

(30 responses)
  • A
    87% (26)
  • B
    7% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Explanation

Enabling Microsoft Defender for Cloud (formerly Azure Security Center) is the prerequisite step required before you can deploy a security policy (SecPol1), because Security Center must be active and configured in the subscription before any security policies or initiatives can be assigned and enforced through it. Without Defender for Cloud enabled, the Security Center blade won't have the functionality needed to deploy custom security policies at scale.

Why the distractors are wrong:

  • B (Create a Management Group): While management groups help organize subscriptions for policy assignment, they are not a prerequisite specifically for deploying a security policy through Security Center.
  • C (Create an initiative): An initiative is a collection of policies, but you cannot deploy it through Security Center until Security Center itself is enabled - creating one first would skip the foundational requirement.
  • D (Configure continuous export): Continuous export is used to stream Security Center data to external tools (like Log Analytics or Event Hubs) and has no bearing on deploying a security policy.

Memory Tip: Think of it as "turning on the lights before reading the map" - you must enable the platform first (Defender for Cloud) before you can configure or deploy anything within it. Whenever an exam question asks about a first step in Security Center, enabling/activating the service is almost always the answer if it hasn't been done yet.

Topics

#Microsoft Defender for Cloud#Azure Security Center#Security Policy#Initial Setup

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice