AZ-500 · Question #280
Case Study 3 - Fabrikam, Inc General Overview Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources…
The correct answer is A. Enable Microsoft Defender for Cloud. Explanation Enabling Microsoft Defender for Cloud (formerly Azure Security Center) is the prerequisite step required before you can deploy a security policy (SecPol1), because Security Center must be active and configured in the subscription before any security policies or…
Question
Exhibits
Options
- AEnable Microsoft Defender for Cloud.
- BCreate an Azure Management group.
- CCreate an initiative.
- DConfigure continuous export.
How the community answered
(30 responses)- A87% (26)
- B7% (2)
- C3% (1)
- D3% (1)
Explanation
Explanation
Enabling Microsoft Defender for Cloud (formerly Azure Security Center) is the prerequisite step required before you can deploy a security policy (SecPol1), because Security Center must be active and configured in the subscription before any security policies or initiatives can be assigned and enforced through it. Without Defender for Cloud enabled, the Security Center blade won't have the functionality needed to deploy custom security policies at scale.
Why the distractors are wrong:
- B (Create a Management Group): While management groups help organize subscriptions for policy assignment, they are not a prerequisite specifically for deploying a security policy through Security Center.
- C (Create an initiative): An initiative is a collection of policies, but you cannot deploy it through Security Center until Security Center itself is enabled - creating one first would skip the foundational requirement.
- D (Configure continuous export): Continuous export is used to stream Security Center data to external tools (like Log Analytics or Event Hubs) and has no bearing on deploying a security policy.
Memory Tip: Think of it as "turning on the lights before reading the map" - you must enable the platform first (Defender for Cloud) before you can configure or deploy anything within it. Whenever an exam question asks about a first step in Security Center, enabling/activating the service is almost always the answer if it hasn't been done yet.
Topics
Community Discussion
No community discussion yet for this question.











