nerdexam
Microsoft

AZ-500 · Question #3

Case Study 1 - Litware, Inc Overview Litware, Inc. is a digital media company that has 500 employees in the Chicago area and 20 employees in the San Francisco area. Existing Environment Litware has…

The correct answer is C. Upgrade the pricing tier of Security Center to Standard. Explanation Upgrading Azure Security Center to the Standard tier is the necessary first step because the ability to customize OS security configurations (using Security Center's OS security configuration feature) is exclusively available in the Standard pricing tier - the Free…

Submitted by saadiq_pk· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

Case Study 1 - Litware, Inc Overview Litware, Inc. is a digital media company that has 500 employees in the Chicago area and 20 employees in the San Francisco area. Existing Environment Litware has an Azure subscription named Sub1 that has a subscription ID of 43894a43-17c2- 4a39-8cfc-3540c2653ef4. Sub1 is associated to an Azure Active Directory (Azure AD) tenant named litwareinc.com. The tenant contains the user objects and the device objects of all the Litware employees and their devices. Each user is assigned an Azure AD Premium P2 license. Azure AD Privileged Identity Management (PIM) is activated. The tenant contains the groups shown in the following table. The Azure subscription contains the objects shown in the following table. Azure Security Center is set to the Free tier. Planned changes Litware plans to deploy the Azure resources shown in the following table. Litware identifies the following identity and access requirements: All San Francisco users and their devices must be members of Group1. The members of Group2 must be assigned the Contributor role to Resource Group2 by using a permanent eligible assignment. Users must be prevented from registering applications in Azure AD and from consenting to applications that access company information on the users' behalf. Platform Protection Requirements Litware identifies the following platform protection requirements: Microsoft Antimalware must be installed on the virtual machines in Resource Group1. The members of Group2 must be assigned the Azure Kubernetes Service Cluster Admin Role. Azure AD users must be to authenticate to AKS1 by using their Azure AD credentials. Following the implementation of the planned changes, the IT team must be able to connect to VM0 by using JIT VM access. A new custom RBAC role named Role1 must be used to delegate the administration of the managed disks in Resource Group1. Role1 must be available only for Resource Group1. Security Operations Requirements Litware must be able to customize the operating system security configurations in Azure Security Center. You need to ensure that you can meet the security operations requirements. What should you do first?

Options

  • ATurn on Auto Provisioning in Security Center.
  • BIntegrate Security Center and Microsoft Cloud App Security.
  • CUpgrade the pricing tier of Security Center to Standard.
  • DModify the Security Center workspace configuration.

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    6% (4)
  • C
    77% (48)
  • D
    13% (8)

Explanation

Explanation

Upgrading Azure Security Center to the Standard tier is the necessary first step because the ability to customize OS security configurations (using Security Center's OS security configuration feature) is exclusively available in the Standard pricing tier - the Free tier used by Litware does not support this capability. Without this upgrade, none of the other options can fulfill the security operations requirement, making it a prerequisite action.

Why the distractors are wrong:

  • Option A (Auto Provisioning): Auto Provisioning installs the Log Analytics agent on VMs automatically, but this alone doesn't unlock OS security configuration customization - it still requires the Standard tier.
  • Option B (Cloud App Security integration): This integration relates to cloud app discovery and threat protection, not OS security configuration customization, making it entirely irrelevant to this requirement.
  • Option D (Modify workspace configuration): Changing the workspace configuration affects where Security Center sends log data, but it does not enable the OS security customization feature without first upgrading the tier.

Memory Tip: Think of the Standard tier as the "unlock key" - whenever an exam question asks about advanced Security Center features (vulnerability assessment, OS customization, JIT access, etc.), always ask yourself: "Is the Standard tier enabled?" If not, that's your first step before anything else.

Topics

#Microsoft Defender for Cloud#Pricing Tiers#Security Configuration#Operating System Security

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice