nerdexam
MicrosoftMicrosoft

AZ-500 · Question #596

AZ-500 Question #596: Real Exam Question with Answer & Explanation

The correct answer is A: the native cloud connector. With cloud workloads commonly spanning multiple cloud platforms, cloud security services must do the same. Microsoft Defender for Cloud protects workloads in Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), GitHub and Azure DevOps (ADO). To protect your AWS-based re

Submitted by andres_qro· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure subscription that uses Microsoft Defender for Cloud. You have an Amazon Web Services (AWS) account. You need to ensure that when you deploy a new AWS Elastic Compute Cloud (EC2) instance, the Microsoft Defender for Servers agent installs automatically. What should you configure first?

Options

  • Athe native cloud connector
  • Bthe classic cloud connector
  • Cthe Azure Connected Machine agent
  • Dthe Azure Monitor agent

Explanation

With cloud workloads commonly spanning multiple cloud platforms, cloud security services must do the same. Microsoft Defender for Cloud protects workloads in Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), GitHub and Azure DevOps (ADO). To protect your AWS-based resources, you can connect an AWS account with either: Native cloud connector (recommended) - Provides an agentless connection to your AWS account that you can extend with Defender for Cloud'’ Defender plans to secure your AWS resources. Classic cloud connector - Requires configuration in your AWS account to create a user that Defender for Cloud can use to connect to your AWS environment. https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws

Community Discussion

No community discussion yet for this question.

Full AZ-500 PracticeBrowse All AZ-500 Questions