Enable and configure Defender for Cloud workload protection plans (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Enable and configure Defender for Cloud workload protection plans


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Defender for Cloud provides security capabilities for cloud environments from security posture management through active workload protection.

For the SC-500 exam, an important distinction is between:

  • Cloud Security Posture Management (CSPM) — identifies security weaknesses, misconfigurations, exposure, and compliance gaps.
  • Cloud Workload Protection Platform (CWPP) — provides workload-specific threat protection and security capabilities for resources such as servers, containers, databases, storage, applications, APIs, and AI services.

Defender for Cloud’s workload protection plans are enabled according to the types of workloads an organization needs to protect. These plans provide capabilities such as threat detection, vulnerability assessment, runtime protection, malware scanning, and other workload-specific security controls.

For the SC-500 exam, you should understand which Defender plan protects which workload, how to enable the plan, how to configure important plan-specific settings, how to deploy plans at scale, and how to verify coverage.


1. What Is Cloud Workload Protection?

Cloud workload protection focuses on protecting workloads while they are running, rather than simply identifying whether their configuration is secure.

For example:

WorkloadPotential Security ConcernRelevant Defender Capability
Virtual machinesMalware, vulnerabilities, suspicious activityDefender for Servers
KubernetesVulnerable containers, runtime attacksDefender for Containers
Azure StorageMalicious uploads, data threatsDefender for Storage
Azure SQLDatabase attacks and vulnerabilitiesDefender for Databases
App ServiceAttacks against web applicationsDefender for App Service
APIsAPI vulnerabilities and attacksDefender for APIs
Key VaultSuspicious access to secrets and keysDefender for Key Vault
AI servicesThreats against generative AI applicationsDefender for AI Services
Azure resource managementSuspicious resource-management operationsDefender for Resource Manager
DNSDNS-layer threatsDefender for DNS

The important SC-500 concept is that you select protection plans based on the workloads that exist in your environment.

Defender for Cloud currently provides a broad catalog of workload-specific protection plans, including servers, containers, storage, databases, Key Vault, App Service, APIs, AI Services, DNS, and Resource Manager.


2. CSPM vs. CWPP

One of the most important distinctions for the exam is the difference between CSPM and workload protection.

Cloud Security Posture Management

CSPM answers questions such as:

“Is this environment configured securely?”

Examples include:

  • Is a storage account publicly accessible?
  • Is encryption configured?
  • Is a network security control missing?
  • Does a resource violate a security policy?
  • Does the environment have excessive risk?

Defender for Cloud’s foundational CSPM capabilities include recommendations, asset inventory, workbooks, Secure Score, and Microsoft cloud security benchmark capabilities.

Cloud Workload Protection

CWPP answers questions such as:

“Is this workload currently protected against threats?”

Examples include:

  • Is a VM protected against malware and endpoint threats?
  • Is a Kubernetes cluster receiving runtime threat detection?
  • Is malicious content being detected when uploaded to storage?
  • Are suspicious database activities being detected?
  • Are API attacks being detected?
  • Are AI workloads receiving threat protection?

Exam tip:

CSPM focuses primarily on improving security posture.
CWPP focuses primarily on protecting workloads from active threats.

In real environments, the two capabilities complement each other rather than replacing one another.


3. Defender for Cloud Workload Protection Plans

Defender for Cloud contains multiple workload-specific plans.

Some of the important plans for SC-500 include:

Defender for Servers

Protects physical and virtual machines across Azure and supported multicloud environments.

Defender for Servers provides capabilities such as:

  • Threat detection
  • Endpoint protection integration
  • Vulnerability assessment
  • Security recommendations
  • Agentless scanning
  • Additional Plan 2 capabilities

Defender for Servers is available as Plan 1 (P1) and Plan 2 (P2).


Defender for Containers

Protects Kubernetes environments, including supported Azure Kubernetes Service, Amazon EKS, Google GKE, and Azure Arc-enabled Kubernetes environments.

Depending on the environment and configuration, capabilities can include:

  • Vulnerability scanning
  • Runtime threat protection
  • Security posture assessments
  • Agentless scanning
  • Defender sensor
  • Kubernetes API access
  • Registry access

The exact components available depend on the Kubernetes environment and configuration.


Defender for Storage

Defender for Storage provides security monitoring and threat detection for Azure Storage.

The current plan includes capabilities such as:

  • Activity monitoring
  • On-upload malware scanning
  • Sensitive-data threat detection

Malware scanning can also be configured with options such as scanning limits, filtering, scan-result storage, and automated integration through Event Grid or Log Analytics.


Defender for Databases

Defender for Databases protects supported database workloads.

For example, Defender for Azure SQL Databases provides attack detection and threat-response capabilities for Azure SQL databases.

The broader database protection capabilities also include support for other database workloads, depending on the specific Defender plan and supported environment.

For SQL Server running on machines, the SQL Servers on Machines protection is selected within the Defender for Databases plan.


Defender for App Service

Defender for App Service provides protection for applications running on Azure App Service.

It is designed to identify attacks targeting App Service web applications and APIs.


Defender for APIs

Defender for APIs provides security visibility and protection for APIs managed through Azure API Management.

Capabilities include:

  • API discovery
  • Security posture assessment
  • Vulnerability prioritization
  • Threat detection
  • Runtime protection

Defender for APIs is enabled at the subscription level, and the appropriate plan should be selected based on API traffic requirements.

Important exam consideration: enabling Defender for APIs does not automatically mean that every API in existence is protected. The APIs must be onboarded appropriately, and the APIs you want to protect must be published through Azure API Management.


Defender for Key Vault

Defender for Key Vault detects unusual and potentially harmful attempts to access or exploit Key Vault accounts.

This is particularly important because Key Vault can contain highly sensitive:

  • Secrets
  • Encryption keys
  • Certificates

The purpose is not simply to encrypt the vault. Defender for Key Vault adds threat-detection capabilities around access and usage.


Defender for AI Services

AI workloads introduce threats that traditional infrastructure security controls may not completely address.

Defender for AI Services provides threat protection for generative AI applications and can detect suspicious activity involving supported AI services.

For SC-500, remember:

AI workloads are now explicitly part of the Defender for Cloud workload-protection model.

This is especially relevant because the SC-500 certification focuses on cloud and AI workloads, rather than traditional cloud infrastructure alone.


Defender for Resource Manager

Defender for Resource Manager monitors Azure resource-management operations and can detect suspicious activity involving management operations.

This protects an important control plane:

The Azure Resource Manager layer through which resources are created, modified, and managed.

It is different from protecting a VM’s operating system or a storage account’s data plane.


Defender for DNS

Defender for DNS provides DNS-layer threat detection for Azure resources.

This illustrates another important Defender for Cloud concept:

Defender plans are specialized according to the attack surface being protected.


4. Choosing the Appropriate Defender Plan

A common SC-500 scenario is:

“An organization has identified a particular workload and wants to enable the appropriate Defender protection.”

The first step is to identify the workload.

For example:

RequirementAppropriate plan
Protect Azure VMsDefender for Servers
Protect AKS/KubernetesDefender for Containers
Detect malicious files uploaded to StorageDefender for Storage
Protect Azure SQL databasesDefender for Databases
Protect App Service applicationsDefender for App Service
Protect APIs managed through API ManagementDefender for APIs
Detect suspicious Key Vault accessDefender for Key Vault
Protect generative AI servicesDefender for AI Services
Detect suspicious Azure resource-management operationsDefender for Resource Manager
Detect DNS-based threatsDefender for DNS

The exam may deliberately include several plausible answers.

The key is to identify the workload, not simply the type of security problem.


5. Enabling Defender for Cloud

Before configuring individual workload protection plans, Defender for Cloud must be enabled for the relevant environment.

For Azure, Defender for Cloud can be accessed through the Azure portal.

Once the environment is available, the administrator can use:

Microsoft Defender for Cloud → Environment settings

From there, the administrator selects the relevant:

  • Azure subscription
  • AWS account
  • GCP project
  • Other supported environment/connector

The available Defender plans can then be configured for that environment.


6. Environment Settings

The Environment settings area is particularly important for SC-500.

It provides a centralized location for configuring Defender plans for the selected environment.

A typical workflow is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the target environment.
  4. Locate the desired Defender plan.
  5. Turn the plan On.
  6. Configure plan-specific settings.
  7. Save the configuration.
  8. Verify coverage.

For example, to enable Defender for Servers, you select the appropriate environment, turn on the Servers plan, choose the appropriate plan tier, and save the configuration.


7. Defender for Servers Plan 1 vs. Plan 2

Defender for Servers is especially important for the SC-500 exam because it contains two plan levels:

  • Plan 1
  • Plan 2

When enabling Defender for Servers, Plan 2 is selected by default in the current Azure portal workflow, but the administrator can change the selection to Plan 1.

The plans provide different levels of capability.

For example:

CapabilityPlan 1Plan 2
Defender for Endpoint integrationYesYes
Vulnerability assessmentYesYes
Agentless scanning—Yes
File integrity monitoring—Available
Additional advanced capabilitiesLimitedMore extensive

Current configuration guidance indicates that vulnerability assessment is enabled by default when either P1 or P2 is enabled, Defender for Endpoint integration is available with both, and agentless scanning is associated with Plan 2. File integrity monitoring is a Plan 2 capability that is not enabled by default.

Exam strategy

If a question specifically requires a Plan 2-only capability, Plan 1 is not sufficient.

Do not assume:

“Servers enabled = every Defender for Servers capability is enabled.”

Instead, identify the required capability and determine which plan provides it.


8. Configuring Defender for Servers

After enabling Defender for Servers, plan-specific settings can be configured.

Examples include:

Vulnerability assessment

Helps identify vulnerable software and applications on protected machines.

Endpoint protection

Defender for Endpoint integration provides endpoint detection and response capabilities.

Agentless scanning

Agentless scanning can provide additional visibility without requiring a traditional security agent for certain scanning scenarios.

File integrity monitoring

File integrity monitoring can identify changes to important files and registries.

The availability and default state of these capabilities depend on the selected plan.


9. Defender for Storage Configuration

Defender for Storage provides several important configurable capabilities.

The current Defender for Storage plan includes:

  • Activity monitoring
  • Malware scanning
  • Sensitive-data threat detection

Malware scanning can be configured with options such as:

  • Monthly scanning caps
  • Scan filtering
  • Blob index tags for scan results
  • Soft deletion of malicious blobs
  • Event Grid integration
  • Log Analytics integration

Example

Suppose an organization uploads customer documents to Azure Blob Storage.

The security team wants to:

  1. Detect malicious files immediately after upload.
  2. Record scan results.
  3. Automatically initiate downstream processing when malware is discovered.

Defender for Storage can provide the malware scanning capability, while Event Grid can be used to integrate scan results into automated response workflows.


10. Defender for Storage: Important Exam Distinction

Do not confuse:

Activity monitoring

with:

Malware scanning

Activity monitoring provides security analysis of activity involving storage.

Malware scanning specifically detects malicious files, including files uploaded to storage.

Similarly, sensitive-data threat detection addresses suspicious activity involving resources containing sensitive data.

Therefore, if an exam question says:

“Detect malicious files as they are uploaded to Blob Storage.”

The relevant capability is:

Defender for Storage with on-upload malware scanning.


11. Defender for Databases

Defender for Databases protects database workloads against threats and vulnerabilities.

For Azure SQL databases, Defender for Azure SQL Databases can be enabled through the Databases plan.

The administrator:

  1. Opens Defender for Cloud.
  2. Selects Environment settings.
  3. Selects the relevant environment.
  4. Locates Databases.
  5. Selects Select types.
  6. Enables Azure SQL Databases.
  7. Selects Continue.
  8. Saves the configuration.

This illustrates an important Defender for Cloud design:

A single high-level plan may contain multiple workload-specific resource types.

For example, Defender for Databases contains multiple database protection capabilities rather than representing only one specific database engine.


12. SQL Servers on Machines

SQL Server workloads may run on:

  • Azure virtual machines
  • Azure Arc-enabled servers

For SQL Servers on Machines, the protection is configured under the Defender for Databases plan.

The administrator can select the SQL Servers on Machines resource type within the Databases plan.

This is a useful exam distinction.

If a question describes:

“SQL Server installed on an Azure VM”

do not automatically treat it as the same configuration scenario as an Azure SQL Database.

The underlying workload type matters.


13. Defender for Containers

Defender for Containers protects Kubernetes environments.

Depending on the environment, administrators can configure components such as:

  • Agentless scanning
  • Defender sensor
  • Azure Policy
  • Kubernetes API access
  • Registry access

These capabilities support different aspects of container security.

For example:

Defender sensor

is associated with collecting runtime security telemetry used for threat detection.

Registry access

supports vulnerability assessment for container images in connected registries.

Azure Policy

supports Kubernetes security posture assessment and related recommendations.

Kubernetes API access

allows Defender for Cloud to obtain Kubernetes metadata required for inventory, configuration analysis, and related capabilities.


14. Defender for APIs

Defender for APIs provides protection for APIs managed through Azure API Management.

Its capabilities include:

  • Discovery
  • Security posture visibility
  • Vulnerability prioritization
  • Runtime threat detection
  • Response capabilities

One important configuration consideration is selecting the appropriate plan based on API traffic.

The current deployment guidance indicates that subscriptions are opted into Plan 1 by default and that organizations should select a plan appropriate for their API traffic volume to avoid unexpected overages.

Exam scenario

A company has a high-volume API platform.

The question asks what should be considered before selecting the Defender for APIs plan.

The best answer is likely to focus on:

API traffic volume and the plan entitlement associated with that traffic.


15. Defender for AI Services

AI workloads require specialized protection because they introduce risks beyond conventional infrastructure.

Defender for Cloud’s AI threat protection can provide:

  • AI workload discovery
  • Security posture capabilities
  • Runtime threat detection
  • Security alerts
  • Investigation capabilities

Microsoft’s current Defender for Cloud training specifically includes enabling and configuring the AI workloads plan and reviewing AI resource insights, posture, and runtime threats.

This is particularly important for SC-500 because AI security is integrated directly into the certification’s scope.


16. AI Threat Detection and Application Context

AI security can involve applications that sit between an end user and an AI service.

For example:

User → Web application → Azure OpenAI → Model

The AI service may see a request, but security investigators may need to understand:

  • Which user initiated it?
  • Which application generated it?
  • What source IP was involved?

Defender for Cloud’s AI threat protection can use additional security context to improve alert investigation. Microsoft documents the use of fields such as end-user identity, source IP, and application name for supported Azure OpenAI scenarios.

The important SC-500 concept is:

AI workload protection is not limited to infrastructure configuration; it can also provide runtime threat detection and investigation context.


17. Azure-Only vs. Multicloud Defender Plans

Not every Defender for Cloud workload plan applies to every cloud.

Some plans support Azure, AWS, and GCP workloads, while others are Azure-specific.

For example, current support information identifies these as Azure-only plans:

  • Defender for Storage
  • Defender for Key Vault
  • Defender for Resource Manager
  • Defender for DNS
  • Defender for App Service
  • Defender for APIs
  • Defender for AI Services

Defender for Servers and Defender for Containers, by contrast, have significant multicloud support.

Exam tip

If a question says:

“An organization wants to protect an AWS EC2 instance.”

Think about plans that support multicloud workloads, such as:

Defender for Servers

rather than Azure-only plans such as Defender for Storage.


18. Subscription-Level vs. Resource-Level Configuration

Defender for Cloud supports different deployment scopes depending on the plan.

A common approach is to enable a workload protection plan at the subscription level.

This is generally easier to manage and provides broader coverage.

Some scenarios also support resource-level configuration.

For example, Defender for Servers can be configured at different scopes, although Microsoft recommends subscription-level deployment for many scenarios.

However, resource-level configuration can be useful when:

  • Different workloads require different protection levels.
  • Specific resources need to be excluded.
  • An organization is transitioning workloads.
  • Different security requirements exist within the same subscription.

Important exam concept

Do not assume every Defender plan supports the same resource-level configuration options.

Always evaluate the specific plan.


19. Management Group Deployment

Large organizations often have many subscriptions.

Enabling every Defender plan manually on every subscription can be inefficient.

Defender for Cloud can be managed at larger scopes, including management groups, where supported.

This enables organizations to establish consistent protection across a portfolio of subscriptions.

The basic enterprise pattern is:

Management Group

↓

Subscriptions

↓

Workloads

The objective is centralized governance combined with consistent security coverage.


20. Deploying Defender Plans at Scale

Azure Policy can be used to help configure Defender for Cloud plans at scale.

Microsoft provides built-in policy initiatives for configuring Defender plans.

For example, there are built-in policies for:

  • Defender for Servers
  • Defender for Containers
  • Defender for Storage
  • Defender for Databases
  • Defender for APIs
  • Defender for AI Services
  • Defender CSPM
  • Other Defender capabilities

This is especially valuable when an organization wants to enforce security requirements consistently.

Example

An organization has 50 Azure subscriptions and wants Defender for Storage enabled consistently.

Instead of manually configuring each subscription, the organization can use an appropriate Azure Policy assignment to configure the plan at scale.


21. Azure Policy and Defender Plans

An important distinction is:

Azure Policy

can be used to enforce or deploy configurations.

Defender for Cloud

provides the security-management and workload-protection capabilities.

They work together.

For example, a policy can require that Defender for Storage be enabled.

The policy can evaluate the environment and deploy the appropriate configuration where applicable. Microsoft provides a built-in policy specifically for configuring Defender for Storage with its available capabilities.


22. Verifying Protection Coverage

Enabling a Defender plan is not the final step.

Security administrators should verify that the intended resources are actually covered.

Defender for Cloud provides a Coverage workbook that shows which plans are enabled and provides insight into coverage across subscriptions and resources.

A good operational workflow is:

Select plan

↓

Enable plan

↓

Configure plan-specific settings

↓

Deploy required components

↓

Verify coverage

↓

Review alerts/recommendations

↓

Remediate gaps


23. Why Verification Matters

Consider this scenario:

An administrator enables Defender for Servers at the subscription level.

They assume every VM is protected.

However:

  • Some resources may have different configuration.
  • Some resources may be excluded.
  • Required components may not be deployed.
  • Resource-level settings may override broader settings.
  • Multicloud resources may require appropriate onboarding.

Therefore:

Turning a Defender plan on is not the same thing as proving that every intended workload is protected.

The Coverage workbook is designed to help validate the actual deployment state.


24. Monitoring Workload Protection

Defender for Cloud provides workload protection insights and security alerts.

The Workload protections area can show the status of advanced protection for workloads such as:

  • Virtual machines
  • SQL databases
  • Containers
  • Web applications
  • Other supported workload types

Security alerts can provide:

  • Affected resource
  • Threat information
  • Suggested remediation
  • Additional investigation information
  • In some cases, automated response options

This allows security teams to move from:

Protection configuration

to:

Threat detection and response


25. Important Licensing and Cost Considerations

Many workload protection plans are paid capabilities.

Before enabling a plan broadly, an organization should understand:

  • Which workloads will be protected
  • Which features will be enabled
  • Which resources are in scope
  • Whether the plan has multiple tiers
  • Whether optional features incur additional costs
  • Expected usage
  • How long the plan will remain enabled

For example, Defender for Storage includes configurable malware-scanning capabilities, and Defender for APIs has plan selection considerations based on API traffic.

Exam strategy

If a scenario asks for the best security configuration, do not automatically choose the least expensive option.

First satisfy the security requirement.

If the question specifically introduces cost as a constraint, then cost becomes part of the decision.


26. Common SC-500 Workload Protection Scenarios

Scenario 1 — Virtual machines

Requirement: Detect vulnerabilities and protect Azure VMs.

Solution: Defender for Servers.


Scenario 2 — Kubernetes

Requirement: Detect container vulnerabilities and runtime threats in AKS.

Solution: Defender for Containers.


Scenario 3 — Malicious file uploads

Requirement: Detect malicious files uploaded to Blob Storage.

Solution: Defender for Storage with malware scanning.


Scenario 4 — Azure SQL

Requirement: Detect suspicious activity against Azure SQL databases.

Solution: Defender for Databases with Azure SQL Database protection enabled.


Scenario 5 — SQL Server on VM

Requirement: Protect SQL Server running on an Azure VM.

Solution: Configure the SQL Servers on Machines capability within Defender for Databases.


Scenario 6 — API attacks

Requirement: Discover and detect threats against APIs hosted through Azure API Management.

Solution: Defender for APIs.


Scenario 7 — AI threats

Requirement: Detect runtime threats targeting generative AI services.

Solution: Defender for AI Services.


Scenario 8 — Suspicious Azure management activity

Requirement: Detect suspicious Azure resource-management operations.

Solution: Defender for Resource Manager.


27. Common Mistakes to Avoid

Mistake 1: Confusing CSPM with workload protection

CSPM identifies posture weaknesses.

CWPP provides workload-specific protection.


Mistake 2: Enabling the wrong plan

A plan should be selected based on the workload being protected.


Mistake 3: Assuming one Defender plan protects everything

Defender for Cloud uses specialized plans for different workload categories.


Mistake 4: Assuming “On” means every feature is enabled

Some plans contain configurable components and tiers.


Mistake 5: Ignoring plan tiers

Defender for Servers has P1 and P2.

If a scenario requires a Plan 2 capability, enabling P1 is insufficient.


Mistake 6: Forgetting multicloud scope

Some Defender plans support AWS and GCP while others are Azure-only.


Mistake 7: Ignoring API traffic

Defender for APIs plan selection should take API traffic volume into account.


Mistake 8: Forgetting Storage malware scanning

Enabling Defender for Storage and enabling/configuring malware scanning are related but distinct considerations.


Mistake 9: Failing to verify coverage

Always verify that intended workloads are actually protected.


Mistake 10: Treating recommendations as runtime protection

A security recommendation identifies a security weakness.

A workload protection plan provides additional protection against threats.

They complement one another.


28. SC-500 Exam Comparison Table

RequirementThink About
Improve overall cloud security postureCSPM
Improve Secure ScoreCSPM
Identify misconfigurationsCSPM
Protect Azure VMsDefender for Servers
Protect KubernetesDefender for Containers
Detect malicious files in StorageDefender for Storage
Protect Azure SQLDefender for Databases
Protect SQL Server on machinesDefender for Databases → SQL Servers on Machines
Protect App ServiceDefender for App Service
Protect APIsDefender for APIs
Protect Key VaultDefender for Key Vault
Protect generative AI servicesDefender for AI Services
Detect suspicious Azure management activityDefender for Resource Manager
Detect DNS threatsDefender for DNS
Apply configuration consistently at scaleAzure Policy
Verify plan/resource coverageCoverage workbook

29. Recommended Deployment Method

For an enterprise environment, a strong implementation approach is:

Step 1 — Inventory workloads

Identify:

  • VMs
  • Containers
  • Storage
  • Databases
  • APIs
  • App Services
  • Key Vaults
  • AI services
  • Other cloud workloads

Step 2 — Map workloads to Defender plans

Determine which workload protection plan applies to each workload.

Step 3 — Determine scope

Decide whether protection should apply at:

  • Management group
  • Subscription
  • Resource
  • Connected multicloud environment

Step 4 — Select appropriate tiers

For plans with multiple tiers, select the tier that satisfies the security requirement.

Step 5 — Configure plan-specific features

Examples include:

  • Server vulnerability assessment
  • Server agentless scanning
  • Storage malware scanning
  • Storage sensitive-data detection
  • Container runtime protection
  • Container registry scanning
  • API plan selection
  • AI threat protection

Step 6 — Automate deployment

Use Azure Policy where appropriate to establish consistent deployment at scale.

Step 7 — Verify coverage

Use Defender for Cloud’s Coverage workbook.

Step 8 — Monitor

Review:

  • Security alerts
  • Recommendations
  • Coverage
  • Workload protection status

Step 9 — Remediate

Address identified vulnerabilities and configuration gaps.


30. Key Takeaways

For the SC-500 exam, remember these principles:

  1. Defender for Cloud combines CSPM and workload protection capabilities.
  2. CWPP plans are workload-specific.
  3. Choose the Defender plan based on the workload that needs protection.
  4. Defender for Servers has Plan 1 and Plan 2.
  5. Plan 2 provides additional advanced server protection capabilities.
  6. Defender for Storage can provide malware scanning and sensitive-data threat detection.
  7. Defender for Databases protects supported database workloads.
  8. Defender for Containers protects Kubernetes environments.
  9. Defender for APIs protects APIs managed through Azure API Management.
  10. Defender for AI Services provides specialized protection for supported AI workloads.
  11. Not every Defender plan supports AWS and GCP.
  12. Azure Policy can help deploy Defender plans consistently at scale.
  13. Enabling a plan is not the same as verifying coverage.
  14. Use the Coverage workbook to validate deployment coverage.
  15. Always distinguish posture management from active workload protection.

The central exam concept is simple:

Identify the workload → select the appropriate Defender plan → choose the required tier/features → deploy at the appropriate scope → verify coverage → monitor and remediate.


Practice Exam Questions

Question 1

An organization has several Azure virtual machines. The security team wants to detect vulnerabilities, integrate endpoint protection, and provide additional threat protection for the machines.

Which Microsoft Defender for Cloud plan should the organization enable?

A. Defender for Servers

B. Defender for Storage

C. Defender for APIs

D. Defender for Key Vault

Answer: A. Defender for Servers

Explanation: Defender for Servers is the workload protection plan designed for server and machine workloads. It provides capabilities such as vulnerability assessment and Defender for Endpoint integration. Defender for Storage protects storage accounts, Defender for APIs protects APIs, and Defender for Key Vault protects Key Vault resources.


Question 2

A security administrator needs to protect an AKS environment against container vulnerabilities and runtime threats.

Which Defender for Cloud plan should be configured?

A. Defender for App Service

B. Defender for Resource Manager

C. Defender for Servers

D. Defender for Containers

Answer: D. Defender for Containers

Explanation: Defender for Containers is designed to protect Kubernetes environments such as AKS. Depending on the configuration, it can provide vulnerability assessment, runtime threat protection, posture assessment, agentless scanning, registry assessment, and other Kubernetes security capabilities. Defender for Servers is intended primarily for machine workloads.


Question 3

A company uploads documents to Azure Blob Storage. The security team wants Defender for Cloud to identify malicious files when they are uploaded.

Which capability should be configured?

A. Defender for Storage malware scanning

B. Defender for Databases

C. Defender for Key Vault

D. Defender for APIs

Answer: A. Defender for Storage malware scanning

Explanation: Defender for Storage provides on-upload malware scanning for supported storage workloads. The capability is specifically intended to detect malicious files uploaded to storage. Defender for Key Vault, Databases, and APIs address different workload types.


Question 4

An organization enables Defender for Servers and needs a capability that is associated with Plan 2 rather than Plan 1.

Which plan should the organization select?

A. Foundational CSPM

B. Defender for Servers Plan 1

C. Defender CSPM

D. Defender for Servers Plan 2

Answer: D. Defender for Servers Plan 2

Explanation: Defender for Servers has Plan 1 and Plan 2. Plan 2 provides additional advanced capabilities, including agentless scanning. File integrity monitoring is also available as a Plan 2 capability, although it isn’t enabled by default.


Question 5

A company uses Azure API Management and wants to discover APIs, assess their security posture, prioritize API vulnerabilities, and detect active API threats.

Which Defender for Cloud plan should be used?

A. Defender for APIs

B. Defender for App Service

C. Defender for Containers

D. Defender for Resource Manager

Answer: A. Defender for APIs

Explanation: Defender for APIs provides discovery, security posture visibility, vulnerability prioritization, and runtime threat detection for APIs managed through Azure API Management. The APIs must be appropriately onboarded, and plan selection should account for API traffic requirements.


Question 6

An organization wants to apply Microsoft Defender for Cloud workload protection configurations consistently across a large number of Azure subscriptions.

Which service is most appropriate for enforcing configuration at scale?

A. Azure Bastion

B. Azure Policy

C. Azure Monitor

D. Azure DNS

Answer: B. Azure Policy

Explanation: Azure Policy can be used to enforce and deploy security configurations consistently across Azure resources and subscriptions. Microsoft provides built-in policy definitions and initiatives for configuring various Defender for Cloud plans, including Defender for Servers, Storage, Containers, APIs, AI Services, and others.


Question 7

A security engineer wants to verify which subscriptions and resources are actually covered by the Defender for Cloud plans that have been enabled.

Which capability should the engineer use?

A. Secure Score

B. Regulatory Compliance dashboard

C. Coverage workbook

D. Azure Service Health

Answer: C. Coverage workbook

Explanation: The Defender for Cloud Coverage workbook provides visibility into which Defender plans are enabled and the resulting coverage across subscriptions and resources. This is particularly important because simply enabling a plan does not necessarily mean that every intended workload has been successfully protected.


Question 8

A company is deploying a generative AI application and wants specialized Defender for Cloud protection that can identify threats targeting supported AI services.

Which plan should the security team consider?

A. Defender for DNS

B. Defender for Key Vault

C. Defender for Storage

D. Defender for AI Services

Answer: D. Defender for AI Services

Explanation: Defender for AI Services provides specialized threat protection for supported generative AI services and applications. Defender for Cloud’s AI protection capabilities can provide discovery, posture assessment, runtime threat detection, and investigation capabilities for AI workloads.


Question 9

An organization has an Azure SQL Database and wants to enable Defender for Cloud’s attack detection and threat-response capabilities for that database.

Which configuration should the administrator use?

A. Defender for Databases with Azure SQL Databases enabled

B. Defender for Servers Plan 2

C. Defender for Storage

D. Defender for Containers

Answer: A. Defender for Databases with Azure SQL Databases enabled

Explanation: Azure SQL Database protection is configured through the Defender for Databases plan. The administrator selects the Databases plan and enables the Azure SQL Databases resource type. Defender for Servers is intended for machine workloads, while Storage and Containers address different workload categories.


Question 10

An organization has connected its AWS environment to Microsoft Defender for Cloud. The security team wants to protect Windows and Linux EC2 instances against threats.

Which Defender for Cloud plan is the best fit?

A. Defender for Storage

B. Defender for Servers

C. Defender for APIs

D. Defender for AI Services

Answer: B. Defender for Servers

Explanation: Defender for Servers supports multicloud machine workloads, including supported AWS and GCP machines. AWS and GCP machines use the appropriate Defender for Cloud onboarding mechanisms, including Azure Arc for supported server scenarios. Azure-only plans such as Defender for Storage, APIs, and AI Services are not the appropriate choice for protecting EC2 machines.


Final SC-500 Exam Reminder

When you see a Defender for Cloud workload-protection question, first ask:

“What workload am I protecting?”

Then map it to the appropriate plan:

Servers → Defender for Servers

Containers/Kubernetes → Defender for Containers

Storage → Defender for Storage

Databases → Defender for Databases

App Service → Defender for App Service

APIs → Defender for APIs

Key Vault → Defender for Key Vault

AI Services → Defender for AI Services

Resource management → Defender for Resource Manager

DNS → Defender for DNS

Then determine whether the question requires a particular plan tier, feature, deployment scope, or configuration option.

Finally, remember to verify actual coverage rather than assuming that enabling the plan means the deployment is complete.

This topic is important for SC-500 because Microsoft is increasingly treating AI workloads as a first-class security workload, so I would expect questions to test not only the traditional Servers/Storage/Databases/Containers plans but also Defender for AI Services, Defender for APIs, plan-specific configuration, and coverage verification.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply