Configure Microsoft Defender Vulnerability Management settings for Azure VMs (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Configure Microsoft Defender Vulnerability Management settings for Azure VMs


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Defender Vulnerability Management (MDVM) is an important component of the security capabilities provided by Microsoft Defender for Cloud and Microsoft Defender for Servers. It helps security teams discover vulnerabilities in software installed on virtual machines, prioritize those vulnerabilities, and take action to reduce the organization’s exposure to known security risks.

One important current distinction is that Microsoft Defender Vulnerability Management (MDVM) is natively integrated with Defender for Servers, and Azure VM vulnerability scanning can now use both agent-based and agentless approaches depending on the Defender for Servers plan and configuration.

For the SC-500 exam, it is important to understand more than simply what a vulnerability scanner does. You should understand:

  • How Defender Vulnerability Management integrates with Defender for Servers
  • The difference between agent-based and agentless vulnerability scanning
  • The relationship between Defender for Servers Plan 1 (P1) and Plan 2 (P2)
  • How vulnerability assessment is enabled at subscription and machine scope
  • How to review vulnerability findings
  • How CVEs and severity information are used to prioritize remediation
  • How vulnerability findings can be managed when an organization has an accepted risk
  • The additional MDVM capabilities available with Defender for Servers Plan 2
  • How security baseline assessment and vulnerable application blocking fit into the overall solution

The current SC-500 study guide specifically includes configuring Defender for Servers settings such as vulnerability scanning and EDR, as well as implementing agentless VM scanning.


1. What Is Microsoft Defender Vulnerability Management?

Microsoft Defender Vulnerability Management is Microsoft’s vulnerability-management capability for continuously discovering and assessing vulnerabilities and helping organizations prioritize remediation.

Within Defender for Cloud, MDVM is integrated with Microsoft Defender for Endpoint and Defender for Servers.

This integration provides capabilities such as:

  • Software inventory
  • Vulnerability discovery
  • Vulnerability assessment
  • CVE identification
  • Risk-based prioritization
  • Security recommendations
  • Vulnerability remediation
  • Security baseline assessment
  • Premium vulnerability-management capabilities with Defender for Servers Plan 2

For servers protected by Defender for Servers, Defender Vulnerability Management is integrated natively rather than requiring a completely separate Microsoft vulnerability-management product.

Important SC-500 concept

Think of the relationship as:

Defender for Servers → integrates Defender for Endpoint + Defender Vulnerability Management

This allows Defender for Cloud to provide both:

Threat protection

and

Vulnerability management

for supported machines.


2. What Does Defender Vulnerability Management Scan?

Defender Vulnerability Management identifies vulnerabilities associated with software and configurations on machines.

For example, suppose an Azure VM is running:

  • Windows Server
  • IIS
  • .NET
  • Java
  • A third-party application

A vulnerability-management solution can identify vulnerable versions of installed software and associate them with known vulnerabilities such as Common Vulnerabilities and Exposures (CVEs).

Defender for Cloud then surfaces vulnerability information and recommendations that security teams can investigate and remediate.

A useful way to think about the process is:

Discover → Assess → Prioritize → Remediate → Verify


3. Defender Vulnerability Management and Defender for Servers

Defender Vulnerability Management scanning for Azure VMs is provided through the Defender for Servers plan.

Current Defender for Cloud documentation describes two primary vulnerability-scanning approaches:

CapabilityDefender for Servers Plan 1Defender for Servers Plan 2
Defender Vulnerability Management integrationYesYes
Agent-based vulnerability scanningYesYes
Agentless vulnerability scanningNoYes
Premium MDVM capabilitiesNoYes
Security baseline assessmentNoYes
Vulnerable application blockingNoYes
Other advanced Defender for Servers capabilitiesLimitedExpanded

Defender for Servers Plan 2 includes the capabilities of Plan 1 plus additional functionality, including agentless scanning and premium Defender Vulnerability Management capabilities.

Exam tip

A common SC-500 question pattern is:

An organization wants vulnerability scanning without depending on an agent installed inside the VM. Which capability should be considered?

The key concept is:

Agentless vulnerability scanning → Defender for Servers Plan 2


4. Agent-Based Vulnerability Scanning

Agent-based scanning uses the Microsoft Defender for Endpoint integration.

The Defender for Endpoint sensor provides information that Defender Vulnerability Management can use to assess the machine.

Agent-based vulnerability scanning is available with:

  • Defender for Servers Plan 1
  • Defender for Servers Plan 2

The Defender for Endpoint integration is enabled by default when Defender for Servers is enabled, although individual plan settings can be modified.

Advantages

Agent-based scanning can provide:

  • Continuous vulnerability information
  • Software inventory
  • Vulnerability information
  • Endpoint security integration
  • Additional threat-detection capabilities through Defender for Endpoint

It is particularly useful when the organization already uses the Defender for Endpoint sensor as part of its endpoint-security architecture.


5. Agentless Vulnerability Scanning

Agentless scanning provides vulnerability visibility without requiring the traditional endpoint sensor for the vulnerability assessment itself.

This is particularly valuable when organizations want broader coverage while minimizing the need to install and maintain agents.

According to the current Defender for Cloud documentation, agentless vulnerability scanning is available with Defender for Servers Plan 2. It is also enabled by default when Defender for Servers Plan 2 or the Defender CSPM plan is enabled, subject to applicable requirements.

Why is agentless scanning important?

Consider an organization with hundreds of Azure VMs.

Installing and maintaining agents on every machine may introduce:

  • Deployment effort
  • Operational overhead
  • Additional dependencies
  • Potential compatibility concerns

Agentless scanning can provide vulnerability visibility without requiring the same agent-based deployment model.


6. Agent-Based vs. Agentless Scanning

This distinction is especially important for SC-500.

CharacteristicAgent-BasedAgentless
Requires Defender for Endpoint sensorYesNo
Defender for Servers P1SupportedNot supported
Defender for Servers P2SupportedSupported
Provides vulnerability assessmentYesYes
Software inventoryYesYes
Useful when minimizing agentsLess suitableHighly suitable
Included with P2YesYes

The current Defender for Cloud implementation can also use a hybrid approach. If a machine has both agent-based and agentless scanning available, Defender for Cloud can use the agent-based results because they provide greater data freshness.

Exam scenario

If a question says:

A VM has both Defender for Endpoint-based scanning and agentless scanning available. Which results should you generally expect Defender for Cloud to use?

The important concept is:

Agent-based results take precedence because they provide better freshness.


7. Enabling Vulnerability Scanning at Subscription Scope

Vulnerability scanning can be configured for an Azure subscription through Defender for Cloud.

A typical configuration process is:

  1. Open Microsoft Defender for Cloud.
  2. Open Environment settings.
  3. Select the Azure subscription.
  4. Locate Defender for Servers.
  5. Open the relevant monitoring/settings configuration.
  6. Locate Vulnerability assessment for machines.
  7. Configure the vulnerability-assessment solution.
  8. Apply and save the configuration.

Current Microsoft documentation indicates that vulnerability scanning is enabled by default when Defender for Servers is enabled, although administrators can manually configure the vulnerability-assessment settings when required.

Important distinction

There are two related concepts:

Enabling Defender for Servers

and

Configuring the vulnerability-assessment behavior

Enabling Defender for Servers provides the overall server-protection framework, while the vulnerability-assessment settings determine how vulnerability scanning is configured.


8. Configuring Vulnerability Scanning for an Individual VM

Although configuring protection at subscription scope is generally preferable for consistent security management, Defender for Cloud also supports resource-level configuration.

This can be useful when:

  • Different VMs require different protection levels
  • An organization is gradually onboarding machines
  • Certain workloads require exceptions
  • Different server populations use different Defender for Servers plans

If a VM does not have an appropriate vulnerability assessment solution, Defender for Cloud can generate the recommendation:

Machines should have a vulnerability assessment solution

Administrators can use the recommendation to identify affected machines and configure a vulnerability solution.


9. Required Permissions

Permissions matter when configuring vulnerability scanning.

Current Microsoft guidance identifies:

  • Owner permissions at the resource-group level are required to deploy the scanner.
  • Security Reader permissions are sufficient to view vulnerability findings.

This illustrates an important security principle:

The person who needs to view vulnerability information does not necessarily need the permissions required to deploy or change vulnerability scanning.

This follows the principle of least privilege.


10. Reviewing Vulnerability Findings

Once vulnerability scanning is active, security teams need to interpret and prioritize the findings.

Defender for Cloud surfaces vulnerability information that can include:

  • Vulnerable machines
  • Affected software
  • CVEs
  • Severity
  • Remediation recommendations
  • Related security information

The Defender Vulnerability Management experience also provides broader vulnerability-management capabilities through the Microsoft Defender portal and Exposure Management.


11. Understanding CVEs

A Common Vulnerabilities and Exposures (CVE) identifier provides a standardized identifier for a publicly known vulnerability.

For example:

CVE-YYYY-NNNNN

can identify a specific vulnerability affecting a particular product or component.

When reviewing a vulnerability finding, security professionals should not simply look at the number of vulnerabilities.

Instead, they should consider:

  • Vulnerability severity
  • Affected asset
  • Business importance of the asset
  • Exploitability
  • Exposure
  • Attack-path information
  • Available remediation
  • Whether the vulnerability is actively being exploited

This helps organizations prioritize the vulnerabilities that present the greatest practical risk.


12. CVSS Scores

Vulnerability findings can also contain Common Vulnerability Scoring System (CVSS) information.

CVSS provides a standardized way to communicate the severity of a vulnerability.

For example:

CVSSGeneral interpretation
LowLower severity
MediumModerate severity
HighSignificant severity
CriticalExtremely serious vulnerability

However, organizations should avoid treating CVSS as the only factor in remediation decisions.

A medium-severity vulnerability on an internet-facing production server could be more important to an organization than a critical vulnerability on an isolated development VM.

Modern Defender Vulnerability Management therefore emphasizes risk-based prioritization rather than simply sorting vulnerabilities by CVSS score.


13. Vulnerability Findings as Defender for Cloud Recommendations

Defender for Cloud presents vulnerability findings as recommendations.

For example:

Machines should have vulnerability findings resolved

can identify machines with vulnerabilities requiring attention.

The recommendation experience can provide:

  • Affected resources
  • Vulnerability information
  • CVEs
  • Severity
  • Remediation guidance

Administrators can investigate individual resources or examine findings across the environment.


14. Managing Accepted Risk

Not every vulnerability can immediately be remediated.

For example, an organization might determine that:

  • A vulnerable application cannot yet be upgraded.
  • The vulnerability affects a legacy application.
  • The vulnerability is not exploitable in the organization’s environment.
  • Compensating controls reduce the risk.
  • The vulnerability is below an organization’s defined risk threshold.

In these situations, organizations need a controlled way to manage exceptions.

Historically, Defender for Cloud provided disable rules for suppressing selected vulnerability findings.

However, current Microsoft guidance states that disable rules are being deprecated as part of the transition from grouped recommendations to individual recommendations, with recommendation exemptions becoming the preferred approach for managing exceptions.

Exam consideration

If a question is based on current functionality and asks how an organization should manage an accepted recommendation exception, understand the transition toward:

Recommendation exemptions

rather than assuming older disable-rule terminology is always the current answer.


15. Defender for Servers Plan 2 Premium Vulnerability Management

One of the most important reasons an organization might select Defender for Servers Plan 2 is access to additional vulnerability-management capabilities.

Current Defender documentation identifies premium capabilities associated with Plan 2, including:

  • Security baseline assessment
  • Vulnerable application blocking
  • Additional inventory and assessment capabilities
  • Additional remediation and mitigation functionality

These capabilities go beyond simply identifying CVEs.


16. Security Baseline Assessment

Security baseline assessment evaluates machines against defined security configuration profiles.

The goal is to determine whether a machine is configured according to an organization’s desired security posture.

For example, an organization might establish a baseline requiring:

  • Specific security settings
  • Appropriate authentication configuration
  • Required system protections
  • Secure operating-system configuration

Current Microsoft documentation identifies Defender Vulnerability Management security baseline assessment as a Plan 2 capability and notes that this assessment capability is currently in public preview.

Important distinction

Vulnerability assessment asks:

“Is the software or system vulnerable?”

Security baseline assessment asks:

“Is the system configured according to the desired security baseline?”

These are related but different security questions.


17. Vulnerable Application Blocking

Defender Vulnerability Management premium capabilities can also provide mechanisms for dealing with vulnerable applications.

Vulnerable application blocking is designed to reduce exploitation risk by preventing vulnerable applications from running under supported scenarios.

This is different from simply generating a vulnerability report.

The progression is approximately:

Discover vulnerability → Assess risk → Recommend remediation → Mitigate exploitation

Vulnerable application blocking therefore represents a more proactive mitigation capability.

It is associated with the premium Defender Vulnerability Management capabilities available through Defender for Servers Plan 2.


18. Defender for Servers Plan 1 vs. Plan 2

For the SC-500 exam, memorize the conceptual differences rather than attempting to memorize every individual feature.

CapabilityPlan 1Plan 2
Defender for Endpoint integrationYesYes
Agent-based vulnerability assessmentYesYes
Agentless machine scanningNoYes
Premium MDVM capabilitiesNoYes
Security baseline assessmentNoYes
Vulnerable application blockingNoYes
Advanced server protectionMore limitedMore comprehensive

Exam shortcut

When the question emphasizes:

“agentless vulnerability scanning”

think:

Plan 2

When it emphasizes:

“premium Defender Vulnerability Management capabilities”

think:

Plan 2

When it simply asks whether Defender Vulnerability Management-based vulnerability scanning is available with Defender for Servers:

Plan 1 and Plan 2


19. What Happens When Agent-Based and Agentless Scanning Overlap?

This is an excellent potential exam scenario.

Suppose:

  • Defender for Servers Plan 2 is enabled.
  • Agentless scanning is enabled.
  • Defender for Endpoint is also installed and reporting vulnerability information.

Both methods may be available.

Defender for Cloud uses a hybrid behavior.

If both scanning methods provide results, agent-based results are preferred because they provide better data freshness.

This does not mean agentless scanning is unnecessary. It can extend coverage to machines that do not have an agent-based vulnerability-scanning solution.


20. Bring Your Own License Vulnerability Scanners

Organizations that already use another vulnerability-management product can use a supported Bring Your Own License (BYOL) vulnerability scanner.

Current Defender for Cloud documentation identifies supported partner solutions such as:

  • Qualys
  • Rapid7

The partner solution reports vulnerability data to its management platform, and vulnerability information can be surfaced through Defender for Cloud.

Important exam distinction

The integrated Microsoft solution is:

Microsoft Defender Vulnerability Management

A BYOL deployment is:

A supported third-party vulnerability assessment solution

These are alternative vulnerability-assessment approaches rather than two scanners that an organization necessarily needs to run simultaneously.

Only one BYOL scanner is supported for a machine.


21. Hybrid Behavior with BYOL Scanners

Defender for Cloud can combine different vulnerability-scanning capabilities depending on the machine’s configuration.

Current behavior includes:

  • If there is no agent-based scanner, agentless scanning can provide results where supported.
  • If Defender Vulnerability Management is integrated through Defender for Endpoint, Defender for Cloud can use the agent-based results.
  • If a supported BYOL scanner is installed, partner results generally take precedence.
  • Agentless results can be used for machines that do not have the partner scanner or are not reporting findings correctly.
  • Organizations can configure vulnerability-scanning behavior to use Defender Vulnerability Management results where appropriate.

This is an area where exam questions may test your understanding of which scanning method takes precedence rather than simply asking what each scanner does.


22. Vulnerability Scanning Is Not the Same as Network Vulnerability Scanning

Another important distinction:

The integrated Defender Vulnerability Management scanner focuses on vulnerabilities on the machine itself.

It does not function as a general network-vulnerability scanner that scans the entire network for network-device vulnerabilities.

Therefore:

“Find vulnerable software installed on this VM”

is a Defender Vulnerability Management use case.

Whereas:

“Scan the entire network for vulnerable network devices”

is a different security requirement.


23. Relationship Between Vulnerability Management and EDR

Endpoint Detection and Response (EDR) and vulnerability management address different security problems.

Defender for Endpoint / EDR

Focuses on detecting and responding to threats.

Examples include:

  • Suspicious behavior
  • Malware
  • Attacks
  • Endpoint incidents
  • Security alerts

Defender Vulnerability Management

Focuses on exposure and weaknesses.

Examples include:

  • Vulnerable software
  • Missing security updates
  • Vulnerable applications
  • Security recommendations
  • Risk prioritization

Defender for Servers integrates these capabilities to provide a more comprehensive security solution for protected machines.


24. A Practical Configuration Strategy

A good implementation strategy can be summarized as follows.

Step 1 — Enable Defender for Cloud

Ensure the Azure subscription is onboarded to Defender for Cloud.

Step 2 — Select Defender for Servers

Determine whether the organization needs:

  • Plan 1
  • Plan 2

Step 3 — Determine the scanning approach

Decide whether vulnerability assessment should use:

  • Agent-based scanning
  • Agentless scanning
  • A supported BYOL solution

Step 4 — Configure vulnerability assessment

Use Defender for Cloud Environment settings to configure vulnerability assessment for the appropriate subscription.

Step 5 — Validate machine coverage

Review the affected VMs and ensure vulnerability scanning is active.

Step 6 — Review findings

Analyze:

  • CVEs
  • Severity
  • Affected software
  • Affected machines
  • Remediation guidance

Step 7 — Prioritize

Prioritize vulnerabilities based on actual organizational risk, not simply CVSS score.

Step 8 — Remediate

Apply patches, update applications, modify configurations, or apply other compensating controls.

Step 9 — Handle accepted risks

Where remediation is not currently possible, use the appropriate recommendation-exemption mechanism according to current Defender for Cloud functionality.

Step 10 — Consider Plan 2 capabilities

For higher-security environments, evaluate:

  • Agentless scanning
  • Security baseline assessment
  • Vulnerable application blocking
  • Other premium Defender Vulnerability Management capabilities

25. Common Mistakes to Avoid

Mistake 1: Assuming Plan 1 provides agentless vulnerability scanning

It does not.

Agentless vulnerability scanning is associated with Plan 2.

Mistake 2: Assuming Plan 2 eliminates agent-based scanning

It does not.

Plan 2 supports both agent-based and agentless approaches.

Mistake 3: Confusing vulnerability management with EDR

Vulnerability management identifies weaknesses.

EDR detects and responds to active threats.

Mistake 4: Treating CVSS as the only prioritization factor

CVSS is important, but modern vulnerability management also considers contextual risk.

Mistake 5: Assuming every vulnerability should immediately be remediated

Some vulnerabilities may require documented risk acceptance or compensating controls.

Mistake 6: Confusing vulnerability assessment with network scanning

Defender Vulnerability Management focuses on vulnerabilities associated with the machine and its software.

Mistake 7: Forgetting resource scope

Defender for Servers and vulnerability assessment can be configured at subscription level, while resource-level configurations can be used for specific scenarios.

Mistake 8: Using outdated disable-rule assumptions

Microsoft is transitioning away from disable rules toward recommendation exemptions for managing exceptions.


26. SC-500 Exam-Focused Comparison

Requirement in the scenarioMost relevant concept
Scan VM vulnerabilities using Defender for EndpointAgent-based MDVM
Scan VMs without relying on an endpoint agentAgentless scanning
Enable agentless vulnerability scanningDefender for Servers Plan 2
Obtain premium MDVM capabilitiesDefender for Servers Plan 2
Assess security configuration against baselinesSecurity baseline assessment
Prevent vulnerable applications from runningVulnerable application blocking
View vulnerability informationSecurity Reader can view findings
Deploy scanner/configurationAppropriate administrative permissions, including Owner at required scope
Identify known software vulnerabilitiesMDVM
Detect active endpoint threatsDefender for Endpoint/EDR
Use an existing Qualys or Rapid7 solutionBYOL vulnerability assessment
Identify a known vulnerabilityCVE
Assess vulnerability severityCVSS and contextual risk
Manage accepted exceptionsRecommendation exemptions

27. Key Takeaways

For the SC-500 exam, remember these core concepts:

  1. Microsoft Defender Vulnerability Management is integrated with Defender for Servers.
  2. Defender for Servers Plan 1 supports agent-based vulnerability scanning.
  3. Defender for Servers Plan 2 supports both agent-based and agentless vulnerability scanning.
  4. Agentless vulnerability scanning is a major Plan 2 capability.
  5. If both agent-based and agentless results are available, agent-based results are generally preferred because of their freshness.
  6. Defender Vulnerability Management identifies software vulnerabilities and provides remediation information.
  7. CVEs identify known vulnerabilities; CVSS helps communicate severity.
  8. Risk prioritization should consider organizational context rather than relying exclusively on CVSS.
  9. Security baseline assessment is different from vulnerability assessment.
  10. Premium Defender Vulnerability Management capabilities, including security baseline assessment and vulnerable application blocking, are associated with Defender for Servers Plan 2.
  11. Qualys and Rapid7 are examples of supported BYOL vulnerability-assessment solutions.
  12. Vulnerability assessment is not the same thing as network vulnerability scanning.
  13. Defender Vulnerability Management complements Defender for Endpoint/EDR rather than replacing it.
  14. Current Defender for Cloud functionality is moving toward recommendation exemptions rather than older disable-rule mechanisms.

The most important mental model is:

Defender for Servers provides the server-protection framework; Defender Vulnerability Management identifies and prioritizes vulnerabilities; Defender for Endpoint provides endpoint protection and threat detection; Plan 2 adds agentless scanning and premium vulnerability-management capabilities.


Practice Exam Questions

Question 1

An organization has 500 Azure virtual machines protected by Microsoft Defender for Servers. The security team wants to identify software vulnerabilities but does not want the vulnerability assessment process to depend on installing an agent on every VM.

Which capability should the organization use?

A. Agentless vulnerability scanning with Defender for Servers Plan 2

B. Defender for Endpoint Plan 1 only

C. Microsoft Sentinel analytics rules

D. Azure Network Watcher

Answer: A

Explanation

A is correct. Defender for Servers Plan 2 supports agentless vulnerability scanning, which allows Defender Vulnerability Management to assess supported machines without relying on the traditional agent-based vulnerability-scanning approach. Agentless scanning is a key distinction between Plan 1 and Plan 2.

B is incorrect because Defender for Endpoint is associated with the agent-based approach and does not provide the requested agentless architecture.

C is incorrect because Microsoft Sentinel is primarily a SIEM/security analytics platform rather than a VM vulnerability scanner.

D is incorrect because Network Watcher provides network monitoring and diagnostics, not software vulnerability assessment.


Question 2

A company has enabled Defender for Servers Plan 1 for its Azure VMs. The security team wants to use Defender Vulnerability Management to identify vulnerabilities in installed software.

Which statement is correct?

A. Vulnerability Management requires Plan 2 and cannot be used with Plan 1.

B. Vulnerability Management is available only through Microsoft Sentinel.

C. Plan 1 supports agent-based vulnerability scanning through the Defender for Endpoint integration.

D. Plan 1 provides agentless vulnerability scanning but not agent-based scanning.

Answer: C

Explanation

C is correct. Defender for Servers Plan 1 supports agent-based vulnerability scanning through the Defender for Endpoint integration. Plan 2 expands the available capabilities by adding agentless scanning and premium Defender Vulnerability Management functionality.

A is incorrect because Plan 1 does support vulnerability assessment.

B is incorrect because Defender Vulnerability Management is integrated with Defender for Servers rather than requiring Sentinel.

D is incorrect because agentless scanning is a Plan 2 capability, whereas Plan 1 supports the agent-based approach.


Question 3

A security administrator is reviewing a vulnerability finding for an Azure VM. The finding includes a CVE identifier and a CVSS score.

What is the primary purpose of the CVE identifier?

A. To identify the Azure subscription containing the VM

B. To uniquely identify a publicly known vulnerability

C. To identify the severity category assigned by the organization’s security team

D. To identify the Defender for Servers billing plan

Answer: B

Explanation

B is correct. A Common Vulnerabilities and Exposures (CVE) identifier provides a standardized identifier for a publicly known vulnerability.

A is incorrect because Azure subscription identifiers are unrelated to CVEs.

C is incorrect because CVSS is used to communicate vulnerability severity; the CVE identifies the vulnerability itself.

D is incorrect because CVEs have nothing to do with Defender for Servers licensing.


Question 4

An organization has Defender for Servers Plan 2 enabled. Both agent-based Defender Vulnerability Management scanning and agentless scanning are available for the same VM.

Which result should an administrator generally expect Defender for Cloud to prioritize?

A. Agentless results because they always have higher accuracy

B. Results from whichever scanner has the highest CVSS score

C. Results from the scanner that was enabled most recently

D. Agent-based results because they generally provide better data freshness

Answer: D

Explanation

D is correct. When both agent-based and agentless scanning are available, Defender for Cloud generally uses the agent-based results because they provide better data freshness.

A is incorrect because agentless scanning does not automatically take precedence when both methods are available.

B is incorrect because CVSS does not determine which scanning source is selected.

C is incorrect because scanner selection is not based simply on which method was enabled most recently.


Question 5

A security team wants to evaluate whether Azure VMs conform to defined security configuration baselines. They are not merely interested in identifying known software vulnerabilities.

Which Defender Vulnerability Management capability addresses this requirement?

A. CVSS scoring

B. Security baseline assessment

C. Network vulnerability scanning

D. Microsoft Sentinel workbook analysis

Answer: B

Explanation

B is correct. Security baseline assessment evaluates machine configuration against defined security baseline profiles. It answers a different question from conventional vulnerability assessment. Current Microsoft documentation identifies this capability with Defender for Servers Plan 2.

A is incorrect because CVSS communicates vulnerability severity rather than evaluating configuration baselines.

C is incorrect because Defender Vulnerability Management’s integrated machine scanning is not a general network vulnerability scanner.

D is incorrect because Sentinel is not the service providing this MDVM capability.


Question 6

A security administrator needs to enable vulnerability assessment for machines across an Azure subscription.

Which location should the administrator use in Microsoft Defender for Cloud?

A. Environment settings for the subscription and the Defender for Servers settings

B. Azure Network Watcher

C. Microsoft Sentinel Analytics rules

D. Azure Key Vault access policies

Answer: A

Explanation

A is correct. Vulnerability assessment can be configured through Defender for Cloud → Environment settings → relevant subscription → Defender for Servers settings. Current guidance identifies vulnerability assessment for machines as a configurable Defender for Servers setting.

B is incorrect because Network Watcher handles network monitoring and diagnostics.

C is incorrect because Sentinel analytics rules detect and correlate security events rather than enabling VM vulnerability scanning.

D is incorrect because Key Vault access policies control access to Key Vault resources.


Question 7

An organization already uses a supported third-party vulnerability-management product and wants to integrate its findings into Microsoft Defender for Cloud instead of switching entirely to Microsoft’s integrated scanner.

Which approach should the organization consider?

A. Azure Bastion

B. Microsoft Sentinel data connectors

C. Azure Policy guest configuration

D. A supported Bring Your Own License vulnerability-assessment solution

Answer: D

Explanation

D is correct. Defender for Cloud supports Bring Your Own License (BYOL) vulnerability-assessment solutions, including supported partner solutions such as Qualys and Rapid7.

A is incorrect because Azure Bastion provides secure administrative access to VMs.

B is incorrect because Sentinel connectors are used for security-data ingestion rather than implementing the vulnerability scanner.

C is incorrect because Azure Policy guest configuration addresses configuration compliance rather than serving as the third-party vulnerability scanner.


Question 8

A security team wants to reduce exploitation risk by preventing vulnerable applications from running on protected servers when supported by the Defender Vulnerability Management capability.

Which Defender for Servers plan should they evaluate?

A. Defender for Servers Plan 1

B. Foundational CSPM only

C. Defender for Servers Plan 2

D. Azure Network Watcher

Answer: C

Explanation

C is correct. Vulnerable application blocking is among the premium Defender Vulnerability Management capabilities associated with Defender for Servers Plan 2.

A is incorrect because Plan 1 provides the basic Defender for Servers capabilities and agent-based vulnerability scanning but not the premium MDVM functionality described here.

B is incorrect because Foundational CSPM is focused on security posture management rather than providing the premium server vulnerability-management capability in the scenario.

D is incorrect because Network Watcher is a network diagnostic service.


Question 9

A security analyst has Security Reader permissions and needs to investigate vulnerability findings on Azure VMs. Another administrator will be responsible for deploying or changing the vulnerability scanner configuration.

Which statement best describes the permissions required?

A. Security Reader can view findings, while stronger permissions such as Owner at the required resource-group scope are needed to deploy the scanner.

B. Security Reader must be granted Global Administrator before findings can be viewed.

C. Contributor permissions are always required just to view vulnerability findings.

D. No Azure RBAC permissions are required for vulnerability information.

Answer: A

Explanation

A is correct. Current guidance specifies that Security Reader can view vulnerability findings, while Owner at the resource-group level is required to deploy the scanner.

This is an important least-privilege concept: viewing security information should not automatically require deployment-level permissions.

B is incorrect because Global Administrator is not required for viewing Defender for Cloud vulnerability findings.

C is incorrect because Contributor is not required merely to view the findings.

D is incorrect because Azure RBAC controls access to Defender for Cloud resources and findings.


Question 10

An organization determines that a particular vulnerability cannot currently be remediated because the affected application is business-critical and the organization has implemented compensating controls. The security team wants to manage the finding as an accepted exception using current Defender for Cloud functionality.

Which approach should the team favor?

A. Delete the vulnerability record

B. Use a recommendation exemption

C. Disable Microsoft Defender for Endpoint

D. Turn off Defender for Servers

Answer: B

Explanation

B is correct. Current Microsoft guidance is transitioning away from older disable rules toward recommendation exemptions for managing accepted exceptions.

The important security principle is that an accepted risk should be explicitly documented and governed rather than hiding the vulnerability by disabling the entire security capability.

A is incorrect because administrators should not attempt to delete vulnerability records to manage accepted risk.

C is incorrect because disabling Defender for Endpoint would remove important security capabilities rather than properly documenting the exception.

D is incorrect because disabling Defender for Servers would eliminate the broader server-protection capabilities and would not be an appropriate way to manage an individual accepted vulnerability.


Final Word

A key exam distinction to keep in mind is Plan 1 = agent-based vulnerability scanning; Plan 2 = agent-based + agentless scanning plus premium MDVM capabilities. Also watch for questions that distinguish vulnerability assessment, security-baseline assessment, EDR, and network scanning—they are deliberately different concepts.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply