This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
--> Manage security posture by using Defender for Cloud
--> Configure Microsoft Defender Vulnerability Management settings for Azure VMs
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
Microsoft Defender Vulnerability Management (MDVM) is an important component of the security capabilities provided by Microsoft Defender for Cloud and Microsoft Defender for Servers. It helps security teams discover vulnerabilities in software installed on virtual machines, prioritize those vulnerabilities, and take action to reduce the organization’s exposure to known security risks.
One important current distinction is that Microsoft Defender Vulnerability Management (MDVM) is natively integrated with Defender for Servers, and Azure VM vulnerability scanning can now use both agent-based and agentless approaches depending on the Defender for Servers plan and configuration.
For the SC-500 exam, it is important to understand more than simply what a vulnerability scanner does. You should understand:
- How Defender Vulnerability Management integrates with Defender for Servers
- The difference between agent-based and agentless vulnerability scanning
- The relationship between Defender for Servers Plan 1 (P1) and Plan 2 (P2)
- How vulnerability assessment is enabled at subscription and machine scope
- How to review vulnerability findings
- How CVEs and severity information are used to prioritize remediation
- How vulnerability findings can be managed when an organization has an accepted risk
- The additional MDVM capabilities available with Defender for Servers Plan 2
- How security baseline assessment and vulnerable application blocking fit into the overall solution
The current SC-500 study guide specifically includes configuring Defender for Servers settings such as vulnerability scanning and EDR, as well as implementing agentless VM scanning.
1. What Is Microsoft Defender Vulnerability Management?
Microsoft Defender Vulnerability Management is Microsoft’s vulnerability-management capability for continuously discovering and assessing vulnerabilities and helping organizations prioritize remediation.
Within Defender for Cloud, MDVM is integrated with Microsoft Defender for Endpoint and Defender for Servers.
This integration provides capabilities such as:
- Software inventory
- Vulnerability discovery
- Vulnerability assessment
- CVE identification
- Risk-based prioritization
- Security recommendations
- Vulnerability remediation
- Security baseline assessment
- Premium vulnerability-management capabilities with Defender for Servers Plan 2
For servers protected by Defender for Servers, Defender Vulnerability Management is integrated natively rather than requiring a completely separate Microsoft vulnerability-management product.
Important SC-500 concept
Think of the relationship as:
Defender for Servers → integrates Defender for Endpoint + Defender Vulnerability Management
This allows Defender for Cloud to provide both:
Threat protection
and
Vulnerability management
for supported machines.
2. What Does Defender Vulnerability Management Scan?
Defender Vulnerability Management identifies vulnerabilities associated with software and configurations on machines.
For example, suppose an Azure VM is running:
- Windows Server
- IIS
- .NET
- Java
- A third-party application
A vulnerability-management solution can identify vulnerable versions of installed software and associate them with known vulnerabilities such as Common Vulnerabilities and Exposures (CVEs).
Defender for Cloud then surfaces vulnerability information and recommendations that security teams can investigate and remediate.
A useful way to think about the process is:
Discover → Assess → Prioritize → Remediate → Verify
3. Defender Vulnerability Management and Defender for Servers
Defender Vulnerability Management scanning for Azure VMs is provided through the Defender for Servers plan.
Current Defender for Cloud documentation describes two primary vulnerability-scanning approaches:
| Capability | Defender for Servers Plan 1 | Defender for Servers Plan 2 |
|---|---|---|
| Defender Vulnerability Management integration | Yes | Yes |
| Agent-based vulnerability scanning | Yes | Yes |
| Agentless vulnerability scanning | No | Yes |
| Premium MDVM capabilities | No | Yes |
| Security baseline assessment | No | Yes |
| Vulnerable application blocking | No | Yes |
| Other advanced Defender for Servers capabilities | Limited | Expanded |
Defender for Servers Plan 2 includes the capabilities of Plan 1 plus additional functionality, including agentless scanning and premium Defender Vulnerability Management capabilities.
Exam tip
A common SC-500 question pattern is:
An organization wants vulnerability scanning without depending on an agent installed inside the VM. Which capability should be considered?
The key concept is:
Agentless vulnerability scanning → Defender for Servers Plan 2
4. Agent-Based Vulnerability Scanning
Agent-based scanning uses the Microsoft Defender for Endpoint integration.
The Defender for Endpoint sensor provides information that Defender Vulnerability Management can use to assess the machine.
Agent-based vulnerability scanning is available with:
- Defender for Servers Plan 1
- Defender for Servers Plan 2
The Defender for Endpoint integration is enabled by default when Defender for Servers is enabled, although individual plan settings can be modified.
Advantages
Agent-based scanning can provide:
- Continuous vulnerability information
- Software inventory
- Vulnerability information
- Endpoint security integration
- Additional threat-detection capabilities through Defender for Endpoint
It is particularly useful when the organization already uses the Defender for Endpoint sensor as part of its endpoint-security architecture.
5. Agentless Vulnerability Scanning
Agentless scanning provides vulnerability visibility without requiring the traditional endpoint sensor for the vulnerability assessment itself.
This is particularly valuable when organizations want broader coverage while minimizing the need to install and maintain agents.
According to the current Defender for Cloud documentation, agentless vulnerability scanning is available with Defender for Servers Plan 2. It is also enabled by default when Defender for Servers Plan 2 or the Defender CSPM plan is enabled, subject to applicable requirements.
Why is agentless scanning important?
Consider an organization with hundreds of Azure VMs.
Installing and maintaining agents on every machine may introduce:
- Deployment effort
- Operational overhead
- Additional dependencies
- Potential compatibility concerns
Agentless scanning can provide vulnerability visibility without requiring the same agent-based deployment model.
6. Agent-Based vs. Agentless Scanning
This distinction is especially important for SC-500.
| Characteristic | Agent-Based | Agentless |
|---|---|---|
| Requires Defender for Endpoint sensor | Yes | No |
| Defender for Servers P1 | Supported | Not supported |
| Defender for Servers P2 | Supported | Supported |
| Provides vulnerability assessment | Yes | Yes |
| Software inventory | Yes | Yes |
| Useful when minimizing agents | Less suitable | Highly suitable |
| Included with P2 | Yes | Yes |
The current Defender for Cloud implementation can also use a hybrid approach. If a machine has both agent-based and agentless scanning available, Defender for Cloud can use the agent-based results because they provide greater data freshness.
Exam scenario
If a question says:
A VM has both Defender for Endpoint-based scanning and agentless scanning available. Which results should you generally expect Defender for Cloud to use?
The important concept is:
Agent-based results take precedence because they provide better freshness.
7. Enabling Vulnerability Scanning at Subscription Scope
Vulnerability scanning can be configured for an Azure subscription through Defender for Cloud.
A typical configuration process is:
- Open Microsoft Defender for Cloud.
- Open Environment settings.
- Select the Azure subscription.
- Locate Defender for Servers.
- Open the relevant monitoring/settings configuration.
- Locate Vulnerability assessment for machines.
- Configure the vulnerability-assessment solution.
- Apply and save the configuration.
Current Microsoft documentation indicates that vulnerability scanning is enabled by default when Defender for Servers is enabled, although administrators can manually configure the vulnerability-assessment settings when required.
Important distinction
There are two related concepts:
Enabling Defender for Servers
and
Configuring the vulnerability-assessment behavior
Enabling Defender for Servers provides the overall server-protection framework, while the vulnerability-assessment settings determine how vulnerability scanning is configured.
8. Configuring Vulnerability Scanning for an Individual VM
Although configuring protection at subscription scope is generally preferable for consistent security management, Defender for Cloud also supports resource-level configuration.
This can be useful when:
- Different VMs require different protection levels
- An organization is gradually onboarding machines
- Certain workloads require exceptions
- Different server populations use different Defender for Servers plans
If a VM does not have an appropriate vulnerability assessment solution, Defender for Cloud can generate the recommendation:
Machines should have a vulnerability assessment solution
Administrators can use the recommendation to identify affected machines and configure a vulnerability solution.
9. Required Permissions
Permissions matter when configuring vulnerability scanning.
Current Microsoft guidance identifies:
- Owner permissions at the resource-group level are required to deploy the scanner.
- Security Reader permissions are sufficient to view vulnerability findings.
This illustrates an important security principle:
The person who needs to view vulnerability information does not necessarily need the permissions required to deploy or change vulnerability scanning.
This follows the principle of least privilege.
10. Reviewing Vulnerability Findings
Once vulnerability scanning is active, security teams need to interpret and prioritize the findings.
Defender for Cloud surfaces vulnerability information that can include:
- Vulnerable machines
- Affected software
- CVEs
- Severity
- Remediation recommendations
- Related security information
The Defender Vulnerability Management experience also provides broader vulnerability-management capabilities through the Microsoft Defender portal and Exposure Management.
11. Understanding CVEs
A Common Vulnerabilities and Exposures (CVE) identifier provides a standardized identifier for a publicly known vulnerability.
For example:
CVE-YYYY-NNNNN
can identify a specific vulnerability affecting a particular product or component.
When reviewing a vulnerability finding, security professionals should not simply look at the number of vulnerabilities.
Instead, they should consider:
- Vulnerability severity
- Affected asset
- Business importance of the asset
- Exploitability
- Exposure
- Attack-path information
- Available remediation
- Whether the vulnerability is actively being exploited
This helps organizations prioritize the vulnerabilities that present the greatest practical risk.
12. CVSS Scores
Vulnerability findings can also contain Common Vulnerability Scoring System (CVSS) information.
CVSS provides a standardized way to communicate the severity of a vulnerability.
For example:
| CVSS | General interpretation |
|---|---|
| Low | Lower severity |
| Medium | Moderate severity |
| High | Significant severity |
| Critical | Extremely serious vulnerability |
However, organizations should avoid treating CVSS as the only factor in remediation decisions.
A medium-severity vulnerability on an internet-facing production server could be more important to an organization than a critical vulnerability on an isolated development VM.
Modern Defender Vulnerability Management therefore emphasizes risk-based prioritization rather than simply sorting vulnerabilities by CVSS score.
13. Vulnerability Findings as Defender for Cloud Recommendations
Defender for Cloud presents vulnerability findings as recommendations.
For example:
Machines should have vulnerability findings resolved
can identify machines with vulnerabilities requiring attention.
The recommendation experience can provide:
- Affected resources
- Vulnerability information
- CVEs
- Severity
- Remediation guidance
Administrators can investigate individual resources or examine findings across the environment.
14. Managing Accepted Risk
Not every vulnerability can immediately be remediated.
For example, an organization might determine that:
- A vulnerable application cannot yet be upgraded.
- The vulnerability affects a legacy application.
- The vulnerability is not exploitable in the organization’s environment.
- Compensating controls reduce the risk.
- The vulnerability is below an organization’s defined risk threshold.
In these situations, organizations need a controlled way to manage exceptions.
Historically, Defender for Cloud provided disable rules for suppressing selected vulnerability findings.
However, current Microsoft guidance states that disable rules are being deprecated as part of the transition from grouped recommendations to individual recommendations, with recommendation exemptions becoming the preferred approach for managing exceptions.
Exam consideration
If a question is based on current functionality and asks how an organization should manage an accepted recommendation exception, understand the transition toward:
Recommendation exemptions
rather than assuming older disable-rule terminology is always the current answer.
15. Defender for Servers Plan 2 Premium Vulnerability Management
One of the most important reasons an organization might select Defender for Servers Plan 2 is access to additional vulnerability-management capabilities.
Current Defender documentation identifies premium capabilities associated with Plan 2, including:
- Security baseline assessment
- Vulnerable application blocking
- Additional inventory and assessment capabilities
- Additional remediation and mitigation functionality
These capabilities go beyond simply identifying CVEs.
16. Security Baseline Assessment
Security baseline assessment evaluates machines against defined security configuration profiles.
The goal is to determine whether a machine is configured according to an organization’s desired security posture.
For example, an organization might establish a baseline requiring:
- Specific security settings
- Appropriate authentication configuration
- Required system protections
- Secure operating-system configuration
Current Microsoft documentation identifies Defender Vulnerability Management security baseline assessment as a Plan 2 capability and notes that this assessment capability is currently in public preview.
Important distinction
Vulnerability assessment asks:
“Is the software or system vulnerable?”
Security baseline assessment asks:
“Is the system configured according to the desired security baseline?”
These are related but different security questions.
17. Vulnerable Application Blocking
Defender Vulnerability Management premium capabilities can also provide mechanisms for dealing with vulnerable applications.
Vulnerable application blocking is designed to reduce exploitation risk by preventing vulnerable applications from running under supported scenarios.
This is different from simply generating a vulnerability report.
The progression is approximately:
Discover vulnerability → Assess risk → Recommend remediation → Mitigate exploitation
Vulnerable application blocking therefore represents a more proactive mitigation capability.
It is associated with the premium Defender Vulnerability Management capabilities available through Defender for Servers Plan 2.
18. Defender for Servers Plan 1 vs. Plan 2
For the SC-500 exam, memorize the conceptual differences rather than attempting to memorize every individual feature.
| Capability | Plan 1 | Plan 2 |
|---|---|---|
| Defender for Endpoint integration | Yes | Yes |
| Agent-based vulnerability assessment | Yes | Yes |
| Agentless machine scanning | No | Yes |
| Premium MDVM capabilities | No | Yes |
| Security baseline assessment | No | Yes |
| Vulnerable application blocking | No | Yes |
| Advanced server protection | More limited | More comprehensive |
Exam shortcut
When the question emphasizes:
“agentless vulnerability scanning”
think:
Plan 2
When it emphasizes:
“premium Defender Vulnerability Management capabilities”
think:
Plan 2
When it simply asks whether Defender Vulnerability Management-based vulnerability scanning is available with Defender for Servers:
Plan 1 and Plan 2
19. What Happens When Agent-Based and Agentless Scanning Overlap?
This is an excellent potential exam scenario.
Suppose:
- Defender for Servers Plan 2 is enabled.
- Agentless scanning is enabled.
- Defender for Endpoint is also installed and reporting vulnerability information.
Both methods may be available.
Defender for Cloud uses a hybrid behavior.
If both scanning methods provide results, agent-based results are preferred because they provide better data freshness.
This does not mean agentless scanning is unnecessary. It can extend coverage to machines that do not have an agent-based vulnerability-scanning solution.
20. Bring Your Own License Vulnerability Scanners
Organizations that already use another vulnerability-management product can use a supported Bring Your Own License (BYOL) vulnerability scanner.
Current Defender for Cloud documentation identifies supported partner solutions such as:
- Qualys
- Rapid7
The partner solution reports vulnerability data to its management platform, and vulnerability information can be surfaced through Defender for Cloud.
Important exam distinction
The integrated Microsoft solution is:
Microsoft Defender Vulnerability Management
A BYOL deployment is:
A supported third-party vulnerability assessment solution
These are alternative vulnerability-assessment approaches rather than two scanners that an organization necessarily needs to run simultaneously.
Only one BYOL scanner is supported for a machine.
21. Hybrid Behavior with BYOL Scanners
Defender for Cloud can combine different vulnerability-scanning capabilities depending on the machine’s configuration.
Current behavior includes:
- If there is no agent-based scanner, agentless scanning can provide results where supported.
- If Defender Vulnerability Management is integrated through Defender for Endpoint, Defender for Cloud can use the agent-based results.
- If a supported BYOL scanner is installed, partner results generally take precedence.
- Agentless results can be used for machines that do not have the partner scanner or are not reporting findings correctly.
- Organizations can configure vulnerability-scanning behavior to use Defender Vulnerability Management results where appropriate.
This is an area where exam questions may test your understanding of which scanning method takes precedence rather than simply asking what each scanner does.
22. Vulnerability Scanning Is Not the Same as Network Vulnerability Scanning
Another important distinction:
The integrated Defender Vulnerability Management scanner focuses on vulnerabilities on the machine itself.
It does not function as a general network-vulnerability scanner that scans the entire network for network-device vulnerabilities.
Therefore:
“Find vulnerable software installed on this VM”
is a Defender Vulnerability Management use case.
Whereas:
“Scan the entire network for vulnerable network devices”
is a different security requirement.
23. Relationship Between Vulnerability Management and EDR
Endpoint Detection and Response (EDR) and vulnerability management address different security problems.
Defender for Endpoint / EDR
Focuses on detecting and responding to threats.
Examples include:
- Suspicious behavior
- Malware
- Attacks
- Endpoint incidents
- Security alerts
Defender Vulnerability Management
Focuses on exposure and weaknesses.
Examples include:
- Vulnerable software
- Missing security updates
- Vulnerable applications
- Security recommendations
- Risk prioritization
Defender for Servers integrates these capabilities to provide a more comprehensive security solution for protected machines.
24. A Practical Configuration Strategy
A good implementation strategy can be summarized as follows.
Step 1 — Enable Defender for Cloud
Ensure the Azure subscription is onboarded to Defender for Cloud.
Step 2 — Select Defender for Servers
Determine whether the organization needs:
- Plan 1
- Plan 2
Step 3 — Determine the scanning approach
Decide whether vulnerability assessment should use:
- Agent-based scanning
- Agentless scanning
- A supported BYOL solution
Step 4 — Configure vulnerability assessment
Use Defender for Cloud Environment settings to configure vulnerability assessment for the appropriate subscription.
Step 5 — Validate machine coverage
Review the affected VMs and ensure vulnerability scanning is active.
Step 6 — Review findings
Analyze:
- CVEs
- Severity
- Affected software
- Affected machines
- Remediation guidance
Step 7 — Prioritize
Prioritize vulnerabilities based on actual organizational risk, not simply CVSS score.
Step 8 — Remediate
Apply patches, update applications, modify configurations, or apply other compensating controls.
Step 9 — Handle accepted risks
Where remediation is not currently possible, use the appropriate recommendation-exemption mechanism according to current Defender for Cloud functionality.
Step 10 — Consider Plan 2 capabilities
For higher-security environments, evaluate:
- Agentless scanning
- Security baseline assessment
- Vulnerable application blocking
- Other premium Defender Vulnerability Management capabilities
25. Common Mistakes to Avoid
Mistake 1: Assuming Plan 1 provides agentless vulnerability scanning
It does not.
Agentless vulnerability scanning is associated with Plan 2.
Mistake 2: Assuming Plan 2 eliminates agent-based scanning
It does not.
Plan 2 supports both agent-based and agentless approaches.
Mistake 3: Confusing vulnerability management with EDR
Vulnerability management identifies weaknesses.
EDR detects and responds to active threats.
Mistake 4: Treating CVSS as the only prioritization factor
CVSS is important, but modern vulnerability management also considers contextual risk.
Mistake 5: Assuming every vulnerability should immediately be remediated
Some vulnerabilities may require documented risk acceptance or compensating controls.
Mistake 6: Confusing vulnerability assessment with network scanning
Defender Vulnerability Management focuses on vulnerabilities associated with the machine and its software.
Mistake 7: Forgetting resource scope
Defender for Servers and vulnerability assessment can be configured at subscription level, while resource-level configurations can be used for specific scenarios.
Mistake 8: Using outdated disable-rule assumptions
Microsoft is transitioning away from disable rules toward recommendation exemptions for managing exceptions.
26. SC-500 Exam-Focused Comparison
| Requirement in the scenario | Most relevant concept |
|---|---|
| Scan VM vulnerabilities using Defender for Endpoint | Agent-based MDVM |
| Scan VMs without relying on an endpoint agent | Agentless scanning |
| Enable agentless vulnerability scanning | Defender for Servers Plan 2 |
| Obtain premium MDVM capabilities | Defender for Servers Plan 2 |
| Assess security configuration against baselines | Security baseline assessment |
| Prevent vulnerable applications from running | Vulnerable application blocking |
| View vulnerability information | Security Reader can view findings |
| Deploy scanner/configuration | Appropriate administrative permissions, including Owner at required scope |
| Identify known software vulnerabilities | MDVM |
| Detect active endpoint threats | Defender for Endpoint/EDR |
| Use an existing Qualys or Rapid7 solution | BYOL vulnerability assessment |
| Identify a known vulnerability | CVE |
| Assess vulnerability severity | CVSS and contextual risk |
| Manage accepted exceptions | Recommendation exemptions |
27. Key Takeaways
For the SC-500 exam, remember these core concepts:
- Microsoft Defender Vulnerability Management is integrated with Defender for Servers.
- Defender for Servers Plan 1 supports agent-based vulnerability scanning.
- Defender for Servers Plan 2 supports both agent-based and agentless vulnerability scanning.
- Agentless vulnerability scanning is a major Plan 2 capability.
- If both agent-based and agentless results are available, agent-based results are generally preferred because of their freshness.
- Defender Vulnerability Management identifies software vulnerabilities and provides remediation information.
- CVEs identify known vulnerabilities; CVSS helps communicate severity.
- Risk prioritization should consider organizational context rather than relying exclusively on CVSS.
- Security baseline assessment is different from vulnerability assessment.
- Premium Defender Vulnerability Management capabilities, including security baseline assessment and vulnerable application blocking, are associated with Defender for Servers Plan 2.
- Qualys and Rapid7 are examples of supported BYOL vulnerability-assessment solutions.
- Vulnerability assessment is not the same thing as network vulnerability scanning.
- Defender Vulnerability Management complements Defender for Endpoint/EDR rather than replacing it.
- Current Defender for Cloud functionality is moving toward recommendation exemptions rather than older disable-rule mechanisms.
The most important mental model is:
Defender for Servers provides the server-protection framework; Defender Vulnerability Management identifies and prioritizes vulnerabilities; Defender for Endpoint provides endpoint protection and threat detection; Plan 2 adds agentless scanning and premium vulnerability-management capabilities.
Practice Exam Questions
Question 1
An organization has 500 Azure virtual machines protected by Microsoft Defender for Servers. The security team wants to identify software vulnerabilities but does not want the vulnerability assessment process to depend on installing an agent on every VM.
Which capability should the organization use?
A. Agentless vulnerability scanning with Defender for Servers Plan 2
B. Defender for Endpoint Plan 1 only
C. Microsoft Sentinel analytics rules
D. Azure Network Watcher
Answer: A
Explanation
A is correct. Defender for Servers Plan 2 supports agentless vulnerability scanning, which allows Defender Vulnerability Management to assess supported machines without relying on the traditional agent-based vulnerability-scanning approach. Agentless scanning is a key distinction between Plan 1 and Plan 2.
B is incorrect because Defender for Endpoint is associated with the agent-based approach and does not provide the requested agentless architecture.
C is incorrect because Microsoft Sentinel is primarily a SIEM/security analytics platform rather than a VM vulnerability scanner.
D is incorrect because Network Watcher provides network monitoring and diagnostics, not software vulnerability assessment.
Question 2
A company has enabled Defender for Servers Plan 1 for its Azure VMs. The security team wants to use Defender Vulnerability Management to identify vulnerabilities in installed software.
Which statement is correct?
A. Vulnerability Management requires Plan 2 and cannot be used with Plan 1.
B. Vulnerability Management is available only through Microsoft Sentinel.
C. Plan 1 supports agent-based vulnerability scanning through the Defender for Endpoint integration.
D. Plan 1 provides agentless vulnerability scanning but not agent-based scanning.
Answer: C
Explanation
C is correct. Defender for Servers Plan 1 supports agent-based vulnerability scanning through the Defender for Endpoint integration. Plan 2 expands the available capabilities by adding agentless scanning and premium Defender Vulnerability Management functionality.
A is incorrect because Plan 1 does support vulnerability assessment.
B is incorrect because Defender Vulnerability Management is integrated with Defender for Servers rather than requiring Sentinel.
D is incorrect because agentless scanning is a Plan 2 capability, whereas Plan 1 supports the agent-based approach.
Question 3
A security administrator is reviewing a vulnerability finding for an Azure VM. The finding includes a CVE identifier and a CVSS score.
What is the primary purpose of the CVE identifier?
A. To identify the Azure subscription containing the VM
B. To uniquely identify a publicly known vulnerability
C. To identify the severity category assigned by the organization’s security team
D. To identify the Defender for Servers billing plan
Answer: B
Explanation
B is correct. A Common Vulnerabilities and Exposures (CVE) identifier provides a standardized identifier for a publicly known vulnerability.
A is incorrect because Azure subscription identifiers are unrelated to CVEs.
C is incorrect because CVSS is used to communicate vulnerability severity; the CVE identifies the vulnerability itself.
D is incorrect because CVEs have nothing to do with Defender for Servers licensing.
Question 4
An organization has Defender for Servers Plan 2 enabled. Both agent-based Defender Vulnerability Management scanning and agentless scanning are available for the same VM.
Which result should an administrator generally expect Defender for Cloud to prioritize?
A. Agentless results because they always have higher accuracy
B. Results from whichever scanner has the highest CVSS score
C. Results from the scanner that was enabled most recently
D. Agent-based results because they generally provide better data freshness
Answer: D
Explanation
D is correct. When both agent-based and agentless scanning are available, Defender for Cloud generally uses the agent-based results because they provide better data freshness.
A is incorrect because agentless scanning does not automatically take precedence when both methods are available.
B is incorrect because CVSS does not determine which scanning source is selected.
C is incorrect because scanner selection is not based simply on which method was enabled most recently.
Question 5
A security team wants to evaluate whether Azure VMs conform to defined security configuration baselines. They are not merely interested in identifying known software vulnerabilities.
Which Defender Vulnerability Management capability addresses this requirement?
A. CVSS scoring
B. Security baseline assessment
C. Network vulnerability scanning
D. Microsoft Sentinel workbook analysis
Answer: B
Explanation
B is correct. Security baseline assessment evaluates machine configuration against defined security baseline profiles. It answers a different question from conventional vulnerability assessment. Current Microsoft documentation identifies this capability with Defender for Servers Plan 2.
A is incorrect because CVSS communicates vulnerability severity rather than evaluating configuration baselines.
C is incorrect because Defender Vulnerability Management’s integrated machine scanning is not a general network vulnerability scanner.
D is incorrect because Sentinel is not the service providing this MDVM capability.
Question 6
A security administrator needs to enable vulnerability assessment for machines across an Azure subscription.
Which location should the administrator use in Microsoft Defender for Cloud?
A. Environment settings for the subscription and the Defender for Servers settings
B. Azure Network Watcher
C. Microsoft Sentinel Analytics rules
D. Azure Key Vault access policies
Answer: A
Explanation
A is correct. Vulnerability assessment can be configured through Defender for Cloud → Environment settings → relevant subscription → Defender for Servers settings. Current guidance identifies vulnerability assessment for machines as a configurable Defender for Servers setting.
B is incorrect because Network Watcher handles network monitoring and diagnostics.
C is incorrect because Sentinel analytics rules detect and correlate security events rather than enabling VM vulnerability scanning.
D is incorrect because Key Vault access policies control access to Key Vault resources.
Question 7
An organization already uses a supported third-party vulnerability-management product and wants to integrate its findings into Microsoft Defender for Cloud instead of switching entirely to Microsoft’s integrated scanner.
Which approach should the organization consider?
A. Azure Bastion
B. Microsoft Sentinel data connectors
C. Azure Policy guest configuration
D. A supported Bring Your Own License vulnerability-assessment solution
Answer: D
Explanation
D is correct. Defender for Cloud supports Bring Your Own License (BYOL) vulnerability-assessment solutions, including supported partner solutions such as Qualys and Rapid7.
A is incorrect because Azure Bastion provides secure administrative access to VMs.
B is incorrect because Sentinel connectors are used for security-data ingestion rather than implementing the vulnerability scanner.
C is incorrect because Azure Policy guest configuration addresses configuration compliance rather than serving as the third-party vulnerability scanner.
Question 8
A security team wants to reduce exploitation risk by preventing vulnerable applications from running on protected servers when supported by the Defender Vulnerability Management capability.
Which Defender for Servers plan should they evaluate?
A. Defender for Servers Plan 1
B. Foundational CSPM only
C. Defender for Servers Plan 2
D. Azure Network Watcher
Answer: C
Explanation
C is correct. Vulnerable application blocking is among the premium Defender Vulnerability Management capabilities associated with Defender for Servers Plan 2.
A is incorrect because Plan 1 provides the basic Defender for Servers capabilities and agent-based vulnerability scanning but not the premium MDVM functionality described here.
B is incorrect because Foundational CSPM is focused on security posture management rather than providing the premium server vulnerability-management capability in the scenario.
D is incorrect because Network Watcher is a network diagnostic service.
Question 9
A security analyst has Security Reader permissions and needs to investigate vulnerability findings on Azure VMs. Another administrator will be responsible for deploying or changing the vulnerability scanner configuration.
Which statement best describes the permissions required?
A. Security Reader can view findings, while stronger permissions such as Owner at the required resource-group scope are needed to deploy the scanner.
B. Security Reader must be granted Global Administrator before findings can be viewed.
C. Contributor permissions are always required just to view vulnerability findings.
D. No Azure RBAC permissions are required for vulnerability information.
Answer: A
Explanation
A is correct. Current guidance specifies that Security Reader can view vulnerability findings, while Owner at the resource-group level is required to deploy the scanner.
This is an important least-privilege concept: viewing security information should not automatically require deployment-level permissions.
B is incorrect because Global Administrator is not required for viewing Defender for Cloud vulnerability findings.
C is incorrect because Contributor is not required merely to view the findings.
D is incorrect because Azure RBAC controls access to Defender for Cloud resources and findings.
Question 10
An organization determines that a particular vulnerability cannot currently be remediated because the affected application is business-critical and the organization has implemented compensating controls. The security team wants to manage the finding as an accepted exception using current Defender for Cloud functionality.
Which approach should the team favor?
A. Delete the vulnerability record
B. Use a recommendation exemption
C. Disable Microsoft Defender for Endpoint
D. Turn off Defender for Servers
Answer: B
Explanation
B is correct. Current Microsoft guidance is transitioning away from older disable rules toward recommendation exemptions for managing accepted exceptions.
The important security principle is that an accepted risk should be explicitly documented and governed rather than hiding the vulnerability by disabling the entire security capability.
A is incorrect because administrators should not attempt to delete vulnerability records to manage accepted risk.
C is incorrect because disabling Defender for Endpoint would remove important security capabilities rather than properly documenting the exception.
D is incorrect because disabling Defender for Servers would eliminate the broader server-protection capabilities and would not be an appropriate way to manage an individual accepted vulnerability.
Final Word
A key exam distinction to keep in mind is Plan 1 = agent-based vulnerability scanning; Plan 2 = agent-based + agentless scanning plus premium MDVM capabilities. Also watch for questions that distinguish vulnerability assessment, security-baseline assessment, EDR, and network scanning—they are deliberately different concepts.
Go to the SC-500 Exam Prep Hub main page
