This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
--> Manage security posture by using Defender for Cloud
--> Enable and configure Defender for Cloud workload protection plans
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
Microsoft Defender for Cloud provides security capabilities for cloud environments from security posture management through active workload protection.
For the SC-500 exam, an important distinction is between:
- Cloud Security Posture Management (CSPM) — identifies security weaknesses, misconfigurations, exposure, and compliance gaps.
- Cloud Workload Protection Platform (CWPP) — provides workload-specific threat protection and security capabilities for resources such as servers, containers, databases, storage, applications, APIs, and AI services.
Defender for Cloud’s workload protection plans are enabled according to the types of workloads an organization needs to protect. These plans provide capabilities such as threat detection, vulnerability assessment, runtime protection, malware scanning, and other workload-specific security controls.
For the SC-500 exam, you should understand which Defender plan protects which workload, how to enable the plan, how to configure important plan-specific settings, how to deploy plans at scale, and how to verify coverage.
1. What Is Cloud Workload Protection?
Cloud workload protection focuses on protecting workloads while they are running, rather than simply identifying whether their configuration is secure.
For example:
| Workload | Potential Security Concern | Relevant Defender Capability |
|---|---|---|
| Virtual machines | Malware, vulnerabilities, suspicious activity | Defender for Servers |
| Kubernetes | Vulnerable containers, runtime attacks | Defender for Containers |
| Azure Storage | Malicious uploads, data threats | Defender for Storage |
| Azure SQL | Database attacks and vulnerabilities | Defender for Databases |
| App Service | Attacks against web applications | Defender for App Service |
| APIs | API vulnerabilities and attacks | Defender for APIs |
| Key Vault | Suspicious access to secrets and keys | Defender for Key Vault |
| AI services | Threats against generative AI applications | Defender for AI Services |
| Azure resource management | Suspicious resource-management operations | Defender for Resource Manager |
| DNS | DNS-layer threats | Defender for DNS |
The important SC-500 concept is that you select protection plans based on the workloads that exist in your environment.
Defender for Cloud currently provides a broad catalog of workload-specific protection plans, including servers, containers, storage, databases, Key Vault, App Service, APIs, AI Services, DNS, and Resource Manager.
2. CSPM vs. CWPP
One of the most important distinctions for the exam is the difference between CSPM and workload protection.
Cloud Security Posture Management
CSPM answers questions such as:
“Is this environment configured securely?”
Examples include:
- Is a storage account publicly accessible?
- Is encryption configured?
- Is a network security control missing?
- Does a resource violate a security policy?
- Does the environment have excessive risk?
Defender for Cloud’s foundational CSPM capabilities include recommendations, asset inventory, workbooks, Secure Score, and Microsoft cloud security benchmark capabilities.
Cloud Workload Protection
CWPP answers questions such as:
“Is this workload currently protected against threats?”
Examples include:
- Is a VM protected against malware and endpoint threats?
- Is a Kubernetes cluster receiving runtime threat detection?
- Is malicious content being detected when uploaded to storage?
- Are suspicious database activities being detected?
- Are API attacks being detected?
- Are AI workloads receiving threat protection?
Exam tip:
CSPM focuses primarily on improving security posture.
CWPP focuses primarily on protecting workloads from active threats.
In real environments, the two capabilities complement each other rather than replacing one another.
3. Defender for Cloud Workload Protection Plans
Defender for Cloud contains multiple workload-specific plans.
Some of the important plans for SC-500 include:
Defender for Servers
Protects physical and virtual machines across Azure and supported multicloud environments.
Defender for Servers provides capabilities such as:
- Threat detection
- Endpoint protection integration
- Vulnerability assessment
- Security recommendations
- Agentless scanning
- Additional Plan 2 capabilities
Defender for Servers is available as Plan 1 (P1) and Plan 2 (P2).
Defender for Containers
Protects Kubernetes environments, including supported Azure Kubernetes Service, Amazon EKS, Google GKE, and Azure Arc-enabled Kubernetes environments.
Depending on the environment and configuration, capabilities can include:
- Vulnerability scanning
- Runtime threat protection
- Security posture assessments
- Agentless scanning
- Defender sensor
- Kubernetes API access
- Registry access
The exact components available depend on the Kubernetes environment and configuration.
Defender for Storage
Defender for Storage provides security monitoring and threat detection for Azure Storage.
The current plan includes capabilities such as:
- Activity monitoring
- On-upload malware scanning
- Sensitive-data threat detection
Malware scanning can also be configured with options such as scanning limits, filtering, scan-result storage, and automated integration through Event Grid or Log Analytics.
Defender for Databases
Defender for Databases protects supported database workloads.
For example, Defender for Azure SQL Databases provides attack detection and threat-response capabilities for Azure SQL databases.
The broader database protection capabilities also include support for other database workloads, depending on the specific Defender plan and supported environment.
For SQL Server running on machines, the SQL Servers on Machines protection is selected within the Defender for Databases plan.
Defender for App Service
Defender for App Service provides protection for applications running on Azure App Service.
It is designed to identify attacks targeting App Service web applications and APIs.
Defender for APIs
Defender for APIs provides security visibility and protection for APIs managed through Azure API Management.
Capabilities include:
- API discovery
- Security posture assessment
- Vulnerability prioritization
- Threat detection
- Runtime protection
Defender for APIs is enabled at the subscription level, and the appropriate plan should be selected based on API traffic requirements.
Important exam consideration: enabling Defender for APIs does not automatically mean that every API in existence is protected. The APIs must be onboarded appropriately, and the APIs you want to protect must be published through Azure API Management.
Defender for Key Vault
Defender for Key Vault detects unusual and potentially harmful attempts to access or exploit Key Vault accounts.
This is particularly important because Key Vault can contain highly sensitive:
- Secrets
- Encryption keys
- Certificates
The purpose is not simply to encrypt the vault. Defender for Key Vault adds threat-detection capabilities around access and usage.
Defender for AI Services
AI workloads introduce threats that traditional infrastructure security controls may not completely address.
Defender for AI Services provides threat protection for generative AI applications and can detect suspicious activity involving supported AI services.
For SC-500, remember:
AI workloads are now explicitly part of the Defender for Cloud workload-protection model.
This is especially relevant because the SC-500 certification focuses on cloud and AI workloads, rather than traditional cloud infrastructure alone.
Defender for Resource Manager
Defender for Resource Manager monitors Azure resource-management operations and can detect suspicious activity involving management operations.
This protects an important control plane:
The Azure Resource Manager layer through which resources are created, modified, and managed.
It is different from protecting a VM’s operating system or a storage account’s data plane.
Defender for DNS
Defender for DNS provides DNS-layer threat detection for Azure resources.
This illustrates another important Defender for Cloud concept:
Defender plans are specialized according to the attack surface being protected.
4. Choosing the Appropriate Defender Plan
A common SC-500 scenario is:
“An organization has identified a particular workload and wants to enable the appropriate Defender protection.”
The first step is to identify the workload.
For example:
| Requirement | Appropriate plan |
|---|---|
| Protect Azure VMs | Defender for Servers |
| Protect AKS/Kubernetes | Defender for Containers |
| Detect malicious files uploaded to Storage | Defender for Storage |
| Protect Azure SQL databases | Defender for Databases |
| Protect App Service applications | Defender for App Service |
| Protect APIs managed through API Management | Defender for APIs |
| Detect suspicious Key Vault access | Defender for Key Vault |
| Protect generative AI services | Defender for AI Services |
| Detect suspicious Azure resource-management operations | Defender for Resource Manager |
| Detect DNS-based threats | Defender for DNS |
The exam may deliberately include several plausible answers.
The key is to identify the workload, not simply the type of security problem.
5. Enabling Defender for Cloud
Before configuring individual workload protection plans, Defender for Cloud must be enabled for the relevant environment.
For Azure, Defender for Cloud can be accessed through the Azure portal.
Once the environment is available, the administrator can use:
Microsoft Defender for Cloud → Environment settings
From there, the administrator selects the relevant:
- Azure subscription
- AWS account
- GCP project
- Other supported environment/connector
The available Defender plans can then be configured for that environment.
6. Environment Settings
The Environment settings area is particularly important for SC-500.
It provides a centralized location for configuring Defender plans for the selected environment.
A typical workflow is:
- Open Microsoft Defender for Cloud.
- Select Environment settings.
- Select the target environment.
- Locate the desired Defender plan.
- Turn the plan On.
- Configure plan-specific settings.
- Save the configuration.
- Verify coverage.
For example, to enable Defender for Servers, you select the appropriate environment, turn on the Servers plan, choose the appropriate plan tier, and save the configuration.
7. Defender for Servers Plan 1 vs. Plan 2
Defender for Servers is especially important for the SC-500 exam because it contains two plan levels:
- Plan 1
- Plan 2
When enabling Defender for Servers, Plan 2 is selected by default in the current Azure portal workflow, but the administrator can change the selection to Plan 1.
The plans provide different levels of capability.
For example:
| Capability | Plan 1 | Plan 2 |
|---|---|---|
| Defender for Endpoint integration | Yes | Yes |
| Vulnerability assessment | Yes | Yes |
| Agentless scanning | — | Yes |
| File integrity monitoring | — | Available |
| Additional advanced capabilities | Limited | More extensive |
Current configuration guidance indicates that vulnerability assessment is enabled by default when either P1 or P2 is enabled, Defender for Endpoint integration is available with both, and agentless scanning is associated with Plan 2. File integrity monitoring is a Plan 2 capability that is not enabled by default.
Exam strategy
If a question specifically requires a Plan 2-only capability, Plan 1 is not sufficient.
Do not assume:
“Servers enabled = every Defender for Servers capability is enabled.”
Instead, identify the required capability and determine which plan provides it.
8. Configuring Defender for Servers
After enabling Defender for Servers, plan-specific settings can be configured.
Examples include:
Vulnerability assessment
Helps identify vulnerable software and applications on protected machines.
Endpoint protection
Defender for Endpoint integration provides endpoint detection and response capabilities.
Agentless scanning
Agentless scanning can provide additional visibility without requiring a traditional security agent for certain scanning scenarios.
File integrity monitoring
File integrity monitoring can identify changes to important files and registries.
The availability and default state of these capabilities depend on the selected plan.
9. Defender for Storage Configuration
Defender for Storage provides several important configurable capabilities.
The current Defender for Storage plan includes:
- Activity monitoring
- Malware scanning
- Sensitive-data threat detection
Malware scanning can be configured with options such as:
- Monthly scanning caps
- Scan filtering
- Blob index tags for scan results
- Soft deletion of malicious blobs
- Event Grid integration
- Log Analytics integration
Example
Suppose an organization uploads customer documents to Azure Blob Storage.
The security team wants to:
- Detect malicious files immediately after upload.
- Record scan results.
- Automatically initiate downstream processing when malware is discovered.
Defender for Storage can provide the malware scanning capability, while Event Grid can be used to integrate scan results into automated response workflows.
10. Defender for Storage: Important Exam Distinction
Do not confuse:
Activity monitoring
with:
Malware scanning
Activity monitoring provides security analysis of activity involving storage.
Malware scanning specifically detects malicious files, including files uploaded to storage.
Similarly, sensitive-data threat detection addresses suspicious activity involving resources containing sensitive data.
Therefore, if an exam question says:
“Detect malicious files as they are uploaded to Blob Storage.”
The relevant capability is:
Defender for Storage with on-upload malware scanning.
11. Defender for Databases
Defender for Databases protects database workloads against threats and vulnerabilities.
For Azure SQL databases, Defender for Azure SQL Databases can be enabled through the Databases plan.
The administrator:
- Opens Defender for Cloud.
- Selects Environment settings.
- Selects the relevant environment.
- Locates Databases.
- Selects Select types.
- Enables Azure SQL Databases.
- Selects Continue.
- Saves the configuration.
This illustrates an important Defender for Cloud design:
A single high-level plan may contain multiple workload-specific resource types.
For example, Defender for Databases contains multiple database protection capabilities rather than representing only one specific database engine.
12. SQL Servers on Machines
SQL Server workloads may run on:
- Azure virtual machines
- Azure Arc-enabled servers
For SQL Servers on Machines, the protection is configured under the Defender for Databases plan.
The administrator can select the SQL Servers on Machines resource type within the Databases plan.
This is a useful exam distinction.
If a question describes:
“SQL Server installed on an Azure VM”
do not automatically treat it as the same configuration scenario as an Azure SQL Database.
The underlying workload type matters.
13. Defender for Containers
Defender for Containers protects Kubernetes environments.
Depending on the environment, administrators can configure components such as:
- Agentless scanning
- Defender sensor
- Azure Policy
- Kubernetes API access
- Registry access
These capabilities support different aspects of container security.
For example:
Defender sensor
is associated with collecting runtime security telemetry used for threat detection.
Registry access
supports vulnerability assessment for container images in connected registries.
Azure Policy
supports Kubernetes security posture assessment and related recommendations.
Kubernetes API access
allows Defender for Cloud to obtain Kubernetes metadata required for inventory, configuration analysis, and related capabilities.
14. Defender for APIs
Defender for APIs provides protection for APIs managed through Azure API Management.
Its capabilities include:
- Discovery
- Security posture visibility
- Vulnerability prioritization
- Runtime threat detection
- Response capabilities
One important configuration consideration is selecting the appropriate plan based on API traffic.
The current deployment guidance indicates that subscriptions are opted into Plan 1 by default and that organizations should select a plan appropriate for their API traffic volume to avoid unexpected overages.
Exam scenario
A company has a high-volume API platform.
The question asks what should be considered before selecting the Defender for APIs plan.
The best answer is likely to focus on:
API traffic volume and the plan entitlement associated with that traffic.
15. Defender for AI Services
AI workloads require specialized protection because they introduce risks beyond conventional infrastructure.
Defender for Cloud’s AI threat protection can provide:
- AI workload discovery
- Security posture capabilities
- Runtime threat detection
- Security alerts
- Investigation capabilities
Microsoft’s current Defender for Cloud training specifically includes enabling and configuring the AI workloads plan and reviewing AI resource insights, posture, and runtime threats.
This is particularly important for SC-500 because AI security is integrated directly into the certification’s scope.
16. AI Threat Detection and Application Context
AI security can involve applications that sit between an end user and an AI service.
For example:
User → Web application → Azure OpenAI → Model
The AI service may see a request, but security investigators may need to understand:
- Which user initiated it?
- Which application generated it?
- What source IP was involved?
Defender for Cloud’s AI threat protection can use additional security context to improve alert investigation. Microsoft documents the use of fields such as end-user identity, source IP, and application name for supported Azure OpenAI scenarios.
The important SC-500 concept is:
AI workload protection is not limited to infrastructure configuration; it can also provide runtime threat detection and investigation context.
17. Azure-Only vs. Multicloud Defender Plans
Not every Defender for Cloud workload plan applies to every cloud.
Some plans support Azure, AWS, and GCP workloads, while others are Azure-specific.
For example, current support information identifies these as Azure-only plans:
- Defender for Storage
- Defender for Key Vault
- Defender for Resource Manager
- Defender for DNS
- Defender for App Service
- Defender for APIs
- Defender for AI Services
Defender for Servers and Defender for Containers, by contrast, have significant multicloud support.
Exam tip
If a question says:
“An organization wants to protect an AWS EC2 instance.”
Think about plans that support multicloud workloads, such as:
Defender for Servers
rather than Azure-only plans such as Defender for Storage.
18. Subscription-Level vs. Resource-Level Configuration
Defender for Cloud supports different deployment scopes depending on the plan.
A common approach is to enable a workload protection plan at the subscription level.
This is generally easier to manage and provides broader coverage.
Some scenarios also support resource-level configuration.
For example, Defender for Servers can be configured at different scopes, although Microsoft recommends subscription-level deployment for many scenarios.
However, resource-level configuration can be useful when:
- Different workloads require different protection levels.
- Specific resources need to be excluded.
- An organization is transitioning workloads.
- Different security requirements exist within the same subscription.
Important exam concept
Do not assume every Defender plan supports the same resource-level configuration options.
Always evaluate the specific plan.
19. Management Group Deployment
Large organizations often have many subscriptions.
Enabling every Defender plan manually on every subscription can be inefficient.
Defender for Cloud can be managed at larger scopes, including management groups, where supported.
This enables organizations to establish consistent protection across a portfolio of subscriptions.
The basic enterprise pattern is:
Management Group
↓
Subscriptions
↓
Workloads
The objective is centralized governance combined with consistent security coverage.
20. Deploying Defender Plans at Scale
Azure Policy can be used to help configure Defender for Cloud plans at scale.
Microsoft provides built-in policy initiatives for configuring Defender plans.
For example, there are built-in policies for:
- Defender for Servers
- Defender for Containers
- Defender for Storage
- Defender for Databases
- Defender for APIs
- Defender for AI Services
- Defender CSPM
- Other Defender capabilities
This is especially valuable when an organization wants to enforce security requirements consistently.
Example
An organization has 50 Azure subscriptions and wants Defender for Storage enabled consistently.
Instead of manually configuring each subscription, the organization can use an appropriate Azure Policy assignment to configure the plan at scale.
21. Azure Policy and Defender Plans
An important distinction is:
Azure Policy
can be used to enforce or deploy configurations.
Defender for Cloud
provides the security-management and workload-protection capabilities.
They work together.
For example, a policy can require that Defender for Storage be enabled.
The policy can evaluate the environment and deploy the appropriate configuration where applicable. Microsoft provides a built-in policy specifically for configuring Defender for Storage with its available capabilities.
22. Verifying Protection Coverage
Enabling a Defender plan is not the final step.
Security administrators should verify that the intended resources are actually covered.
Defender for Cloud provides a Coverage workbook that shows which plans are enabled and provides insight into coverage across subscriptions and resources.
A good operational workflow is:
Select plan
↓
Enable plan
↓
Configure plan-specific settings
↓
Deploy required components
↓
Verify coverage
↓
Review alerts/recommendations
↓
Remediate gaps
23. Why Verification Matters
Consider this scenario:
An administrator enables Defender for Servers at the subscription level.
They assume every VM is protected.
However:
- Some resources may have different configuration.
- Some resources may be excluded.
- Required components may not be deployed.
- Resource-level settings may override broader settings.
- Multicloud resources may require appropriate onboarding.
Therefore:
Turning a Defender plan on is not the same thing as proving that every intended workload is protected.
The Coverage workbook is designed to help validate the actual deployment state.
24. Monitoring Workload Protection
Defender for Cloud provides workload protection insights and security alerts.
The Workload protections area can show the status of advanced protection for workloads such as:
- Virtual machines
- SQL databases
- Containers
- Web applications
- Other supported workload types
Security alerts can provide:
- Affected resource
- Threat information
- Suggested remediation
- Additional investigation information
- In some cases, automated response options
This allows security teams to move from:
Protection configuration
to:
Threat detection and response
25. Important Licensing and Cost Considerations
Many workload protection plans are paid capabilities.
Before enabling a plan broadly, an organization should understand:
- Which workloads will be protected
- Which features will be enabled
- Which resources are in scope
- Whether the plan has multiple tiers
- Whether optional features incur additional costs
- Expected usage
- How long the plan will remain enabled
For example, Defender for Storage includes configurable malware-scanning capabilities, and Defender for APIs has plan selection considerations based on API traffic.
Exam strategy
If a scenario asks for the best security configuration, do not automatically choose the least expensive option.
First satisfy the security requirement.
If the question specifically introduces cost as a constraint, then cost becomes part of the decision.
26. Common SC-500 Workload Protection Scenarios
Scenario 1 — Virtual machines
Requirement: Detect vulnerabilities and protect Azure VMs.
Solution: Defender for Servers.
Scenario 2 — Kubernetes
Requirement: Detect container vulnerabilities and runtime threats in AKS.
Solution: Defender for Containers.
Scenario 3 — Malicious file uploads
Requirement: Detect malicious files uploaded to Blob Storage.
Solution: Defender for Storage with malware scanning.
Scenario 4 — Azure SQL
Requirement: Detect suspicious activity against Azure SQL databases.
Solution: Defender for Databases with Azure SQL Database protection enabled.
Scenario 5 — SQL Server on VM
Requirement: Protect SQL Server running on an Azure VM.
Solution: Configure the SQL Servers on Machines capability within Defender for Databases.
Scenario 6 — API attacks
Requirement: Discover and detect threats against APIs hosted through Azure API Management.
Solution: Defender for APIs.
Scenario 7 — AI threats
Requirement: Detect runtime threats targeting generative AI services.
Solution: Defender for AI Services.
Scenario 8 — Suspicious Azure management activity
Requirement: Detect suspicious Azure resource-management operations.
Solution: Defender for Resource Manager.
27. Common Mistakes to Avoid
Mistake 1: Confusing CSPM with workload protection
CSPM identifies posture weaknesses.
CWPP provides workload-specific protection.
Mistake 2: Enabling the wrong plan
A plan should be selected based on the workload being protected.
Mistake 3: Assuming one Defender plan protects everything
Defender for Cloud uses specialized plans for different workload categories.
Mistake 4: Assuming “On” means every feature is enabled
Some plans contain configurable components and tiers.
Mistake 5: Ignoring plan tiers
Defender for Servers has P1 and P2.
If a scenario requires a Plan 2 capability, enabling P1 is insufficient.
Mistake 6: Forgetting multicloud scope
Some Defender plans support AWS and GCP while others are Azure-only.
Mistake 7: Ignoring API traffic
Defender for APIs plan selection should take API traffic volume into account.
Mistake 8: Forgetting Storage malware scanning
Enabling Defender for Storage and enabling/configuring malware scanning are related but distinct considerations.
Mistake 9: Failing to verify coverage
Always verify that intended workloads are actually protected.
Mistake 10: Treating recommendations as runtime protection
A security recommendation identifies a security weakness.
A workload protection plan provides additional protection against threats.
They complement one another.
28. SC-500 Exam Comparison Table
| Requirement | Think About |
|---|---|
| Improve overall cloud security posture | CSPM |
| Improve Secure Score | CSPM |
| Identify misconfigurations | CSPM |
| Protect Azure VMs | Defender for Servers |
| Protect Kubernetes | Defender for Containers |
| Detect malicious files in Storage | Defender for Storage |
| Protect Azure SQL | Defender for Databases |
| Protect SQL Server on machines | Defender for Databases → SQL Servers on Machines |
| Protect App Service | Defender for App Service |
| Protect APIs | Defender for APIs |
| Protect Key Vault | Defender for Key Vault |
| Protect generative AI services | Defender for AI Services |
| Detect suspicious Azure management activity | Defender for Resource Manager |
| Detect DNS threats | Defender for DNS |
| Apply configuration consistently at scale | Azure Policy |
| Verify plan/resource coverage | Coverage workbook |
29. Recommended Deployment Method
For an enterprise environment, a strong implementation approach is:
Step 1 — Inventory workloads
Identify:
- VMs
- Containers
- Storage
- Databases
- APIs
- App Services
- Key Vaults
- AI services
- Other cloud workloads
Step 2 — Map workloads to Defender plans
Determine which workload protection plan applies to each workload.
Step 3 — Determine scope
Decide whether protection should apply at:
- Management group
- Subscription
- Resource
- Connected multicloud environment
Step 4 — Select appropriate tiers
For plans with multiple tiers, select the tier that satisfies the security requirement.
Step 5 — Configure plan-specific features
Examples include:
- Server vulnerability assessment
- Server agentless scanning
- Storage malware scanning
- Storage sensitive-data detection
- Container runtime protection
- Container registry scanning
- API plan selection
- AI threat protection
Step 6 — Automate deployment
Use Azure Policy where appropriate to establish consistent deployment at scale.
Step 7 — Verify coverage
Use Defender for Cloud’s Coverage workbook.
Step 8 — Monitor
Review:
- Security alerts
- Recommendations
- Coverage
- Workload protection status
Step 9 — Remediate
Address identified vulnerabilities and configuration gaps.
30. Key Takeaways
For the SC-500 exam, remember these principles:
- Defender for Cloud combines CSPM and workload protection capabilities.
- CWPP plans are workload-specific.
- Choose the Defender plan based on the workload that needs protection.
- Defender for Servers has Plan 1 and Plan 2.
- Plan 2 provides additional advanced server protection capabilities.
- Defender for Storage can provide malware scanning and sensitive-data threat detection.
- Defender for Databases protects supported database workloads.
- Defender for Containers protects Kubernetes environments.
- Defender for APIs protects APIs managed through Azure API Management.
- Defender for AI Services provides specialized protection for supported AI workloads.
- Not every Defender plan supports AWS and GCP.
- Azure Policy can help deploy Defender plans consistently at scale.
- Enabling a plan is not the same as verifying coverage.
- Use the Coverage workbook to validate deployment coverage.
- Always distinguish posture management from active workload protection.
The central exam concept is simple:
Identify the workload → select the appropriate Defender plan → choose the required tier/features → deploy at the appropriate scope → verify coverage → monitor and remediate.
Practice Exam Questions
Question 1
An organization has several Azure virtual machines. The security team wants to detect vulnerabilities, integrate endpoint protection, and provide additional threat protection for the machines.
Which Microsoft Defender for Cloud plan should the organization enable?
A. Defender for Servers
B. Defender for Storage
C. Defender for APIs
D. Defender for Key Vault
Answer: A. Defender for Servers
Explanation: Defender for Servers is the workload protection plan designed for server and machine workloads. It provides capabilities such as vulnerability assessment and Defender for Endpoint integration. Defender for Storage protects storage accounts, Defender for APIs protects APIs, and Defender for Key Vault protects Key Vault resources.
Question 2
A security administrator needs to protect an AKS environment against container vulnerabilities and runtime threats.
Which Defender for Cloud plan should be configured?
A. Defender for App Service
B. Defender for Resource Manager
C. Defender for Servers
D. Defender for Containers
Answer: D. Defender for Containers
Explanation: Defender for Containers is designed to protect Kubernetes environments such as AKS. Depending on the configuration, it can provide vulnerability assessment, runtime threat protection, posture assessment, agentless scanning, registry assessment, and other Kubernetes security capabilities. Defender for Servers is intended primarily for machine workloads.
Question 3
A company uploads documents to Azure Blob Storage. The security team wants Defender for Cloud to identify malicious files when they are uploaded.
Which capability should be configured?
A. Defender for Storage malware scanning
B. Defender for Databases
C. Defender for Key Vault
D. Defender for APIs
Answer: A. Defender for Storage malware scanning
Explanation: Defender for Storage provides on-upload malware scanning for supported storage workloads. The capability is specifically intended to detect malicious files uploaded to storage. Defender for Key Vault, Databases, and APIs address different workload types.
Question 4
An organization enables Defender for Servers and needs a capability that is associated with Plan 2 rather than Plan 1.
Which plan should the organization select?
A. Foundational CSPM
B. Defender for Servers Plan 1
C. Defender CSPM
D. Defender for Servers Plan 2
Answer: D. Defender for Servers Plan 2
Explanation: Defender for Servers has Plan 1 and Plan 2. Plan 2 provides additional advanced capabilities, including agentless scanning. File integrity monitoring is also available as a Plan 2 capability, although it isn’t enabled by default.
Question 5
A company uses Azure API Management and wants to discover APIs, assess their security posture, prioritize API vulnerabilities, and detect active API threats.
Which Defender for Cloud plan should be used?
A. Defender for APIs
B. Defender for App Service
C. Defender for Containers
D. Defender for Resource Manager
Answer: A. Defender for APIs
Explanation: Defender for APIs provides discovery, security posture visibility, vulnerability prioritization, and runtime threat detection for APIs managed through Azure API Management. The APIs must be appropriately onboarded, and plan selection should account for API traffic requirements.
Question 6
An organization wants to apply Microsoft Defender for Cloud workload protection configurations consistently across a large number of Azure subscriptions.
Which service is most appropriate for enforcing configuration at scale?
A. Azure Bastion
B. Azure Policy
C. Azure Monitor
D. Azure DNS
Answer: B. Azure Policy
Explanation: Azure Policy can be used to enforce and deploy security configurations consistently across Azure resources and subscriptions. Microsoft provides built-in policy definitions and initiatives for configuring various Defender for Cloud plans, including Defender for Servers, Storage, Containers, APIs, AI Services, and others.
Question 7
A security engineer wants to verify which subscriptions and resources are actually covered by the Defender for Cloud plans that have been enabled.
Which capability should the engineer use?
A. Secure Score
B. Regulatory Compliance dashboard
C. Coverage workbook
D. Azure Service Health
Answer: C. Coverage workbook
Explanation: The Defender for Cloud Coverage workbook provides visibility into which Defender plans are enabled and the resulting coverage across subscriptions and resources. This is particularly important because simply enabling a plan does not necessarily mean that every intended workload has been successfully protected.
Question 8
A company is deploying a generative AI application and wants specialized Defender for Cloud protection that can identify threats targeting supported AI services.
Which plan should the security team consider?
A. Defender for DNS
B. Defender for Key Vault
C. Defender for Storage
D. Defender for AI Services
Answer: D. Defender for AI Services
Explanation: Defender for AI Services provides specialized threat protection for supported generative AI services and applications. Defender for Cloud’s AI protection capabilities can provide discovery, posture assessment, runtime threat detection, and investigation capabilities for AI workloads.
Question 9
An organization has an Azure SQL Database and wants to enable Defender for Cloud’s attack detection and threat-response capabilities for that database.
Which configuration should the administrator use?
A. Defender for Databases with Azure SQL Databases enabled
B. Defender for Servers Plan 2
C. Defender for Storage
D. Defender for Containers
Answer: A. Defender for Databases with Azure SQL Databases enabled
Explanation: Azure SQL Database protection is configured through the Defender for Databases plan. The administrator selects the Databases plan and enables the Azure SQL Databases resource type. Defender for Servers is intended for machine workloads, while Storage and Containers address different workload categories.
Question 10
An organization has connected its AWS environment to Microsoft Defender for Cloud. The security team wants to protect Windows and Linux EC2 instances against threats.
Which Defender for Cloud plan is the best fit?
A. Defender for Storage
B. Defender for Servers
C. Defender for APIs
D. Defender for AI Services
Answer: B. Defender for Servers
Explanation: Defender for Servers supports multicloud machine workloads, including supported AWS and GCP machines. AWS and GCP machines use the appropriate Defender for Cloud onboarding mechanisms, including Azure Arc for supported server scenarios. Azure-only plans such as Defender for Storage, APIs, and AI Services are not the appropriate choice for protecting EC2 machines.
Final SC-500 Exam Reminder
When you see a Defender for Cloud workload-protection question, first ask:
“What workload am I protecting?”
Then map it to the appropriate plan:
Servers → Defender for Servers
Containers/Kubernetes → Defender for Containers
Storage → Defender for Storage
Databases → Defender for Databases
App Service → Defender for App Service
APIs → Defender for APIs
Key Vault → Defender for Key Vault
AI Services → Defender for AI Services
Resource management → Defender for Resource Manager
DNS → Defender for DNS
Then determine whether the question requires a particular plan tier, feature, deployment scope, or configuration option.
Finally, remember to verify actual coverage rather than assuming that enabling the plan means the deployment is complete.
This topic is important for SC-500 because Microsoft is increasingly treating AI workloads as a first-class security workload, so I would expect questions to test not only the traditional Servers/Storage/Databases/Containers plans but also Defender for AI Services, Defender for APIs, plan-specific configuration, and coverage verification.
Go to the SC-500 Exam Prep Hub main page
