Manage and monitor security posture

Worth 25% of the Microsoft Cloud and AI Security Engineer (SC-500) exam. CertClue has 46 questions on this objective.

What this objective covers

Secure Score, Recommendations and Attack Path Analysis

Microsoft Defender for Cloud turns a sprawling list of misconfigurations into something prioritized and measurable, using three connected features that build on each other.

Exam tip. When a scenario asks which single misconfiguration to fix first among several unrelated findings, the answer usually comes from attack path analysis, since it accounts for exploitability and reachability rather than counting recommendations in isolation.

Microsoft Sentinel: From Ingested Log to Closed Incident

Microsoft Sentinel is Microsoft's cloud native SIEM and SOAR. Data flows through a consistent pipeline from ingestion to detection to response, and exam scenarios usually test whether you know which stage a given feature belongs to.

Exam tip. If a scenario needs an automatic action taken the moment an incident is created, such as disabling a user, the answer is an automation rule triggering a playbook, not an analytics rule; the analytics rule only creates the incident in the first place.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. Brindlewell Foundation's security team wants a single quantified measure of the organization's overall security posture across subscriptions in Defender for Cloud, with prioritized recommendations weighted by the impact each one would have if remediated. Which feature should they use?

  • A. Microsoft Defender for Cloud secure scorecorrect
  • B. Microsoft Sentinel analytics rules
  • C. The regulatory compliance dashboard
  • D. Attack path analysis

Secure score aggregates security recommendations into a single quantified percentage and weights each recommendation by its potential impact on the score, giving a prioritized view of posture improvement opportunities. Sentinel analytics rules generate alerts from log data, not a posture score. The regulatory compliance dashboard maps controls to specific standards rather than giving one unified score. Attack path analysis visualizes exploitable paths to critical assets, it is a different lens than a single score.

2. Coastwise Shipping wants that whenever Defender for Cloud generates the recommendation that a storage account has public blob access enabled, the account is automatically remediated by disabling public access, without an admin manually reviewing and applying the fix each time. What should be configured?

  • A. A static Azure Policy assignment with no trigger tied to the specific recommendation's lifecycle
  • B. A Sentinel automation rule scoped to Sentinel incidents only
  • C. Workflow automation in Defender for Cloud that triggers a Logic App when that specific recommendation is generatedcorrect
  • D. Manual review of the recommendation by an administrator each time it appears

Defender for Cloud's workflow automation lets you trigger a Logic App automatically whenever a specific recommendation, alert, or regulatory compliance change occurs, enabling automated remediation like disabling public blob access without manual intervention. A static policy assignment does not by itself wire remediation to the recommendation event, a Sentinel automation rule is scoped to Sentinel incidents rather than Defender for Cloud recommendations, and manual review is exactly the manual step being eliminated.

Work the whole objective

The full Microsoft Cloud and AI Security Engineer bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free Microsoft Cloud and AI Security Engineer practice test

The other Microsoft Cloud and AI Security Engineer objectives