Microsoft Certified:Azure Security Engineer Associate
Domain 4Objective 4
Configure and Manage Security Monitoring and Automation Solutions AZ-500 Practice Questions (Page 2)
Part of the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain, which accounts for 30–35% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
30–35%of the exam
Questions 6–10
- 6
A security team wants to detect when multiple failed logons occur for the same user account in Microsoft Sentinel. They have enabled the 'Windows Security Events' data connector. What should they do to create a detection for this?
Select an answer first - 7
A company uses Defender for Cloud and Azure Monitor. They receive security alerts from Defender for Cloud, and they also collect network performance data using the Azure Monitor Agent. They want to create a unified view of security alerts and network performance data in a single dashboard. They also want to automate the response to high-severity alerts by creating a ticket in their ITSM system. What should they do?
Select an answer first - 8
An organization wants to use Microsoft Sentinel to detect threats from their on-premises Active Directory. They have already installed the Azure Monitor Agent on domain controllers and configured a data collection rule to send Windows security events to a Log Analytics workspace. What else must they do to enable detection in Sentinel?
Select an answer first - 9
Which Azure service is commonly used as the target action in a Microsoft Defender for Cloud workflow automation to run a custom response?
Select an answer first - 10
Contoso's security team receives a high-severity Defender for Cloud alert for a compromised Linux VM. They want to automatically open a ticket in ServiceNow and notify the on-call engineer via email whenever a high-severity alert is triggered. The team also wants to keep the manual triage process for medium and low alerts. What should you configure in Defender for Cloud?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.