Microsoft Certified:Azure Security Engineer Associate
Domain 4Objective 4
Configure and Manage Security Monitoring and Automation Solutions AZ-500 Practice Questions (Page 4)
Part of the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain, which accounts for 30–35% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
30–35%of the exam
Questions 16–20
- 16
What is the role of a playbook in Microsoft Sentinel?
Select an answer first - 17
A company uses Microsoft Sentinel and wants to ingest firewall logs from their on-premises Palo Alto firewall. They have a syslog server that receives the logs. What should they configure in Sentinel to ingest these logs?
Select an answer first - 18
A company uses Defender for Cloud and wants to automate the response to a specific security alert type by running a Logic App that isolates the affected VM. They want this to happen only for alerts with a 'Confirmed' status. What should you do?
Select an answer first - 19
Your organization uses Microsoft Sentinel. You need to ingest sign-in logs from Microsoft Entra ID and then create an analytics rule that triggers when a user signs in from an impossible travel location. What should you configure first?
Select an answer first - 20
Which Azure Monitor component is used to collect network security events and performance data from virtual machines?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.