Microsoft Certified:Azure Security Engineer Associate
Domain 4Objective 4
Configure and Manage Security Monitoring and Automation Solutions AZ-500 Practice Questions (Page 5)
Part of the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain, which accounts for 30–35% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
30–35%of the exam
Questions 21–25
- 21
A security analyst wants to automatically close low-severity incidents in Microsoft Sentinel that are generated by a specific analytics rule and are false positives. They also want to be notified via email when this happens. What should you configure?
Select an answer first - 22
Your organization uses Microsoft Sentinel. You need to ingest DNS query logs from your on-premises DNS servers. You have installed the Log Analytics agent on the DNS servers. What should you configure in Sentinel to start collecting the DNS logs?
Select an answer first - 23
A security operations center (SOC) wants to automatically assign incidents in Microsoft Sentinel to the appropriate analyst based on the incident title. For example, incidents containing 'Ransomware' should be assigned to the 'Threat Team'. What should you configure?
Select an answer first - 24
A company uses Microsoft Sentinel. They have multiple data connectors enabled, including Azure AD and Azure Activity. They want to create an analytics rule that detects when a user is added to a privileged role and then performs a suspicious Azure action within 5 minutes. They also want to automatically disable the user if the rule triggers. What should they do?
Select an answer first - 25
A security team has a scheduled analytics rule in Microsoft Sentinel that runs every 5 minutes and queries the SigninLogs table for failed logons. The rule is generating a high number of low-severity incidents, overwhelming the SOC. They want to reduce noise while still detecting genuine brute-force attacks. They also want to automatically suppress incidents for known benign IP addresses. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.