Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Azure Security Engineer Associate

Domain 4Objective 4

Configure and Manage Security Monitoring and Automation Solutions AZ-500 Practice Questions (Page 6)

Part of the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain, which accounts for 30–35% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts
30–35%of the exam

Questions 26–30

  1. 26application · medium

    A security analyst wants to receive an email notification whenever a specific analytics rule in Sentinel detects a threat. They also want to automatically create a Microsoft Teams message. What should they configure?

    Select an answer first
  2. 27foundation · easy

    In Microsoft Sentinel, what is the primary function of an analytics rule?

    Select an answer first
  3. 28expert · hard

    A company has Defender for Cloud enabled on multiple subscriptions. They want to automate the response to high-severity alerts by creating a ticket in ServiceNow and notifying the on-call engineer. However, they have a requirement that alerts from the 'Production' subscription must be handled differently: they should also trigger a Logic App that isolates the affected VM. They want to minimize administrative overhead. What should you do?

    Select an answer first
  4. 29expert · hard

    A global company uses Microsoft Sentinel in a single workspace in the US. They need to ingest Azure Activity logs from multiple subscriptions, including subscriptions in the EU. They also want to create analytics rules that detect suspicious Azure resource changes. Compliance requires that EU data not leave the EU. What should they do?

    Select an answer first
  5. 30application · medium

    A company uses Azure Monitor to collect network performance counters from Windows VMs. They now want to send selected network security events (Event ID 5156 and 5157) from those VMs to a Log Analytics workspace. They already have the Azure Monitor Agent installed. What should you configure to collect only those events?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.