Microsoft Certified:Azure Security Engineer Associate
Domain 4Objective 4
Configure and Manage Security Monitoring and Automation Solutions AZ-500 Practice Questions (Page 7)
Part of the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain, which accounts for 30–35% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
30–35%of the exam
Questions 31–35
- 31
Contoso has Microsoft Defender for Cloud enabled on all subscriptions. The security team wants to automatically create a Microsoft Sentinel incident and assign it to the on-call analyst whenever a high-severity security alert is generated. They already have a Logic App that creates the Sentinel incident. What should you configure in Defender for Cloud to trigger the Logic App?
Select an answer first - 32
In Microsoft Sentinel, what is the primary purpose of an automation rule?
Select an answer first - 33
In Microsoft Defender for Cloud, what is the primary purpose of a workflow automation?
Select an answer first - 34
What is the purpose of a suppression rule in Microsoft Defender for Cloud?
Select an answer first - 35
Which of the following is a common data source that can be connected to Microsoft Sentinel using a built-in data connector?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.