Microsoft Certified:Azure Security Engineer Associate
Domain 4Objective 4
Configure and Manage Security Monitoring and Automation Solutions AZ-500 Practice Questions (Page 8)
Part of the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain, which accounts for 30–35% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
30–35%of the exam
Questions 36–37
- 36
An organization uses Microsoft Sentinel as its SIEM. They want to ingest sign-in logs from Microsoft Entra ID (Azure AD) and then create a detection rule that alerts when a user signs in from an impossible travel location. What should you configure in Microsoft Sentinel?
Select an answer first - 37
A multinational company uses Microsoft Sentinel in a single workspace. They need to ingest AWS CloudTrail logs and Azure AD sign-in logs. They also want to create an analytics rule that correlates failed sign-ins with AWS console activity. Compliance requires that data from the EU region stays in the EU. What should they do?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to AZ-500
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.