AZ-500 • Practice Test 9
Free AZ-500 practice test — 10 questions with explanations. Set 9. No signup required.
A security team uses Microsoft Sentinel. They want to detect a potential privilege escalation scenario: when a user is added to the Global Administrator role in Azure AD (audit log) and within 10 minutes that user signs in from a suspicious location (sign-in log). Which type of analytics rule should they create to correlate these two different log sources?
Choose an answer to begin — your selection is scored in the full session.
10 questions · instant feedback and full explanations after every question.