AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel • Set 10
AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel Practice Test 10 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel to monitor hybrid environments. You have a Log Analytics workspace that collects Windows security events. You need to create an analytics rule that triggers when a user account is created on any server, but you only want to generate an incident if the account creation occurs outside of business hours (9 AM - 5 PM). How should you configure the rule query?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.