AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel • Set 11
AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel Practice Test 11 — 15 questions with explanations. Free, no signup.
You are a security engineer for a multinational company with 5000 Azure VMs across multiple subscriptions. You have deployed Microsoft Sentinel to ingest logs from all VMs via the Log Analytics agent. You need to create a detection rule that identifies potential cryptocurrency mining activity based on network traffic patterns. The rule should trigger an incident when any single VM communicates with a known mining pool IP address over port 3333, 4444, or 8333 within a 5-minute window. Additionally, to reduce noise, the rule should only trigger if the same VM sends more than 10 such connections in that window. You have a custom KQL function that extends the CommonSecurityLog table with an 'IsMiningPool' boolean column. Which of the following approaches should you use to create the rule?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.