AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel • Set 5
AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel Practice Test 5 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel and wants to create a custom analytics rule to detect failed logon attempts from a specific IP address. The rule should run every hour and look for the event in the SecurityEvent table. However, the rule never triggers even though the events exist. What is the most likely cause?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.