AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel • Set 7
AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel Practice Test 7 — 15 questions with explanations. Free, no signup.
Your company uses Microsoft Sentinel to monitor security events. You are asked to create an analytics rule that detects when a user outside of business hours (9 PM to 5 AM) performs a high-risk operation like deleting a large number of Azure resources. The rule must trigger an incident and assign it to the SOC team. Which rule type and configuration should you use?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.