AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company uses Microsoft Sentinel for security monitoring. You need to design a solution to detect when a user account is created in Microsoft Entra ID with Global Administrator privileges. When detected, an incident must be created in Sentinel and the account should be disabled temporarily until reviewed. You want to use built-in capabilities where possible. What should you do?
⚠ Common exam trap
The trap here is that candidates may overcomplicate the solution by choosing custom KQL queries or external services (like Defender for Cloud Apps) when a built-in analytics rule template and playbook are available and sufficient for the detection and automated response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Microsoft Sentinel analytics rule template for 'Suspicious Entra ID role assignment' and configure a playbook to disable the account via Microsoft Graph API.
It uses a built-in Sentinel analytics rule template specifically designed to detect suspicious Entra ID role assignments, which meets the requirement for built-in capabilities. The playbook, triggered by the rule, can use the Microsoft Graph API to disable the account temporarily, providing automated remediation without custom code or external services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Entra Privileged Identity Management to require approval for role activation, and audit logs to detect permanent assignments.
Why it's wrong here
Privileged Identity Management (PIM) enforces just-in-time access by requiring approval for role activations, but it does not detect or report on pre-existing permanent assignments that were made outside PIM. Audit logs in Entra ID only record events; they provide evidence but no automated remediation. Since the requirement implies automated detection of suspicious assignments and disabling the account, PIM alone lacks both the detection logic for existing permanent roles and the capability to disable the identity.
- ✗
Use Microsoft Defender for Cloud Apps to monitor for privileged role assignments and send an alert to Sentinel.
Why it's wrong here
Microsoft Defender for Cloud Apps can send alerts to Sentinel when it detects changes in privileged role assignments, and it can use policies to trigger governance actions in cloud apps. However, it is not a SOAR engine and has no built-in playbook that directly calls the Graph API to disable an Entra ID account. The alert would still require someone to manually investigate and execute the remediation; it also does not evaluate the same contextual 'suspicious' criteria as Sentinel's built-in analytics rule.
- ✓
Use a Microsoft Sentinel analytics rule template for 'Suspicious Entra ID role assignment' and configure a playbook to disable the account via Microsoft Graph API.
Why this is correct
The Sentinel analytics rule template 'Suspicious Entra ID role assignment' is purpose-built to detect privileged role assignments that match known attack patterns, such as a new administrator added to a highly privileged role outside normal activation times. Because it natively surfaces the event as an incident, you can attach an automated playbook that invokes Microsoft Graph API to disable the compromised account immediately. This combination provides detection, correlation, and automated response exactly as required.
- ✗
Create a custom KQL query in Log Analytics and schedule it as a Sentinel analytics rule, then use an Azure Function to disable the account.
Why it's wrong here
Writing a custom KQL query and scheduling it as a Sentinel analytics rule is a valid approach, but it reinvents a detection that already exists as a Microsoft-provided template, adding unnecessary effort and maintenance overhead. Using an Azure Function for the remediation introduces a separate compute resource that must be patched, authenticated, and monitored, whereas a Sentinel playbook is the native, serverless authentication pipeline to Graph API. The built-in template also has tested mapping and alert enrichment that custom KQL would need to replicate from scratch.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.