Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to ensure that an alert is generated when an Azure VM is created with an open inbound SSH port (22) from the internet. The solution should use existing Azure resources and minimize administrative overhead. What should you use?

⚠ Common exam trap

The trap here is that candidates may overcomplicate the solution by choosing Defender for Cloud or Azure Policy, thinking they need a security-specific service, when the simplest path is to use the already-connected Azure Activity data connector in Sentinel to monitor control-plane operations for risky configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Microsoft Sentinel analytics rule using the Azure Activity data connector.

Microsoft Sentinel's Azure Activity data connector ingests resource logs from Azure's control plane (Azure Resource Manager). By creating an analytics rule that detects a 'Microsoft.Compute/virtualMachines/write' operation with a network security group rule allowing inbound SSH (port 22) from 'Internet' (any IP), you can generate an alert without deploying additional agents or infrastructure. This minimizes administrative overhead by using existing Sentinel resources and the built-in Activity log connector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Microsoft Sentinel analytics rule using the Azure Activity data connector.

    Why this is correct

    The Azure Activity data connector ingests control-plane events for virtual machine creation and updates. An analytics rule can filter for `Microsoft.Compute/virtualMachines/write` and use KQL to correlate the resource ID with NSG flow logs, network security rules, or resource properties to determine when a new VM is publicly accessible with port 22 open. This is the only option that combines the exact ARM event with a configurable check for SSH port exposure inside a single detection rule.

  • ✗

    Create an Azure Policy with audit effect and configure a Sentinel data connector for Azure Policy.

    Why it's wrong here

    Azure Policy with `audit` effect evaluates resource configuration against governance rules and writes compliance findings, but it does not emit security events or alerts that Sentinel can consume without custom connectors. There is no native Sentinel data connector for Azure Policy, and even if compliance data were streamed via event hubs, it would represent point-in-time state rather than the unauthorized action of opening an SSH port. This approach is neither event-driven nor real-time, so it cannot detect the VM creation-and-port-opening sequence as a single security incident.

  • ✗

    Create an Azure Monitor metric alert on the 'Network In' metric.

    Why it's wrong here

    An Azure Monitor metric alert on `Network In` measures bytes received per second on the VM's network interface, which is a performance counter, not a configuration-change signal. Elevated traffic does not reveal whether port 22 was opened, and opening a port produces no deterministic change in this metric until an external host actually sends traffic. Metric alerts only react to numeric threshold breaches, so they cannot watch for the ARM write operation that creates a VM or modifies an NSG rule.

  • ✗

    Enable Microsoft Defender for Cloud and configure a continuous export to Sentinel.

    Why it's wrong here

    Microsoft Defender for Cloud emits its own security alerts and recommendations, and continuous export to Sentinel streams those findings, but it does not provide raw Azure Activity events or allow you to author a custom detection rule for an exact ARM operation. Defender for Cloud's alerting is based on its built-in rule sets, which may not include a bespoke scenario like 'new VM with SSH open to the internet.' Continuous export is a delivery mechanism, not an analytics-rule authoring engine, so it cannot substitute for a Sentinel analytics rule on the Azure Activity connector.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.