AZ-500 Manage identity and access Practice Question
A security analyst uses Microsoft Defender for Cloud to monitor the security posture of their Azure subscription. They want to receive an email notification whenever a high-severity security alert is generated for any of their Azure resources. What should they configure in Defender for Cloud?
⚠ Common exam trap
Candidates often confuse Defender for Cloud's native email notification settings with Azure Monitor alert rules or Logic Apps playbooks, assuming that security alerts must be routed through external services to trigger email, when in fact Defender for Cloud provides a direct configuration option for this purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure email notifications in the Defender for Cloud settings under 'Notifications'.
Microsoft Defender for Cloud has a built-in 'Email notifications' setting under its environment settings that allows you to configure email recipients for high-severity alerts directly, without needing external services. This feature sends real-time email notifications for security alerts based on severity levels you define, making it the simplest and most direct method for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an alert rule in Azure Monitor that triggers an email when a security alert is raised.
Why it's wrong here
Creating an alert rule in Azure Monitor is not the direct mechanism for receiving email notifications for security alerts generated by Microsoft Defender for Cloud. Defender for Cloud has dedicated email notification settings within its own portal, specifically designed to configure recipients for high-severity security alerts. Azure Monitor alert rules are primarily used for monitoring resource metrics, activity logs, or custom log queries in Log Analytics workspaces, making them suitable for alerting on broader operational issues or security events *exported* to Log Analytics, rather than native Defender for Cloud alerts.
- ✓
Configure email notifications in the Defender for Cloud settings under 'Notifications'.
Why this is correct
Configuring email notifications directly in Microsoft Defender for Cloud is the native, built-in mechanism for receiving security alert emails. In the Defender for Cloud portal, you navigate to Environment Settings, select the relevant subscription, and under 'Notifications' you can specify recipient email addresses and the severity levels (e.g., High, Medium, Low) that trigger emails. This setting is managed within Defender for Cloud itself, so it does not require external services like Azure Monitor, Logic Apps, or a separate SIEM, and it is the exact option designed for this scenario.
- ✗
Use a Logic Apps playbook to send an email when a new alert is generated.
Why it's wrong here
Using a Logic Apps playbook is incorrect because Defender for Cloud provides a native 'Email notifications' setting specifically for sending email alerts based on severity. Logic Apps are designed for orchestrating automated responses, such as triggering remediation actions or integrating with external systems like a SIEM or ticketing platform, rather than configuring basic alert notifications directly. It is tempting as Logic Apps can send emails, but they are for custom, automated workflows beyond simple, built-in alerting.
- ✗
Set up a workflow automation rule in Microsoft Sentinel to forward alerts to email.
Why it's wrong here
Setting up a workflow automation rule in Microsoft Sentinel is not the correct way to receive email notifications for Defender for Cloud alerts because Sentinel is a separate, cloud-native SIEM platform, not the alerting engine for Defender for Cloud. Workflow automation rules in Sentinel are used to automate incident response tasks, such as creating tickets or triggering playbooks, and they require Defender for Cloud to be connected as a data source via the continuous export or connector, which is an additional, indirect integration. In contrast, Defender for Cloud has its own 'Email notifications' configuration under the portal's Settings/Notifications section, which directly sends alert emails based on severity without relying on Sentinel's separate automation framework.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 194-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.