Courseiva

AZ-500 Manage identity and access Practice Question

A team wants to deploy Sentinel content consistently across workspaces. Which two approaches are appropriate?

⚠ Common exam trap

Many candidates confuse 'storing incidents' (operational data) with 'deploying content' (configuration), leading them to incorrectly select Azure Key Vault as a deployment mechanism for Sentinel rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Content Hub solutions where available

Content Hub solutions in Azure Sentinel provide pre-packaged content (analytic rules, workbooks, playbooks) that can be installed consistently across multiple workspaces via the Azure portal or API. This ensures standardized deployment without manual errors, leveraging Microsoft's curated content for common scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually copy screenshots of rules

    Why it's wrong here

    Screenshots are static images that contain no executable rule logic, query text, or schedule settings, so they cannot be programmatically applied to another workspace. Recreating rules from screenshots is a manual, error-prone process that almost certainly introduces configuration drift between environments. While screenshots may be useful for documentation, they are not a deployment mechanism and fail the consistency requirement.

  • ✓

    Use Content Hub solutions where available

    Why this is correct

    Content Hub solutions are Microsoft Sentinel's packaged, versioned bundles of data connectors, analytic rules, workbooks, and playbooks. Installing the same solution across multiple workspaces guarantees a common content baseline and simplifies updates because solutions can be centrally managed. This is correct because it directly addresses consistent, repeatable content deployment at scale.

  • ✗

    Store incidents in Azure Key Vault

    Why it's wrong here

    Azure Key Vault is a secrets management service for keys, certificates, and passwords, not a repository for operational incidents or Sentinel content. Storing incidents there would not push any rule, workbook, or data connector into target workspaces, and it would also interfere with Sentinel's incident lifecycle and investigation workflows. This option confuses secure storage with content deployment, making it incorrect.

  • ✓

    Use infrastructure-as-code or automation for analytic rules and workbooks

    Why this is correct

    Infrastructure-as-code approaches—such as ARM templates, Bicep, Terraform, or Azure Pipelines—treat analytic rules and workbooks as version-controlled artifacts that can be deployed repeatedly to multiple workspaces. This ensures identical rule logic and workbook configuration, and it enables automated validation, rollback, and audit trails. It is the other correct answer because it provides a scalable, consistent deployment path, especially for custom content not available in Content Hub.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.