AZ-500 Manage identity and access Practice Question
A team wants to deploy Sentinel content consistently across workspaces. Which two approaches are appropriate?
⚠ Common exam trap
Many candidates confuse 'storing incidents' (operational data) with 'deploying content' (configuration), leading them to incorrectly select Azure Key Vault as a deployment mechanism for Sentinel rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Content Hub solutions where available
Content Hub solutions in Azure Sentinel provide pre-packaged content (analytic rules, workbooks, playbooks) that can be installed consistently across multiple workspaces via the Azure portal or API. This ensures standardized deployment without manual errors, leveraging Microsoft's curated content for common scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually copy screenshots of rules
Why it's wrong here
Screenshots are static images that contain no executable rule logic, query text, or schedule settings, so they cannot be programmatically applied to another workspace. Recreating rules from screenshots is a manual, error-prone process that almost certainly introduces configuration drift between environments. While screenshots may be useful for documentation, they are not a deployment mechanism and fail the consistency requirement.
- ✓
Use Content Hub solutions where available
Why this is correct
Content Hub solutions are Microsoft Sentinel's packaged, versioned bundles of data connectors, analytic rules, workbooks, and playbooks. Installing the same solution across multiple workspaces guarantees a common content baseline and simplifies updates because solutions can be centrally managed. This is correct because it directly addresses consistent, repeatable content deployment at scale.
- ✗
Store incidents in Azure Key Vault
Why it's wrong here
Azure Key Vault is a secrets management service for keys, certificates, and passwords, not a repository for operational incidents or Sentinel content. Storing incidents there would not push any rule, workbook, or data connector into target workspaces, and it would also interfere with Sentinel's incident lifecycle and investigation workflows. This option confuses secure storage with content deployment, making it incorrect.
- ✓
Use infrastructure-as-code or automation for analytic rules and workbooks
Why this is correct
Infrastructure-as-code approaches—such as ARM templates, Bicep, Terraform, or Azure Pipelines—treat analytic rules and workbooks as version-controlled artifacts that can be deployed repeatedly to multiple workspaces. This ensures identical rule logic and workbook configuration, and it enables automated validation, rollback, and audit trails. It is the other correct answer because it provides a scalable, consistent deployment path, especially for custom content not available in Content Hub.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.