AZ-500 · domain
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
This AZ-500 domain covers Microsoft Defender for Cloud (CSPM, workload protections, secure score, regulatory compliance) and Microsoft Sentinel (data connectors, analytics rules, automation playbooks, workbooks). Questions test configuring continuous export, enabling Defender plans per resource type, connecting hybrid log sources, and building automated response with Logic Apps playbooks.
Focused practice
Practice Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You must configure Defender for Cloud plans and Sentinel data connectors, then build analytics rules and Logic Apps playbooks for automated response. The key is knowing which capability belongs to free foundational CSPM versus paid Defender plans, and how playbooks differ from automation rules.
Enabling Defender for Cloud plans per resource type and interpreting Secure Score recommendations
Configuring foundational CSPM versus Defender CSPM capabilities and continuous export to Log Analytics
Connecting data sources to Microsoft Sentinel using Azure Activity, Azure AD, and Windows Security Events connectors
Building Sentinel automation rules and Logic Apps playbooks triggered by Microsoft Defender XDR incidents
Watch out for
Common Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel exam traps
- ▸Assuming foundational CSPM includes attack path analysis or agentless scanning; those require the paid Defender CSPM plan.
- ▸Confusing Sentinel automation rules with playbooks: rules orchestrate, playbooks perform the actual remediation actions via Logic Apps.
- ▸Forgetting that Defender for Servers requires the Log Analytics agent or Azure Monitor Agent plus a workspace for full data.
Question index
All Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel questions (119)
Click any question to see the full explanation, or start a practice session above.
Your organization is using Microsoft Defender for Cloud to protect Azure SQL databases. You need to enable Advanced Threat Protection (ATP) for all existing and future Azure SQL databases in a subscription. The solution must minimize administrative effort. What should you do?
Hard2Your organization has a complex Azure environment with multiple subscriptions, each containing hundreds of VMs and PaaS services. You are responsible for ensuring that all resources are monitored for security threats using Microsoft Defender for Cloud. The environment includes: - Subscription A: Production workloads, requires the highest security posture. - Subscription B: Development environment, has a lower security budget. - Subscription C: Shared services (e.g., DNS, Active Directory). You need to implement the most cost-effective security monitoring solution that meets the following requirements: - All subscriptions must be covered by Defender for Cloud. - Production subscription must have vulnerability assessment for VMs. - Development subscription does not need vulnerability assessment but must have basic CSPM. - Shared services subscription must have advanced threat protection for Azure SQL databases. - You must minimize administrative overhead and ensure that security policies are centrally managed. What should you do?
Hard3Which TWO actions can be performed using Microsoft Defender for Cloud's 'Regulatory Compliance' dashboard?
Medium4You are configuring Microsoft Sentinel data connectors. Which data connector should you use to ingest logs from Microsoft Entra ID (Azure AD) audit logs and sign-in logs?
Easy5Which TWO features are available in Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) capabilities? (Choose two.)
Easy6You are using Microsoft Defender for Cloud to protect Azure Kubernetes Service (AKS) clusters. You need to receive alerts about suspicious activities within the cluster, such as privilege escalations. What should you enable?
Medium7You need to ensure that security alerts from Microsoft Defender for Cloud are sent to a central SIEM system. What should you configure?
Easy8You run the PowerShell command shown in the exhibit. After execution, you check the Log Analytics workspace in the Azure portal. The workspace is created successfully. However, when you try to onboard the workspace to Microsoft Sentinel, you receive an error that Sentinel cannot be enabled on this workspace. What is the most likely cause?
Easy9Refer to the exhibit. You are reviewing a scheduled analytics rule in Microsoft Sentinel that uses the KQL query shown. The rule is configured to run every hour. A security analyst reports that the rule is generating too many incidents. What is the most likely cause?
Hard10You are a security analyst using Microsoft Defender for Cloud. You need to ensure that any new Azure subscription added to your management group automatically receives the default security policy assignments and that security recommendations are continuously assessed. What should you enable?
Easy11Refer to the exhibit. A Microsoft Sentinel analytics rule uses this KQL query. What is the primary purpose of this rule?
Medium12Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the purpose of this query?
Medium13Your company uses Microsoft Sentinel to monitor Azure resources. A new analytics rule is created to detect anomalous access to storage accounts. The rule runs every 5 minutes and looks at the last 15 minutes of data. After deploying, the rule generates no alerts even though you suspect there are anomalies. What is the most likely issue?
Medium14Your organization has multiple Azure subscriptions managed by Microsoft Defender for Cloud. You need to ensure that all subscriptions have the same security policies applied, and that any new subscription automatically inherits these policies. What should you do?
Medium15Your security team is investigating a potential data exfiltration incident. They have identified that a user has been downloading large amounts of data from Azure Blob Storage to an external IP address. You need to create a Microsoft Sentinel analytics rule that triggers when more than 1 GB of data is downloaded from a storage account in a single hour. Which KQL query should be the basis of the rule?
Medium16Which THREE of the following are capabilities of Microsoft Defender for Cloud's workload protection plans?
Hard17You are responsible for securing an Azure environment using Microsoft Defender for Cloud. You need to reduce the number of false positive security alerts for a specific Azure SQL Database. The database is regularly scanned by a legitimate security tool that generates alerts. What should you do?
Easy18Your security operations center (SOC) uses Microsoft Sentinel. You need to ensure that an incident is automatically created when a specific type of alert fires from Microsoft Defender for Cloud. What is the most efficient way to configure this?
Medium19Your organization is migrating to Azure and needs to protect against advanced threats like fileless malware. You must use a solution that provides real-time protection and integrates with Microsoft Defender for Cloud. What should you deploy on Azure VMs?
Hard20Your company, Contoso Ltd., has a hybrid environment with 500 on-premises Windows servers and 200 Azure VMs. The Azure VMs are spread across multiple subscriptions. You need to implement a centralized security monitoring solution using Microsoft Sentinel. The requirements are: - Collect security events from all on-premises servers. - Collect Azure activity logs and VM logs from all Azure subscriptions. - Detect and respond to threats using built-in and custom analytics. - Automatically remediate common threats such as disabling compromised user accounts. - Ensure compliance with regulatory standards (e.g., NIST 800-53). - Minimize administrative overhead and cost. What should you do?
Hard21You are a security engineer for a large enterprise using Microsoft Sentinel. You have multiple workspaces deployed across different Azure regions to meet data residency requirements. You need to query data across all workspaces from a single query. You have set up a workspace as the 'central' workspace for cross-workspace queries. The central workspace has the necessary permissions to access the other workspaces. Which KQL operator should you use to include data from other workspaces in your query?
Medium22You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory. Which two data connectors are necessary to collect sign-in logs and audit logs?
Easy23A company has enabled Microsoft Defender for Cloud on all subscriptions. The security team wants to ensure that all virtual machines have vulnerability assessment solutions installed. What should they configure?
Medium24Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). You need to investigate a possible insider threat where a user is accessing sensitive data from unusual locations. Which Sentinel feature should you use to visualize the user's activities and related entities?
Hard25A security analyst receives a high-severity alert in Microsoft Sentinel indicating a potential brute-force attack against an Azure VM. The analyst wants to automatically block the attacker IP for 24 hours. What is the most efficient way to achieve this?
Easy26Which TWO are benefits of using Microsoft Sentinel's automation rules? (Choose two.)
Medium27You are a security analyst using Microsoft Sentinel. You need to create an analytics rule that triggers an incident when more than 10 failed sign-ins occur from the same IP address within 5 minutes. The rule should use a KQL query. Which query should you use?
Hard28You are configuring Microsoft Defender for Cloud's 'Workload protections' for a Kubernetes cluster that is already using Azure Kubernetes Service (AKS). The cluster has 'Azure Policy' enabled. You need to enable the 'Microsoft Defender for Containers' plan to protect the cluster. You have already enabled the plan at the subscription level. However, the cluster is not showing as protected in the 'Inventory' blade. You have confirmed that the 'Azure Policy for Kubernetes' add-on is installed. What should you do to ensure the cluster is protected?
Hard29Your company has a hybrid environment with on-premises servers and Azure VMs. All resources are onboarded to Microsoft Defender for Cloud. You need to receive alerts when a critical vulnerability is detected on any server. The security team wants to minimize false positives. What should you configure?
Medium30You are designing a Microsoft Sentinel deployment for a multinational company. The company requires that data from different geographic regions be stored separately to comply with data residency laws. What is the recommended approach?
Hard31You are a security engineer managing a Microsoft Sentinel workspace. The security operations team wants to automatically create a ServiceNow incident whenever a new high-severity incident is generated in Microsoft Sentinel. You need to configure the automation rule to trigger only for incidents with severity High and to include the incident's entities in the ServiceNow ticket. What should you do first?
Medium32A security team uses Microsoft Defender for Cloud's regulatory compliance dashboard to track compliance with PCI DSS. They notice that some controls are marked as 'N/A' even though they have relevant resources. What is the most likely reason?
Hard33Your company uses Microsoft Defender for Cloud to protect Azure resources. You want to enable the 'Defender for Containers' plan to secure AKS clusters. Which two configurations are necessary? (Choose two.)
Medium34Your organization uses Microsoft Defender for Cloud's workload protection for Azure SQL databases. You notice that Defender for Cloud is not generating alerts for anomalous activities on a specific SQL database. The database is in a VNet with a service endpoint enabled for SQL. What should you verify first?
Medium35Your company has multiple Azure subscriptions and wants to use Microsoft Sentinel as a SIEM. You need to collect security events from all Azure VMs, including existing and future ones. What should you use?
Easy36A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically respond to phishing emails detected by Microsoft Defender XDR. They want to create a playbook that, when triggered, will delete the email from all recipients' mailboxes. Which integration should the playbook use?
Medium37You have configured Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). You notice that sign-in logs for external guest users are not appearing in Sentinel. What is the most likely cause?
Hard38You are a security engineer at a company that uses Microsoft Sentinel. You need to create an automation rule that assigns a specific owner to incidents generated from a particular analytics rule and adds a comment. The automation rule must run when an incident is created. What should you use to define the condition?
Medium39Your organization uses Microsoft Sentinel to monitor security events. You need to configure automated response actions for incidents. Which TWO of the following can be used to trigger automated responses in Microsoft Sentinel?
Medium40A security analyst needs to query Microsoft Sentinel logs to find all sign-in events from a specific IP address in the last 24 hours. Which query language should the analyst use?
Easy41Refer to the exhibit. You assign this policy to a subscription that already has a security contact configured with email 'admin@contoso.com'. What will be the outcome?
Hard42You are configuring Microsoft Defender for Cloud for an Azure subscription. You want to receive email notifications when a high-severity alert is generated. What should you configure?
Easy43Which THREE are prerequisites for integrating Microsoft Sentinel with Microsoft Defender XDR? (Choose three.)
Hard44You need to prioritize security recommendations in Microsoft Defender for Cloud. Your compliance team requires a framework that maps to regulatory standards. What should you use?
Easy45You are configuring Microsoft Sentinel to use a playbook for automated response to incidents. The playbook needs to block the source IP address of a malicious sign-in on the Azure Firewall. Which Microsoft Sentinel feature should the playbook use?
Hard46You are a security engineer for a company that uses Microsoft Defender for Cloud. The security team wants to automatically trigger a Logic App playbook when a high-severity alert is generated for an Azure Storage account. The playbook must run without manual intervention. What should you configure?
Medium47A company is deploying Microsoft Sentinel in a new Azure subscription. The security team wants to ingest Windows security events from on-premises servers. Which data connector should they use?
Easy48Your company is using Microsoft Sentinel to monitor security events. You need to ensure that all incidents generated in Sentinel are automatically sent to a third-party ticketing system via a webhook. Which Sentinel feature should you configure?
Easy49Your security team wants to use Microsoft Defender for Cloud's 'Just-In-Time (JIT) VM access' to reduce the attack surface. Which Azure policy must be enabled on the subscription to use JIT?
Easy50You are evaluating Microsoft Defender for Cloud's cloud security posture management (CSPM) capabilities. You need to identify misconfigurations across your Azure, AWS, and GCP environments. What should you enable?
Easy51A company uses Microsoft Defender for Cloud to manage the security posture of multiple Azure subscriptions. The security team wants to ensure that all subscriptions are covered by the same Microsoft Defender for Cloud policy initiative, but one subscription is not showing compliance data. The subscription is in the same Azure AD tenant and has the same tags. What is the most likely cause?
Hard52Your company uses Microsoft Defender for Cloud's Security Posture Management (CSPM) features. You need to identify resources that are not compliant with the organization's security baseline. What should you do?
Medium53You need to configure a continuous export of Microsoft Defender for Cloud alerts to a third-party SIEM. Which feature should you use?
Easy54You manage security for a company using Microsoft Sentinel. The security team wants to automatically assign incidents to the on-call analyst based on the incident severity and the entity involved. They also want to ensure that when an incident is updated, the assignment is re-evaluated. You need to configure this with minimal administrative effort. What should you use?
Medium55You administer an Azure environment with Microsoft Defender for Cloud enabled. A security analyst reports that a suspicious process was executed on a virtual machine, but no alert was found in the portal. You need to ensure that Defender for Cloud can detect and alert on suspicious activities on the VM. What should you do?
Medium56Your company has Microsoft Sentinel deployed in multiple workspaces across several Azure regions. The security operations team wants to query data from all workspaces centrally using a single KQL query. What feature should you implement?
Hard57You are the security engineer for a multinational company that uses Azure to host critical workloads. The company has deployed Microsoft Defender for Cloud with the enhanced security features enabled on all subscriptions. Recently, a security audit revealed that several virtual machines (VMs) in the production environment are missing critical security updates. The audit report indicates that the VMs are not being assessed for missing updates by Defender for Cloud. You need to ensure that all VMs are automatically assessed for missing OS updates using Defender for Cloud's vulnerability assessment capabilities. The solution must minimize administrative overhead and should not require manual installation of agents on existing VMs. What should you do?
Hard58Your organization has a hybrid identity environment with Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You are using Microsoft Defender for Cloud to monitor security posture. You notice that the recommendation 'MFA should be enabled on accounts with owner permissions on your subscription' shows a status of 'Unhealthy' for some accounts, but those accounts already have Microsoft Entra Conditional Access policies requiring MFA. What is the most likely reason for the discrepancy?
Hard59Refer to the exhibit. You are reviewing the Microsoft Defender for Cloud settings for a subscription. The JSON shows that 'autoProvision' is set to true. What does this mean?
Medium60Your security team receives a high-priority alert from Microsoft Sentinel indicating a potential brute-force attack against an Azure SQL Database. The alert was generated by an analytics rule using the following KQL query: 'SigninLogs | where ResultType == "50057" | summarize Count = count() by UserPrincipalName, IPAddress | where Count > 10'. What is the most likely cause of the alert?
Medium61Which TWO are capabilities of Microsoft Sentinel UEBA? (Choose two.)
Medium62You are investigating a security incident in Microsoft Sentinel. The incident involves multiple alerts from different data sources. You need to correlate the alerts to determine the full attack chain. Which Microsoft Sentinel feature should you use?
Medium63A financial services company uses Microsoft Sentinel to detect ransomware activity. They want to correlate alerts from multiple sources to reduce false positives. They have enabled Microsoft Defender for Cloud, Microsoft Defender XDR, and Azure Firewall logs. Which Sentinel feature should they use to create a single alert from multiple signals?
Hard64Your company deploys a new Azure application gateway with WAF policy in prevention mode. After deployment, users report that legitimate traffic is being blocked. You need to identify which WAF rules are causing the blocks without affecting the security posture. What should you do?
Medium65Your company has a hybrid environment with Azure resources and on-premises servers. You have deployed Microsoft Sentinel and connected it to Azure AD, Azure Activity Logs, and Windows Security Events from on-premises servers via the Log Analytics gateway. You need to create a workbook that shows the number of sign-ins from each country over the last 24 hours. The data source is the SigninLogs table. However, the workbook does not display any data. You verify that the Log Analytics workspace is receiving sign-in logs from Azure AD. Which of the following is the most likely reason the workbook shows no data?
Easy66Your organization uses Microsoft Defender for Cloud to monitor Azure SQL databases. You receive an alert indicating a potential SQL injection attack. What is the most effective immediate action to validate and respond?
Medium67You are designing a Microsoft Sentinel solution for a multinational company. The company requires that security incidents be correlated across regions, but data residency mandates require logs to remain in their original region. What should you implement?
Hard68Which THREE of the following are features of Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM)?
Medium69Which THREE are valid ways to trigger a playbook in Microsoft Sentinel? (Choose three.)
Hard70You are investigating a security incident in Microsoft Sentinel. A KQL query returns results indicating that a user logged in from an IP address that is not in the organization's approved list. The user's account has been compromised. You need to automatically disable the user account in Microsoft Entra ID when such an alert is triggered. What should you configure?
Medium71A company uses Microsoft Defender for Cloud to protect its hybrid workloads. Security administrators report that critical alerts for SQL servers are not appearing in the Defender for Cloud dashboard. The SQL servers are on-premises and have Azure Arc enabled. Which configuration step should be verified first?
Medium72You are configuring Microsoft Defender for Cloud to protect your Azure virtual machines. You need to enable just-in-time (JIT) VM access to reduce the attack surface. What prerequisite must be met?
Easy73Which TWO actions can you perform using Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) feature? (Choose two.)
Medium74Your organization has multiple Azure subscriptions and uses Microsoft Defender for Cloud. You need to ensure that all subscriptions have a consistent security policy applied. You create a management group containing all subscriptions. What should you do next to assign a Defender for Cloud initiative to all subscriptions?
Hard75Your company uses Microsoft Sentinel to monitor security events. You need to detect brute-force attacks against Azure VMs that are not yet onboarded to Sentinel. What should you do?
Medium76Your company uses Microsoft Defender for Cloud to protect Azure resources. You notice that some Azure VMs are not showing any security recommendations. You verify that the VMs are running and have network connectivity. What is the most likely cause?
Hard77You are using Microsoft Sentinel to monitor security events. You need to create a custom analytics rule that detects when a user account is added to a privileged group. The rule should run every 5 minutes and generate an incident. Which query language and data source should you use?
Medium78Which THREE are valid methods to ingest data into Microsoft Sentinel? (Select three.)
Hard79Refer to the exhibit. This is an excerpt from an Azure Policy assignment. What is the effect of the 'notScopes' property?
Easy80Which TWO of the following data connectors are available by default in Microsoft Sentinel?
Easy81You need to enable Microsoft Defender for Cloud's workload protection for Azure Kubernetes Service (AKS) clusters. Which Defender plan should you enable?
Easy82Which TWO security controls are automatically provided by enabling Microsoft Defender for Cloud's foundational CSPM (Cloud Security Posture Management) capabilities? (Choose two.)
Easy83You are configuring Microsoft Defender for Cloud for a subscription that contains Azure Kubernetes Service (AKS) clusters. You need to ensure that Defender for Containers provides vulnerability assessment for container images stored in Azure Container Registry (ACR). What should you enable?
Medium84Refer to the exhibit. You are creating a Microsoft Sentinel scheduled analytics rule using the KQL query shown. The rule is set to run every hour. What will this rule detect?
Medium85Which TWO are features of Microsoft Defender for Cloud's workload protection for Azure SQL databases? (Select two.)
Medium86Refer to the exhibit. You are assigning a built-in Azure Policy definition to a subscription using Azure CLI. The policy is 'Audit VMs that do not use managed disks'. After assignment, you check in Microsoft Defender for Cloud and see that the policy is not generating any recommendations. What is the most likely reason?
Easy87Refer to the exhibit. You are reviewing the encryption configuration of an Azure Log Analytics workspace used by Microsoft Sentinel. The configuration shows infrastructure encryption enabled and customer-managed key (CMK) from Azure Key Vault. What additional step must be taken to ensure that the CMK is used for all data?
Medium88Which TWO actions can you perform using Microsoft Defender for Cloud's regulatory compliance dashboard? (Select two.)
Medium89You are configuring Microsoft Defender for Cloud's regulatory compliance dashboard. Your organization must comply with SOC 2. You have enabled the SOC 2 regulatory compliance standard. After a week, some controls show as 'Unhealthy'. What is the most likely reason for the 'Unhealthy' status?
Medium90Your company uses Microsoft Defender for Cloud's 'Vulnerability Assessment' solution for Azure VMs. You have enabled the 'Microsoft Defender for Servers' plan and deployed the integrated Qualys agent. You need to view the vulnerability assessment findings for all VMs in a single dashboard in Microsoft Defender for Cloud. Which blade in the Defender for Cloud portal should you navigate to?
Easy91Which TWO actions should you take to integrate on-premises servers with Microsoft Defender for Cloud for unified security management? (Choose two.)
Medium92You are a security analyst in a company that uses Microsoft Sentinel. You need to create a hunting query that identifies failed sign-in attempts from a specific IP address range and then automatically create an incident if the count exceeds a threshold. Which Microsoft Sentinel feature should you use?
Medium93Your organization uses Microsoft Defender for Cloud. You need to ensure that all Azure subscriptions have the 'Auto-provisioning' extension enabled for Log Analytics agent on new VMs. What should you configure?
Easy94Your organization uses Microsoft Defender for Cloud to protect Azure workloads. You notice that a critical Azure VM is not covered by any of the Defender for Cloud plans. You need to ensure that the VM is protected by the Defender for Servers plan. What should you do?
Medium95You are a security engineer for Contoso Ltd. The company has a hybrid environment with Azure VMs and on-premises servers running Windows Server 2022. You have enabled Microsoft Defender for Cloud's multi-cloud posture management for AWS and GCP. Recently, you deployed Microsoft Sentinel in a Log Analytics workspace named 'ContosoWorkspace'. The security team needs to centralize security alerts from all sources: Azure, on-premises, AWS, and GCP. They also require automated investigation and response for common threats. Specifically, they want to automatically disable a compromised user account when a high-severity alert is generated. You have configured data connectors for Azure Activity, Microsoft Entra ID, and AWS CloudTrail. For on-premises servers, you installed the Azure Monitor Agent (AMA) and enabled Defender for Cloud's plan for servers. For GCP, you are using the GCP Security Command Center connector. The team needs to create a playbook that runs when a high-severity alert from any source is triggered. The playbook should disable the user account in Microsoft Entra ID. You have created a playbook using Azure Logic Apps and granted it the necessary permissions. Which step should you take to ensure the playbook runs automatically when alerts are generated?
Hard96You are a security engineer for a company that uses Microsoft Sentinel. The security operations center (SOC) wants to automatically assign new incidents to the on-call analyst based on the incident's severity and product name. You need to configure this with minimal administrative effort. What should you do?
Medium97Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. The query returns a list of IP addresses that have attempted to sign in more than 10 times in the last day. You notice that the query does not filter out successful sign-ins. You need to modify the query to count only failed sign-in attempts. What should you add?
Medium98Your company uses Microsoft Defender for Cloud to assess the security posture of Azure subscriptions. The security team receives an alert about a critical vulnerability in an Azure VM that was remediated two weeks ago. What is the most likely reason the alert is still active?
Medium99You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). You need to collect sign-in logs and audit logs. Which data connector should you enable?
Medium100Your organization has Microsoft Sentinel deployed in the East US region. You need to ensure that security logs are retained for 2 years to meet compliance requirements. The workspace retention policy is set to 90 days. What should you do?
Hard101Your company has multiple Azure subscriptions. You need to centralize security alerts and incidents in a single dashboard for the security operations center (SOC) team. The solution should provide advanced analytics and threat detection. Which service should you use?
Easy102Which TWO of the following are valid data sources for Microsoft Sentinel's UEBA (User and Entity Behavior Analytics)? (Select two.)
Medium103Your organization wants to use Microsoft Sentinel to detect and respond to threats. You need to ensure that Sentinel can ingest data from Azure Firewall logs. Which three components are required? (Choose three.)
Easy104A company uses Microsoft Sentinel to centralize security logs. They need to ensure that incidents from Microsoft Defender XDR are synchronized into Sentinel. Which data connector should they enable?
Easy105You are configuring Microsoft Defender for Cloud's continuous export feature. You need to export security alerts and recommendations to a Log Analytics workspace for long-term retention and custom analysis. The export should include only high-severity alerts and recommendations. What should you do?
Medium106You need to ensure that all Azure subscriptions in your tenant are automatically assessed for security misconfigurations and compliance against Microsoft cloud security benchmark. What should you configure?
Easy107Your organization wants to use Microsoft Sentinel to automatically respond to high-severity incidents. Which feature should you configure?
Easy108Your company wants to use Microsoft Defender for Cloud's just-in-time (JIT) VM access to reduce the attack surface. You have enabled JIT for a set of VMs. A security administrator reports that they cannot connect via RDP even after requesting access. What is the most likely cause?
Easy109Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to create a custom analytic rule that triggers an incident when a user signs in from an unfamiliar location. Which data source should you use?
Easy110Which TWO of the following are valid methods to ingest data into Microsoft Sentinel? (Select two.)
Medium111Your organization uses Microsoft Sentinel to detect threats across multiple Azure subscriptions. Security analysts need to query threat intelligence data from Microsoft Defender Threat Intelligence (MDTI) directly within Sentinel. However, analysts report that MDTI indicators are not appearing in ThreatIntelligenceIndicator table. What is the most likely cause?
Hard112Your organization uses Microsoft Defender for Cloud to protect Azure SQL databases. You receive a recommendation that 'SQL databases should have vulnerability findings resolved'. You run a vulnerability assessment scan and find a high-severity finding about a missing firewall rule. How should you resolve this finding?
Hard113Your company uses Microsoft Defender for Cloud's regulatory compliance dashboard to track compliance with the PCI DSS standard. You have enabled the PCI DSS initiative on the management group. The dashboard shows that some controls are 'Not started' even though you have implemented the required security configurations. You suspect that the assessment might not be running correctly. You need to ensure that the compliance assessments are triggered for all resources. The environment consists of: - 3 subscriptions under a management group. - All subscriptions have Defender for Cloud enabled with the CSPM plan. - The PCI DSS initiative was assigned at the management group level. - Some resources are in regions that do not support certain policy effects. What is the most likely reason for the 'Not started' status?
Easy114Your organization uses Microsoft Defender for Cloud to protect Azure resources. You need to ensure that storage accounts are only accessible via HTTPS. What should you configure?
Easy115Refer to the exhibit. You are reviewing a policy assignment in Microsoft Defender for Cloud that deploys the Log Analytics agent to Azure VMs. The policy uses 'DeployIfNotExists' effect and specifies a workspace. However, newly created VMs are not showing the agent installed. What is the most likely cause?
Hard116Your organization runs a critical application on an Azure VM that generates sensitive data. You need to ensure that only approved applications can execute on the VM to prevent malware. You have Microsoft Defender for Cloud enabled with the Defender for Servers plan P2. Which feature provides application control without requiring custom rules?
Hard117You manage a Microsoft Sentinel workspace. Your security operations team wants to automatically notify the on-call analyst via Microsoft Teams whenever a new high-severity incident is created, and also create a corresponding ticket in ServiceNow. The team does not want to write code. Which Microsoft Sentinel feature should you use to accomplish this?
Medium118Your organization uses Microsoft Defender for Cloud to monitor Azure resources. You need to ensure that security recommendations are automatically remediated for non-compliant resources. Which TWO options can you use to achieve this?
Medium119Your security team uses Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) to detect insider threats. To enable UEBA, which data source must be connected to Sentinel?
EasyOther domains
All AZ-500 exam domains
Frequently asked questions
- What does the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain cover on the AZ-500 exam?
- You must configure Defender for Cloud plans and Sentinel data connectors, then build analytics rules and Logic Apps playbooks for automated response. The key is knowing which capability belongs to free foundational CSPM versus paid Defender plans, and how playbooks differ from automation rules.
- How many questions are in this domain?
- This page lists all 119 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel questions in the AZ-500 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.