Courseiva

AZ-500 · topic practice

Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel practice questions

This AZ-500 domain covers Microsoft Defender for Cloud (CSPM, workload protections, secure score, regulatory compliance) and Microsoft Sentinel (data connectors, analytics rules, automation playbooks, workbooks). Questions test configuring continuous export, enabling Defender plans per resource type, connecting hybrid log sources, and building automated response with Logic Apps playbooks.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

What the exam tests

What to know about Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You must configure Defender for Cloud plans and Sentinel data connectors, then build analytics rules and Logic Apps playbooks for automated response. The key is knowing which capability belongs to free foundational CSPM versus paid Defender plans, and how playbooks differ from automation rules.

Enabling Defender for Cloud plans per resource type and interpreting Secure Score recommendations

Configuring foundational CSPM versus Defender CSPM capabilities and continuous export to Log Analytics

Connecting data sources to Microsoft Sentinel using Azure Activity, Azure AD, and Windows Security Events connectors

Building Sentinel automation rules and Logic Apps playbooks triggered by Microsoft Defender XDR incidents

Watch out for

Common Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel exam traps

  • ▸Assuming foundational CSPM includes attack path analysis or agentless scanning; those require the paid Defender CSPM plan.
  • ▸Confusing Sentinel automation rules with playbooks: rules orchestrate, playbooks perform the actual remediation actions via Logic Apps.
  • ▸Forgetting that Defender for Servers requires the Log Analytics agent or Azure Monitor Agent plus a workspace for full data.

Practice set

Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel questions

20 questions · select your answer, then reveal the explanation

An organization uses Microsoft Defender for Cloud to protect Azure virtual machines. They notice that several VMs are not receiving vulnerability assessment findings, even though they are in a scope where the integrated Qualys VA solution is enabled. What should they verify first?

A security analyst needs to create a custom alert in Microsoft Defender for Cloud that triggers when a user creates a public IP address in the 'production' resource group. Which type of alert should they use?

An organization uses Microsoft Defender for Cloud to protect Azure SQL databases. They want to receive alerts when a SQL database is accessed from a suspicious location. What should they enable?

Your company uses Microsoft Sentinel to correlate data from multiple sources. You need to create an analytics rule that triggers an incident when a user signs in from an unfamiliar location and then performs a high-risk action in Azure. What is the best approach?

A security analyst needs to view all incidents generated by Microsoft Defender for Cloud across multiple subscriptions in a single pane of glass. What should they use?

You need to ensure that Microsoft Sentinel can detect threats across your Azure environment, including virtual machines, network traffic, and user activities. Which TWO data sources should you connect?

A company uses Microsoft Defender for Cloud's workload protection for Azure Storage. They want to receive alerts when there is suspicious access to blob storage. Which TWO features should they enable?

You are deploying Microsoft Sentinel in a new Azure environment. Which THREE resources are required to deploy a Sentinel workspace?

Refer to the exhibit. You are assigning this Azure Policy to a management group. The goal is to automatically deploy the Azure Monitor Agent to Windows VMs that do not have it. However, after assignment, you notice that the policy is not deploying the agent. What is the most likely reason?

Exhibit

{
  "properties": {
    "displayName": "Deploy Azure Monitor Agent for Windows VMs",
    "policyType": "BuiltIn",
    "mode": "Indexed",
    "parameters": {
      "effect": {
        "type": "String",
        "defaultValue": "DeployIfNotExists",
        "allowedValues": [
          "DeployIfNotExists",
          "AuditIfNotExists",
          "Disabled"
        ]
      }
    },
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Compute/virtualMachines"
      },
      "then": {
        "effect": "[parameters('effect')]"
      }
    }
  }
}

A security analyst reports that Microsoft Sentinel is not receiving Windows Security Events from Azure VMs that have the Log Analytics agent installed. The agent shows as connected, and other data sources (e.g., performance counters) are flowing. What is the most likely cause?

Your organization uses Microsoft Defender for Cloud to assess regulatory compliance. You need to ensure that the compliance dashboard reflects the latest standards and that custom assessments are included. What should you do?

You are reviewing the Azure Policy definition shown in the exhibit. This policy is assigned to a subscription. Several VMs are non-compliant. What is the most likely reason for the non-compliance?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Compute/virtualMachines"
          },
          {
            "field": "Microsoft.Compute/virtualMachines/storageProfile.osDisk.encryptionSettings",
            "exists": "false"
          }
        ]
      },
      "then": {
        "effect": "AuditIfNotExists",
        "details": {
          "type": "Microsoft.Compute/virtualMachines/extensions",
          "existenceCondition": {
            "field": "Microsoft.Compute/virtualMachines/extensions/type",
            "equals": "AzureDiskEncryption"
          }
        }
      }
    }
  }
}
```

You are designing a Microsoft Sentinel deployment for a multinational company. The company requires that all security logs be retained for at least seven years for compliance. The solution must be cost-effective. Which THREE actions should you take?

Your company uses Microsoft Defender for Cloud to protect Azure resources. You need to enable the enhanced security features (formerly Azure Defender) for all supported resource types. Which TWO plans should you enable? (Choose TWO that apply.)

You execute the KQL query shown in the exhibit in Microsoft Sentinel. The query returns no results, but you know there have been high-severity malware alerts in the past week. What is the most likely issue?

Exhibit

Refer to the exhibit.

```kusto
SecurityAlert
| where TimeGenerated > ago(7d)
| where AlertSeverity == "High"
| where AlertName contains "Malware"
| summarize Count = count() by AlertName, CompromisedEntity
| order by Count desc
```

You deploy the Bicep template shown in the exhibit. After deployment, you check Microsoft Sentinel and find it is not enabled. The Log Analytics workspace and Defender for Cloud pricing plan are created successfully. What is the most likely reason Sentinel is not enabled?

Exhibit

Refer to the exhibit.

```bicep
resource defenderPlan 'Microsoft.Security/pricings@2022-03-01' = {
  name: 'VirtualMachines'
  properties: {
    pricingTier: 'Standard'
    subPlan: 'P1'
  }
}

resource workspace 'Microsoft.OperationalInsights/workspaces@2021-06-01' = {
  name: 'la-workspace'
  location: resourceGroup().location
  properties: {
    sku: {
      name: 'PerGB2018'
    }
    retentionInDays: 90
  }
}

resource sentinel 'Microsoft.SecurityInsights/onboardingStates@2021-10-01' = {
  name: 'default'
  properties: {
    onboardingState: 'Onboarded'
  }
}
```

A security engineer configures a Microsoft Sentinel analytics rule to detect anomalous sign-ins from unfamiliar locations. The rule uses the following KQL query: SigninLogs | where RiskLevelDuringSignIn == 'medium' or RiskLevelDuringSignIn == 'high' | summarize count() by UserPrincipalName, IPAddress, bin(TimeGenerated, 1h). After enabling the rule, no alerts are generated even though the team expects many. What is the most likely cause?

You need to ensure that all Azure storage accounts in your subscription are encrypted at rest using customer-managed keys (CMK). Which Azure Policy initiative should you assign to audit compliance?

Your organization uses Microsoft Sentinel to monitor for ransomware attacks. You need to create a custom analytics rule that detects when a large number of files are encrypted within a short time window. Which KQL query should you use as the rule logic?

A security administrator needs to enable just-in-time (JIT) VM access for all Azure VMs in a subscription using Microsoft Defender for Cloud. What are the minimum permissions required to enable JIT on the VMs?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel sessions

Start a Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel only practice session

Every question in these sessions is drawn from the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain — nothing else.

Related practice questions

Related AZ-500 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-500 exam test about Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel?
You must configure Defender for Cloud plans and Sentinel data connectors, then build analytics rules and Logic Apps playbooks for automated response. The key is knowing which capability belongs to free foundational CSPM versus paid Defender plans, and how playbooks differ from automation rules.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel questions in a focused session?
Yes — the session launcher on this page draws every question from the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-500 topics?
Use the topic links above to move to related areas, or go back to the AZ-500 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-500 exam covers. They are not copied from any real exam or dump site.