AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are a security engineer for a company that uses Microsoft Defender for Cloud. The security team wants to automatically trigger a Logic App playbook when a high-severity alert is generated for an Azure Storage account. The playbook must run without manual intervention. What should you configure?
⚠ Common exam trap
The trap here is assuming that Azure Monitor action groups can directly trigger playbooks for Defender for Cloud alerts, when automation rules are the correct feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule in Microsoft Defender for Cloud that triggers the playbook on alerts with severity High and resource type Storage accounts.
Automation rules in Microsoft Defender for Cloud are the native way to automatically respond to security alerts. They can filter by alert severity, resource type, and other properties, and then trigger a Logic App playbook. This provides a no-code, scalable solution that meets the requirement for automatic execution without manual intervention. Other options either require custom code or apply to the wrong resource type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an automation rule in Microsoft Defender for Cloud that triggers the playbook on alerts with severity High and resource type Storage accounts.
Why this is correct
Automation rules in Microsoft Defender for Cloud can trigger Logic Apps based on alert severity, resource type, and other conditions. This directly satisfies the requirement for automatic, no-touch execution. The rule evaluates new alerts and invokes the playbook, which can then perform remediation steps such as isolating the storage account or notifying the SOC.
- ✗
Configure a diagnostic setting to stream alerts to an event hub and use Azure Functions to invoke the playbook.
Why it's wrong here
Diagnostic settings can export alerts to an event hub, but this requires custom code in Azure Functions to parse and trigger the playbook. It adds unnecessary complexity and latency, and does not provide a native, low-code automation path. Defender for Cloud automation rules are the built-in mechanism for this scenario.
- ✗
Enable just-in-time (JIT) VM access on the storage account and attach the playbook to the JIT policy.
Why it's wrong here
JIT VM access applies only to virtual machines, not storage accounts. It controls inbound network access to VMs by opening ports on demand. Storage accounts do not have JIT VM access policies, so this approach is technically invalid and does not address alert-triggered automation.
- ✗
Create an Azure Monitor action group that triggers the playbook when an alert is fired, and assign the action group to the storage account.
Why it's wrong here
Azure Monitor action groups can trigger Logic Apps, but they are designed for metric and log alerts, not for Defender for Cloud security alerts. Defender for Cloud alerts are not Azure Monitor alerts by default. Using action groups would require custom alert rules and would not natively cover all Defender for Cloud alerts for the storage account.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.