AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are configuring Microsoft Defender for Cloud for an Azure subscription. You want to receive email notifications when a high-severity alert is generated. What should you configure?
⚠ Common exam trap
The trap here is overcomplicating the solution by involving other services when Defender for Cloud has a native email notification setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Email notifications settings in Microsoft Defender for Cloud.
Microsoft Defender for Cloud includes a built-in email notification feature that allows you to specify recipients and severity levels for alerts. This is the simplest and most direct method to receive email notifications for high-severity alerts. It does not require additional services like Azure Monitor, Microsoft Sentinel, or Log Analytics, and it is designed specifically for this purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Monitor action groups with an email action.
Why it's wrong here
Azure Monitor action groups are used for alerting on metrics and logs, but Microsoft Defender for Cloud has its own email notification settings. While you could create an alert rule that forwards Defender alerts to an action group, it is not the direct method for Defender for Cloud email notifications. The native email notification setting is simpler and intended for this purpose.
- ✓
The Email notifications settings in Microsoft Defender for Cloud.
Why this is correct
Microsoft Defender for Cloud provides a dedicated email notifications configuration where you can specify email addresses and choose which severity levels trigger notifications. This is the direct and intended way to receive email alerts for high-severity findings. It also allows notifying subscription owners and security contacts. This meets the requirement without additional services.
- ✗
A Microsoft Sentinel analytics rule with an email playbook.
Why it's wrong here
Microsoft Sentinel is a SIEM and can send emails via playbooks, but it is not required for Defender for Cloud email notifications. Using Sentinel would add complexity and cost, and it is not the native method. Defender for Cloud already includes email notification capabilities, so introducing Sentinel is unnecessary for this scenario.
- ✗
A Log Analytics workspace with a scheduled query alert.
Why it's wrong here
Log Analytics scheduled query alerts can be configured to send emails, but this requires writing queries and managing alerts manually. Defender for Cloud already surfaces alerts and has built-in email notifications. Using Log Analytics is an indirect and more complex approach that does not leverage the native integration.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.