Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are configuring Microsoft Defender for Cloud's continuous export feature. You need to export security alerts and recommendations to a Log Analytics workspace for long-term retention and custom analysis. The export should include only high-severity alerts and recommendations. What should you do?

⚠ Common exam trap

Test-takers frequently confuse the continuous export feature with diagnostic settings or assume that a SIEM like Sentinel is required for custom analysis, when in fact Defender for Cloud's built-in export can directly filter and send data to a Log Analytics workspace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable continuous export in Defender for Cloud and select high-severity alerts and recommendations.

Microsoft Defender for Cloud's continuous export feature allows you to directly export security alerts and recommendations to a Log Analytics workspace with granular filtering by severity. This meets the requirement for long-term retention and custom analysis without additional services. Selecting 'high-severity' in the export configuration ensures only the specified alerts and recommendations are exported.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up Microsoft Sentinel to ingest Defender for Cloud alerts and then export to the workspace.

    Why it's wrong here

    This path inserts Microsoft Sentinel as an intermediary, which is an unnecessary extra layer. Continuous export already sends Defender for Cloud alerts and recommendations directly to a Log Analytics workspace, while Sentinel ingestion would require additional connectors and potentially duplicate or delay data. Sentinel is a SIEM for analyzing the workspace, not the destination for the export itself.

  • ✓

    Enable continuous export in Defender for Cloud and select high-severity alerts and recommendations.

    Why this is correct

    Enabling continuous export in Defender for Cloud is the native, centralized method to stream security data to a Log Analytics workspace. You can filter to high-severity alerts and recommendations at the subscription or management-group level, ensuring only actionable events are stored. This is the intended configuration for satisfying the requirement directly.

  • ✗

    Configure diagnostic settings on each Azure resource to send logs to the workspace.

    Why it's wrong here

    Resource diagnostic settings capture platform logs and metrics from individual Azure resources, such as Activity Logs or VM performance counters, but they do not include Defender for Cloud's security alerts or recommendations. There is no severity filter for Defender data, and the approach is fragmented because you must configure every resource separately. Central security events are generated by Defender plans, not by each resource's diagnostic pipeline.

  • ✗

    Use Azure Event Hubs to stream security alerts to the workspace.

    Why it's wrong here

    Event Hubs is a continuous-export destination for streaming data to external consumers, not a service that forwards data into a Log Analytics workspace. To get data from Event Hubs to the workspace, you would need an additional processing pipeline such as an Azure Function or Stream Analytics job. This adds latency and operational overhead, whereas the requirement is to get alerts into Log Analytics directly.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.