Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are investigating a security incident in Microsoft Sentinel. A KQL query returns results indicating that a user logged in from an IP address that is not in the organization's approved list. The user's account has been compromised. You need to automatically disable the user account in Microsoft Entra ID when such an alert is triggered. What should you configure?

⚠ Common exam trap

The trap here is that candidates might confuse Microsoft Defender for Cloud's workload protection capabilities with identity-based remediation, or think that Azure Policy can manage Entra ID objects, when in fact only a Logic Apps-based playbook provides the necessary automation and API access to disable a user account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a playbook in Microsoft Sentinel with a Logic Apps connector to Microsoft Entra ID.

Microsoft Sentinel can use playbooks, which are automated workflows built on Azure Logic Apps, to respond to security alerts. By creating a playbook triggered by a Sentinel alert, you can use the Microsoft Entra ID connector to automatically disable a compromised user account, providing a direct and integrated remediation action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an Azure Policy that disables the user account.

    Why it's wrong here

    Azure Policy is an Azure resource governance service that evaluates compliance of Azure resource configurations and enforces rules via Deny or DeployIfNotExists effects, but it does not operate on Microsoft Entra ID directory objects. Disabling a user requires updating the user's account state in the identity directory, not modifying a resource property, so a policy assignment cannot perform that action. Thus, while Azure Policy is useful for resource compliance, it is the wrong tool for this identity remediation.

  • ✗

    Use Microsoft Defender for Cloud to automatically disable the account.

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud security posture management and workload protection platform that assesses Azure, AWS, and GCP resources, and it does not include native functions to change Microsoft Entra ID user states. Although Defender for Cloud can surface identity-related recommendations from Microsoft Defender for Identity, the platform's workflows are focused on remediating resource misconfigurations, not on executing directory object mutations like account disabling. Therefore, it cannot directly automate the disabling of a compromised Entra ID account from a Sentinel alert.

  • ✗

    Create a Power Automate flow triggered by the Sentinel alert.

    Why it's wrong here

    Power Automate could create a flow with a Sentinel connector, but Sentinel's native automation framework uses automation rules and playbooks built on Azure Logic Apps, not Power Automate. To connect Power Automate to Sentinel alerts, you would need a custom trigger or third-party connector, and it would not have the same built-in incident context, permissions model, and approval capabilities as a Logic Apps-based playbook. Consequently, it is not the recommended or directly integrated mechanism for executing an automated identity response.

  • ✓

    Create a playbook in Microsoft Sentinel with a Logic Apps connector to Microsoft Entra ID.

    Why this is correct

    A Sentinel playbook is an Azure Logic Apps workflow that is designed explicitly to run automated responses in conjunction with Sentinel incidents and alerts. When you create a playbook, you can add a Microsoft Entra ID connector that uses the Microsoft Graph API to perform actions such as disabling a user or updating the accountEnabled property of the target identity. The playbook can be attached to an automation rule that fires on an incident, making it the correct, supported way to automatically disable a compromised account.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.