AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You need to configure a continuous export of Microsoft Defender for Cloud alerts to a third-party SIEM. Which feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse the Azure Monitor agent (which collects VM logs) with the continuous export feature (which streams Defender for Cloud alerts), leading them to select Option C despite it being unrelated to alert export.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the continuous export feature in Defender for Cloud to stream alerts to an Event Hubs namespace.
The continuous export feature in Microsoft Defender for Cloud is specifically designed to stream security alerts and recommendations to an Event Hubs namespace, which can then be consumed by a third-party SIEM. This native integration eliminates the need for custom polling or scripting, ensuring near real-time data flow with minimal latency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an Azure Logic App to periodically query and send alerts.
Why it's wrong here
A Logic App that periodically calls Defender for Cloud to retrieve alerts is a custom pull-based workaround, not the platform's native continuous export. Because it relies on polling, alerts are not streamed in real time and can be missed or delayed between intervals. You would also need to manually handle authentication, pagination, and retry logic, making it unnecessary overhead compared to the built-in export feature.
- ✗
Use the Defender for Cloud REST API to pull alerts.
Why it's wrong here
Calling the Defender for Cloud REST API to pull alerts requires building a separate application that authenticates, pages through results, and repeatedly queries the endpoint. This is a pull model with no push semantics, so it does not provide a continuous export pipeline and depends entirely on your polling cadence. Even if you automate it, you'd face API throttling, token management, and maintenance burden, whereas continuous export pushes alerts directly without custom code.
- ✗
Configure Azure Monitor agent on all VMs.
Why it's wrong here
The Azure Monitor agent is a data collection agent that runs on VMs and gathers OS-level performance counters, Windows/Linux event logs, and custom text logs into a Log Analytics workspace. It does not capture or forward Microsoft Defender for Cloud security alerts, because those alerts are generated by the Defender platform based on cloud and workload analytics, not by the guest OS agent. Therefore, installing the agent on VMs alone will not satisfy a continuous alert export requirement.
- ✓
Use the continuous export feature in Defender for Cloud to stream alerts to an Event Hubs namespace.
Why this is correct
The continuous export feature in Microsoft Defender for Cloud natively streams security alerts and recommendations to an Azure Event Hubs namespace, allowing near real-time integration with an external SIEM or log management tool. You configure it under Environment settings for a subscription or a management group, and it supports filtering for specific alert severities or recommendations. Because this is built in, it handles batching, schema, and transport without custom code, making it the correct method for continuous alert export.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to ensure that security alerts from Microsoft Defender for Cloud are sent to a central SIEM system. What should you configure?
easy- A.Create a playbook that forwards alerts to the SIEM
- B.Configure diagnostic settings for the subscription
- C.Assign an Azure Policy to export alerts
- ✓ D.Enable continuous export to Event Hubs
Why D: Microsoft Defender for Cloud can stream security alerts and recommendations to an Event Hubs namespace via the 'Continuous export' settings. This enables external SIEM systems, such as Splunk or Azure Sentinel, to ingest the data by connecting to the Event Hubs endpoint. Diagnostic settings export activity logs and metrics, not security alerts, and playbooks are for automated response, not data forwarding.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.