Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You need to ensure that security alerts from Microsoft Defender for Cloud are sent to a central SIEM system. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse 'diagnostic settings' (which export logs and metrics) with 'continuous export' (which specifically exports security alerts and recommendations), leading them to incorrectly select Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable continuous export to Event Hubs

Microsoft Defender for Cloud can stream security alerts and recommendations to an Event Hubs namespace via the 'Continuous export' settings. This enables external SIEM systems, such as Splunk or Azure Sentinel, to ingest the data by connecting to the Event Hubs endpoint. Diagnostic settings export activity logs and metrics, not security alerts, and playbooks are for automated response, not data forwarding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a playbook that forwards alerts to the SIEM

    Why it's wrong here

    Playbooks in Microsoft Defender for Cloud are Azure Logic Apps workflows that execute in response to an alert, typically to run remediation or investigation actions. They are fundamentally event-driven and designed for per-alert response, not for guaranteeing continuous, reliable, high-volume telemetry export. Forwarding alerts to a SIEM via a playbook would require an alert to trigger a Logic App each time, introducing latency and a single point of failure, and any missed trigger would silently drop an alert. This approach cannot serve as a systematic export pipeline because it lacks buffering, retries, and streaming throughput.

  • ✗

    Configure diagnostic settings for the subscription

    Why it's wrong here

    Diagnostic settings are an Azure Monitor feature that exports resource diagnostic logs and the Azure Activity Log to destinations like Log Analytics, Storage, or Event Hubs. They are designed for telemetry generated by Azure resources (e.g., VM logs, NSG flow logs, control-plane operations), not for security findings produced by Microsoft Defender for Cloud. While the Activity Log includes some subscription-level security administrative events, it does not include Defender for Cloud's security alerts, which are dynamic detection results tied to threats and vulnerabilities. Enabling diagnostic settings on the subscription therefore fails to capture security alerts and is not the intended export mechanism.

  • ✗

    Assign an Azure Policy to export alerts

    Why it's wrong here

    Azure Policy is a governance service that enforces rules on resource configurations and audits compliance, using effects like Deny, Append, or DeployIfNotExists. It does not have any data-movement or export capabilities—policies can only evaluate and remediate resource settings, not stream runtime security findings. Even if a policy were assigned to 'deploy continuous export' on all subscriptions, the policy itself is not performing the alert export; it would merely be automating the configuration of the actual export service. Assigning Azure Policy alone produces no alert data flowing to a SIEM, so this option is fundamentally incorrect.

  • ✓

    Enable continuous export to Event Hubs

    Why this is correct

    Continuous export is a native Microsoft Defender for Cloud feature that streams security alerts and recommendations to an Event Hubs namespace or a Log Analytics workspace in near real time. This is the officially supported integration path for sending security alerts to an external SIEM, because Event Hubs serves as a high-throughput, durable ingestion endpoint that downstream tools like Splunk or QRadar can consume. You enable it per subscription or configure it centrally with Azure Policy, and it guarantees ongoing delivery without per-alert manual action. This satisfies the requirement of ensuring security alerts reach the SIEM continuously.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.