Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your security operations center (SOC) uses Microsoft Sentinel. You need to ensure that an incident is automatically created when a specific type of alert fires from Microsoft Defender for Cloud. What is the most efficient way to configure this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Microsoft Defender for Cloud data connector in Sentinel and enable incident creation.

Option B is correct because the Microsoft Defender for Cloud data connector in Microsoft Sentinel includes an option to automatically create incidents from Defender for Cloud alerts, which is the native and most efficient integration for this scenario. Once the connector is configured and incident creation is enabled, alerts from Defender for Cloud flow into Sentinel and generate incidents without custom automation. Option A is unnecessary because a playbook and API calls add complexity when the connector already supports automatic incident creation. Option C is incorrect because workbooks are only for visualization and do not create incidents, and manual creation is not automatic. Option D is also incorrect because scheduled analytics rules query log data on a schedule and are not the intended mechanism for ingesting Defender for Cloud alerts as incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a playbook that triggers on alert and generates an incident via API.

    Why it's wrong here

    A playbook triggered on an alert and generating an incident via API introduces unnecessary latency and complexity, because Microsoft Sentinel already provides a native, out-of-the-box analytics rule that automatically creates an incident when a Defender for Cloud alert fires, without requiring custom code or API calls. This option is tempting because playbooks are the correct mechanism for orchestrating automated response actions—such as isolating a compromised VM or sending a notification—after an incident exists, but they are not the most efficient method for the initial incident creation itself.

  • ✓

    Configure the Microsoft Defender for Cloud data connector in Sentinel and enable incident creation.

    Why this is correct

    The Microsoft Defender for Cloud data connector in Microsoft Sentinel is the native integration that ingests security alerts from Defender for Cloud plans into your workspace, and enabling incident creation on that connector activates the built-in analytics rule that automatically generates a Sentinel incident for each incoming alert. This is the intended, supportable path because it requires no custom code or manual effort, and it ensures that Defender for Cloud detection signals flow directly into your SOC incident queue for triage and investigation.

  • ✗

    Design a workbook to monitor alerts and manually create incidents.

    Why it's wrong here

    Workbooks are interactive visualization canvases built on Azure Log Analytics queries, designed to present metrics and trends to analysts, but they have no native action to create or modify incidents. Relying on a workbook for manual incident creation would require a human to continuously watch the dashboard and then use the portal UI or an API call to generate incidents, which introduces latency, human error, and a completely unsupported workflow that bypasses Sentinel's automated detection and event correlation.

  • ✗

    Write a scheduled analytics rule that queries Defender for Cloud logs.

    Why it's wrong here

    Scheduled analytics rules are intended to run your own KQL queries at a specified interval against log tables in the Log Analytics workspace, such as SigninLogs or CommonSecurityLog, and then raise alerts based on threshold or pattern matching. Defender for Cloud alerts are already ingested as security alerts via the data connector, not as a dedicated log source that needs a scheduled query; writing a scheduled rule to query SecurityAlert would duplicate the connector's built-in incident creation, risk missing connector-specific enrichment, and require custom alert-to-incident mapping that the native pipeline already provides.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.