Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are a security engineer for a subscription protected by Microsoft Defender for Cloud. The alert "Brute force attack against an Azure virtual machine" is triggered several times a day against test VMs. The traffic originates from your organization's approved penetration-testing IP range and should no longer raise alerts, but you must still detect the same attack from other sources. What should you do?
Disable the related recommendation in the subscription's Security policy.
Create an alert suppression rule in Microsoft Defender for Cloud that targets the alert type and specifies the penetration-testing IP range.
Mark the affected virtual machines as exempt items in Secure Score.
Configure an Azure Monitor alert rule with a filter that excludes the penetration-testing IP addresses.
Microsoft Defender for Cloud lets you create alert suppression rules that automatically dismiss specific alert types when they match defined conditions, such as particular source IP addresses. By creating a suppression rule scoped to the "Brute force attack against an Azure virtual machine" alert and listing the penetration-testing IP range as the matching entity, the alert will be silently dismissed only for that traffic. Disabling recommendations, excluding the VMs from secure score, or crafting separate Azure Monitor alert rules do not prevent Defender for Cloud from producing the original security alert for other sources.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are alert suppression rules in Microsoft Defender for Cloud?
Open an interactive chat with Bash
How do suppression rules affect the detection of other sources of the same alert?
Open an interactive chat with Bash
Can alert suppression rules help improve Secure Score in Microsoft Defender for Cloud?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .