Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are configuring Microsoft Defender for Cloud to automatically respond to medium and high-severity alerts raised in a Log Analytics workspace that is connected to a Microsoft Sentinel instance. All responses must run without human intervention and should be reusable across multiple subscriptions. Which action should you take first to meet these requirements?
Create a Logic App-based automation workflow from the Microsoft Defender for Cloud Automation page.
Assign an Azure Policy initiative that deploys remediation tasks upon alert creation.
Create an analytics rule in Microsoft Sentinel that runs a playbook when an alert is generated.
Define an action group in Azure Monitor and attach it to the subscriptions.
To trigger fully automated, reusable responses to Defender for Cloud alerts, you must create a logic app as an automation workflow in the Microsoft Defender for Cloud portal. Automation workflows let you define a set of conditions (for example, alert severity) and the Logic App to run when those conditions are met. Once a workflow exists, you can assign it to any subscription or management group. Creating alert rules in Microsoft Sentinel or action groups in Azure Monitor would collect or notify but would not satisfy the need for a Defender for Cloud-native, subscription-scoped automation. Azure Policy controls configuration compliance and does not execute response actions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Logic App-based automation workflow?
Open an interactive chat with Bash
How does Microsoft Defender for Cloud automation differ from Azure Monitor action groups?
Open an interactive chat with Bash
Why can't an Azure Policy initiative handle alert-driven responses?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .