Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are hardening the security observability of an Azure Container Apps (ACA) environment that hosts several mission-critical workloads. The security operations team must receive ACA runtime audit events in Microsoft Sentinel so that custom analytics rules can trigger alerts. Which action meets this requirement without deploying additional agents to the app instances?
Create an Azure Monitor diagnostic setting on the Container Apps environment that sends the ContainerAppSystemLogs and ContainerAppConsoleLogs categories to a Log Analytics workspace connected to Microsoft Sentinel.
Install the Azure Monitor VM extension on every Container Apps worker node and configure it to forward security events to Microsoft Sentinel.
Enable Microsoft Defender for Cloud's Defender for Containers plan for the subscription and rely on its agentless scanning to send audit events to Microsoft Sentinel.
Configure the ACA environment to export application logs to an Azure Storage account and enable Sentinel's Storage Data Connector.
Azure Container Apps exposes its runtime and control-plane activity through Azure Monitor diagnostic settings. By configuring a diagnostic setting on the Container Apps environment and selecting the ContainerAppSystemLogs and ContainerAppConsoleLogs categories, you can stream those events directly to a Log Analytics workspace that is already connected to Microsoft Sentinel. Because ACA integrates natively with Azure Monitor, no extra agents or sidecars need to be installed on the container app instances. Forwarding logs to Storage, Event Hubs, or relying on the App Service extension would not deliver the events to Sentinel for analytics without further components.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Azure Monitor diagnostic settings?
Open an interactive chat with Bash
How does Microsoft Sentinel integrate with Azure Monitor?
Open an interactive chat with Bash
What is the difference between ContainerAppSystemLogs and ContainerAppConsoleLogs?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .