Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You create an Azure Logic App that opens an incident in ServiceNow. You must ensure that the Logic App runs automatically whenever Microsoft Defender for Cloud generates a new security recommendation whose severity is High in any Azure subscription. Which Defender for Cloud configuration should you create to meet the requirement?
A workflow automation scoped to all subscriptions with the event type set to Recommendation and the severity filter set to High.
A continuous export rule that sends recommendation data to an Event Hub consumed by the Logic App.
A custom alert rule in Defender for Cloud that calls a webhook when an alert with High severity is generated.
An Azure Policy initiative that audits High-severity security settings and triggers a remediation task.
Microsoft Defender for Cloud can trigger Azure Logic Apps through its workflow automation feature. When you create a workflow automation, you choose the event type (Security alert, Recommendation, or Regulatory compliance), optionally filter on attributes such as severity, select the management-group, subscription, or resource-group scope, and then associate an existing Logic App. Creating a workflow automation with the event type set to Recommendation and the severity filter set to High ensures the Logic App is invoked only for new High-severity recommendations. Custom alert rules and continuous export cannot directly invoke a Logic App, and Azure Policy initiatives do not trigger Logic Apps on recommendation creation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Logic Apps?
Open an interactive chat with Bash
What is workflow automation in Microsoft Defender for Cloud?
Open an interactive chat with Bash
What is the difference between an event type and severity in Microsoft Defender for Cloud?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .