Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You deployed Microsoft Sentinel to several Azure subscriptions. For one workspace, you must enable the built-in analytics rule template named "Uncommon processes on a Windows host" so that it immediately starts generating incidents. You decide to automate the task by deploying an Azure Resource Manager (ARM) template instead of using the portal. Which ARM resource type must the template deploy to configure and enable the analytics rule?
In Microsoft Sentinel, every analytics rule-whether created from scratch or generated from a built-in template-is represented in Azure Resource Manager as a resource of type Microsoft.SecurityInsights/alertRules. Deploying this resource type with the required properties (such as query, scheduling, tactics, severity, and Enabled set to true) creates or updates the rule and allows it to begin generating incidents.
Microsoft.OperationalInsights/savedSearches defines Kusto queries only and does not create incidents. Microsoft.Insights/scheduledQueryRules is used by Azure Monitor alerting, not by Microsoft Sentinel. Microsoft.SecurityInsights/automationRules represents playbook-like response logic applied after incidents are created and cannot stand in for analytics rules themselves.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the role of Microsoft.SecurityInsights/alertRules in Microsoft Sentinel?
Open an interactive chat with Bash
How is Microsoft.OperationalInsights/savedSearches different from Microsoft.SecurityInsights/alertRules?
Open an interactive chat with Bash
What purpose does Microsoft.SecurityInsights/automationRules serve in contrast to Microsoft.SecurityInsights/alertRules?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .