AZ-500 exam dumps

AZ-500 practice question 253 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 253

Single answer

Your organization uses Microsoft Sentinel to monitor security events. The security team notices repeated malicious sign-in attempts from specific IP addresses flagged by an Azure AD sign-in analytics rule. You want to automatically block these suspicious IPs in Azure Firewall as soon as the Sentinel alert is triggered, with minimal manual intervention. Which solution should you implement?

  1. A

    Create a Microsoft Sentinel analytics rule that triggers a Logic App playbook to update Azure Firewall’s deny list as soon as an alert is raised.

  2. B

    Add a custom workbook in Microsoft Sentinel to visualize malicious IP activity and manually invoke a runbook to update the firewall.

  3. C

    Enable Azure Defender for Storage and configure it to block all suspicious IP addresses from Azure AD sign-in attempts.

  4. D

    Use Azure Monitor to create an alert on Azure AD logs that sends an email notification to the security team for manual firewall updates.

Show answer and explanation

Correct answer: A

Explanation

Microsoft Sentinel analytics rules can invoke Logic Apps (playbooks) that perform automated actions, such as updating Azure Firewall to block malicious IPs. This is in line with best practices for security orchestration, automation, and response (SOAR). For more details, refer to the Microsoft Sentinel documentation on creating analytics rules and playbooks: https://docs.microsoft.com/azure/sentinel/overview

  • A. Correct.

    Correct. Configuring a Sentinel analytics rule to trigger a Logic App (playbook) automates firewall updates whenever an alert is generated. This approach requires minimal manual intervention and is a common best practice for automated threat response.

  • B. Incorrect.

    Incorrect. A custom workbook in Microsoft Sentinel primarily provides visualization and dashboarding capabilities. It does not automatically trigger actions to update the firewall without additional configurations, making it unsuitable for immediate automated blocking.

  • C. Incorrect.

    Incorrect. Azure Defender for Storage specifically focuses on storage-related alerts and protections. It does not automatically block IP addresses from Azure AD sign-in attempts; the scope of protection differs from what you need for Azure Firewall.

  • D. Incorrect.

    Incorrect. Using Azure Monitor to send email notifications still requires manual action to update the firewall. This does not fulfill the requirement for minimal manual intervention or automated blocking in Sentinel.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam