AZ-500 exam dumps

AZ-500 practice question 254 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 254

Select 2

You are a security engineer for a company that uses Microsoft Sentinel to monitor critical sign-in activities in Azure Active Directory. You need to automate the response when any 'High' severity alert is raised, so that an email is sent to the security team and the suspicious account is automatically disabled. Which two steps should you implement to ensure that Microsoft Sentinel triggers this automated response appropriately?

  1. A

    Create a new Logic App in the same subscription and add the 'Microsoft Sentinel Incident' trigger to initiate the workflow.

  2. B

    Associate the Logic App with the Microsoft Sentinel analytics rule that generates the 'High' severity alert.

  3. C

    Enable the default ‘Security Alerts’ connector in Azure Logic Apps to collect sign-in data from Azure Active Directory without configuring analytics rules in Microsoft Sentinel.

  4. D

    Add the Logic App to the Microsoft Sentinel workspace by assigning it the built-in Contributor role at the resource group where Azure Active Directory resides.

Show answer and explanation

Correct answers: A, B

Explanation

To configure automation with Microsoft Sentinel, you must create or use an existing Logic App (playbook) that has the 'Microsoft Sentinel Incident' trigger, then associate it with the relevant analytics rule in Microsoft Sentinel. This ensures that whenever a matching incident is generated, the playbook will execute automatically. Refer to Microsoft Sentinel documentation (https://learn.microsoft.com/azure/sentinel/automate-incident-handling-with-playbooks) for detailed guidance on configuring playbooks, triggers, and analytics rules.

  • A. Correct.

    Explanation for Option 1: Correct. Creating a Logic App in the same subscription and configuring the 'Microsoft Sentinel Incident' trigger ensures that the workflow initiates as soon as the specified incident is created in Microsoft Sentinel.

  • B. Correct.

    Explanation for Option 2: Correct. An analytics rule in Microsoft Sentinel determines which incidents to create. Associating the Logic App with the relevant analytics rule ensures that the automated workflow responds only to 'High' severity alerts.

  • C. Incorrect.

    Explanation for Option 3: Incorrect. The ‘Security Alerts’ connector does collect security data, but to automate responses from Microsoft Sentinel specifically, you must create an analytics rule and connect a playbook via the Microsoft Sentinel triggers and actions. Simply enabling the connector without an analytics rule does not achieve the required automation.

  • D. Incorrect.

    Explanation for Option 4: Incorrect. Assigning the Contributor role at the resource group for Azure Active Directory does not connect the Logic App to the incident creation process in Microsoft Sentinel. You need to link the Logic App directly to the Sentinel workspace or analytics rule to ensure it triggers on 'High' severity alerts.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam