AZ-500 exam dumps

AZ-500 practice question 257 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 257

Select 2

You have received an alert in Microsoft Defender for Cloud indicating suspicious outbound traffic from an Azure VM. Security logs suggest this VM may be compromised. You want to quickly block any further malicious connections and gather more details for an investigation. Which two actions should you take first?

  1. A

    Configure a workflow automation with Azure Logic Apps to block the suspicious source IP in the Network Security Group (NSG).

  2. B

    Use the Investigate feature in Microsoft Defender for Cloud to collect more details about the incident and review related logs.

  3. C

    Immediately delete the VM to ensure the threat is contained and cannot spread further.

  4. D

    Enable just-in-time (JIT) VM access on the suspected VM to prevent outbound malicious traffic.

Show answer and explanation

Correct answers: A, B

Explanation

When responding to security alerts in Microsoft Defender for Cloud, a recommended approach includes investigating to understand the scope and nature of the alert and then applying targeted remediation steps. Workflow automation (via Azure Logic Apps) can be leveraged to automatically block malicious IPs in the firewall or NSG. This aligns with best practices described in Microsoft Defender for Cloud documentation on alert investigations and automated responses.

  • A. Correct.

    Option 1 is correct. Using Azure Logic Apps with Microsoft Defender for Cloud workflow automation is an effective approach to quickly block malicious IP addresses at the NSG or Azure Firewall level. This way, you can automate future responses to similar alerts.

  • B. Correct.

    Option 2 is correct. The Investigate feature in Microsoft Defender for Cloud allows you to examine the scope of the alert and follow the security graph to gather data from relevant logs. This is a crucial step before executing or fine-tuning the remediation process.

  • C. Incorrect.

    Option 3 is incorrect. Although this ensures the compromised VM is removed, it’s typically excessive and can result in data loss. Best practice is to thoroughly investigate the alert first, gather logs, and apply targeted remediation steps or isolate the VM if needed, rather than deleting it outright.

  • D. Incorrect.

    Option 4 is incorrect. Just-in-time VM access is designed to restrict inbound traffic to protect VMs from unauthorized external access. It does not block or control outbound traffic, so it won't prevent malicious connections originating from the VM.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam