AZ-500 exam dumps

AZ-500 practice question 269 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 269

Select 2

You are a Security Engineer at Contoso, where Microsoft Sentinel is used to detect suspicious sign-in attempts across various locations. You created a new scheduled analytics rule with the correct KQL query to detect multiple failed sign-ins from different regions. However, after 24 hours, no incidents are being generated. Which two actions should you take to ensure the analytics rule is properly enabled and can generate incidents?

  1. A

    A. In the analytics rule wizard, set the rule status to 'Enabled.'

  2. B

    B. Configure an Automation Rule in the 'Automated response' section to run after each alert.

  3. C

    C. In the 'Incident settings' of the analytics rule, select 'Create incidents from alerts' and set the appropriate severity.

  4. D

    D. Assign the Owner role at the subscription level to make sure the security team can manage the rule.

Show answer and explanation

Correct answers: A, C

Explanation

To properly enable a new analytics rule in Microsoft Sentinel so that it generates incidents, you must ensure both that the rule is enabled in the wizard and that 'Create incidents from alerts' is enabled under 'Incident settings.' This allows Sentinel to create incidents automatically when an alert meets the conditions defined in your KQL query. For more guidance, refer to Microsoft Sentinel documentation: https://learn.microsoft.com/azure/sentinel/create-analytics-rule.

  • A. Correct.

    A. Correct. Even after creating the rule, you must explicitly enable it in the analytics rule wizard for it to run and generate alerts.

  • B. Incorrect.

    B. Incorrect. While Automation Rules can help orchestrate responses, they are not mandatory for enabling the rule or generating incidents in Microsoft Sentinel. Incidents can be created without an Automation Rule.

  • C. Correct.

    C. Correct. By selecting 'Create incidents from alerts' and choosing a suitable severity in the 'Incident settings,' you ensure that any alerts generated by the rule become incidents. Without this, events might only appear in logs but not as incidents.

  • D. Incorrect.

    D. Incorrect. Having the proper role assignments (e.g., Microsoft Sentinel Contributor) is important, but setting yourself or others as Owner at the subscription level is not required for analytics rules to be enabled or to generate incidents.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam