exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 1 question 33 discussion

Actual exam question from Microsoft's AZ-500
Question #: 33
Topic #: 1
[All AZ-500 Questions]

After creating a new Azure subscription, you are tasked with making sure that custom alert rules can be created in Azure Security Center.
You have created an Azure Storage account.
Which of the following is the action you should take?

  • A. You should make sure that Azure Active Directory (Azure AD) Identity Protection is removed.
  • B. You should create a DLP policy.
  • C. You should create an Azure Log Analytics workspace.
  • D. You should make sure that Security Center has the necessary tier configured.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
amitdimpy
Highly Voted 2 years, 5 months ago
Question was in 8-Jan-2023 exam.
upvoted 15 times
...
Andre369
Highly Voted 2 years, 1 month ago
Selected Answer: C
C. You should create an Azure Log Analytics workspace. Azure Security Center leverages Azure Log Analytics to store and analyze security-related data and generate alerts. By creating an Azure Log Analytics workspace, you provide the necessary storage and analysis capabilities for Security Center to generate and manage custom alert rules. Option A, removing Azure Active Directory (Azure AD) Identity Protection, is unrelated to enabling the creation of custom alert rules in Security Center. Option B, creating a Data Loss Prevention (DLP) policy, is not directly related to enabling custom alert rules in Security Center. DLP policies are used for managing and preventing data loss in various services and applications. Option D, configuring the necessary tier in Security Center, may impact the availability of certain features and capabilities, but it is not specifically required to enable the creation of custom alert rules.
upvoted 8 times
...
Knighthell
Most Recent 2 weeks, 4 days ago
Selected Answer: C
Enhanced Security (Standard) You must enable the Microsoft Defender plan
upvoted 1 times
Knighthell
2 weeks, 4 days ago
Sorry D Answer
upvoted 1 times
...
...
khamrumunnu
1 month, 1 week ago
Selected Answer: D
To create custom alert rules in Azure Security Center (now Microsoft Defender for Cloud), you need: An Azure Log Analytics workspace This is where the security data and logs (such as alerts, assessments, and recommendations) are collected and stored. Custom alert rules are built using Kusto Query Language (KQL) against this data. The correct pricing tier for Microsoft Defender for Cloud You must enable the Microsoft Defender plan (formerly the Standard tier) on the subscription or resource level. This enables advanced features like: Custom alert rules Threat detection Security recommendations
upvoted 2 times
...
mmmyo
1 month, 2 weeks ago
Selected Answer: C
Azure Security Center relies on Azure Log Analytics to collect and analyze security data. To enable custom alert rules, you need a Log Analytics workspace where Security Center can store and process security events. This allows you to define and configure alerts based on security insights, queries, and threat detection patterns. Analysis of Other Options: A (Remove Azure AD Identity Protection) ❌ Incorrect Azure AD Identity Protection enhances security; removing it has no relevance to enabling custom alerts in Security Center. B (Create a DLP policy) ❌ Incorrect Data Loss Prevention (DLP) policies are used in Microsoft Purview and do not directly impact custom alert rules in Security Center. D (Configure the necessary Security Center tier) ✅ Relevant but secondary Standard tier of Security Center offers advanced threat protection and custom alert rules, but the first step for alerts is ensuring Log Analytics is set up.
upvoted 1 times
...
stonwall12
4 months, 1 week ago
Selected Answer: D
--Questions looks to be outdated-- Azure Security Center has been rebranded as Microsoft Defender for Cloud, and some features and terminology have changed. Answer: D, You should make sure that Microsoft Defender for Cloud has the necessary plan enabled. Reason: To create custom alert rules in Microsoft Defender for Cloud (formerly Azure Security Center), you need to have the appropriate Microsoft Defender plan enabled for the resources you want to monitor. Custom alert rules are part of the advanced threat detection capabilities provided by these plans. Simply creating a storage account or Log Analytics workspace is not sufficient to enable this functionality. Reference: https://learn.microsoft.com/en-us/azure/defender-for-cloud/custom-alert-rules
upvoted 4 times
...
Jimmy500
11 months ago
For today answer is as below: I think this question now looks like an outdated questions, because now we do not have custom Alert rules in Defender for Cloud we can create it from Azure Monitor but those would be metrics, logs, activity logs, resource health or service health. We can create Security Alerts from Defender for Cloud as of today , this will generate alert regarding to Workloads , such as virtual machines ,storage accounts, container registry and other workloads that can be protected by defender for cloud. This question can come exam like this , if they ask what do we need to create Custom Alerts we need log analytics workspace , if it asks what do we need first to create Security Alerts then we need to upgrade the plan of Defender of Cloud.
upvoted 6 times
...
Tognan
1 year, 3 months ago
Selected Answer: D
The correct action you should take to ensure custom alert rules can be created in Azure Security Center is: D. You should make sure that Security Center has the necessary tier configured. Here's why: Free tier limitations: The free tier of Azure Security Center may not support creating custom alert rules. These rules allow for more granular security monitoring based on your specific needs. Paid tiers: Upgrading Security Center to a paid tier (such as Standard or Premium) typically unlocks features like custom alert rule creation.
upvoted 3 times
...
Tognan
1 year, 3 months ago
The correct action you should take to ensure custom alert rules can be created in Azure Security Center is: D. You should make sure that Security Center has the necessary tier configured. Here's why: Free tier limitations: The free tier of Azure Security Center may not support creating custom alert rules. These rules allow for more granular security monitoring based on your specific needs. Paid tiers: Upgrading Security Center to a paid tier (such as Standard or Premium) typically unlocks features like custom alert rule creation.
upvoted 2 times
...
JunetGoyal
1 year, 8 months ago
its D, not C
upvoted 1 times
wardy1983
1 year, 7 months ago
why is it D?
upvoted 2 times
...
...
ESAJRR
1 year, 11 months ago
Selected Answer: C
C. You should create an Azure Log Analytics workspace.
upvoted 2 times
...
Dev1079
2 years ago
Selected Answer: C
https://learn.microsoft.com/en-us/answers/questions/1085512/azure-security-center-custom-rules?orderby=oldest
upvoted 2 times
...
Cock
2 years, 1 month ago
Selected Answer: D
The answer is D. Similar questions appeared before
upvoted 1 times
...
AlexPenev95
2 years, 1 month ago
Selected Answer: D
D seems legit to me
upvoted 1 times
...
majstor86
2 years, 3 months ago
Selected Answer: C
C. You should create an Azure Log Analytics workspace. Most Voted
upvoted 2 times
...
DESHAINEMARI
2 years, 4 months ago
D. You should make sure that Security Center has the necessary tier configured. To create custom alert rules in Azure Security Center, you need to have the appropriate tier of Security Center enabled. The Standard tier and the Free tier of Security Center support creating custom alert rules, while the Basic tier does not. Therefore, after creating a new Azure subscription, you should make sure that Security Center has the necessary tier configured, either Standard or Free, to enable the creation of custom alert rules. Creating an Azure Storage account, creating a DLP policy, or creating an Azure Log Analytics workspace are not directly related to enabling the creation of custom alert rules in Azure Security Center.
upvoted 3 times
...
azlearner001
2 years, 4 months ago
Answer should be D. https://woivre.com/blog/2021/12/improve-your-microsoft-defender-for-cloud-with-your-custom-rules
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...