Step2Study
IT & TechnologyAZ-500100% Free

Microsoft Certified: Azure Security Engineer Associate

Practice bank
209 Qs
Real exam
40 Qs
Time limit
120 min
Passing
700 out of 1000

Exam blueprint

Manage identity and access
30%
Implement platform protection
20%
Manage security operations
25%
Secure data and applications
25%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 270 min · pass 70% · 209 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Microsoft Certified: Azure Security Engineer Associate practice test questions

Sample questions from the 209-question bank, with answers and explanations.

All questions
  1. 1. A security operations center (SOC) team uses Microsoft Sentinel for SIEM. They want to create a custom rule to detect a specific type of attack pattern involving multiple failed login attempts followed by a successful login from a new, untrusted IP address within a 10-minute window. This requires correlating events from Azure AD sign-in logs. Which type of analytic rule in Microsoft Sentinel is best suited for this scenario?

    Manage security operations

    • A. Fusion
    • B. Microsoft security
    • C. Anomaly
    • D. Scheduled query
    Show answer

    D. Scheduled query

    A 'Scheduled query' analytic rule allows you to define a custom Kusto Query Language (KQL) query that runs at specified intervals. This is ideal for correlating multiple events over a time window, such as failed logins and subsequent successful logins from a new IP, to detect complex attack patterns.

  2. 2. A security operations team uses Azure Sentinel (now Microsoft Sentinel) for SIEM. They have integrated various data sources, including Azure Active Directory (Azure AD) sign-in logs and activity logs. To detect sophisticated threats that involve multiple stages and different data sources, they need to create custom detection rules that correlate events. Which type of rule in Sentinel is designed for this advanced correlation?

    Manage security operations

    • A. Scheduled query rules
    • B. Machine learning behavior analytics rules
    • C. Basic analytics rules
    • D. Fusion rules
    Show answer

    A. Scheduled query rules

    Scheduled query rules in Microsoft Sentinel allow security analysts to write custom Kusto Query Language (KQL) queries that run on a schedule across multiple data sources. This enables the correlation of events from different logs to detect complex attack patterns or multi-stage threats.

  3. 3. A security engineer is investigating a potential insider threat. They need to analyze changes made to Azure resources by a specific user account over the last week, focusing on any resource deletions, role assignment changes, or modifications to network security group (NSG) rules. Which Azure Monitor log source should the engineer query to find this information?

    Manage security operations

    • A. Azure Active Directory audit logs
    • B. Azure Network Watcher flow logs
    • C. Diagnostic logs from individual resources
    • D. Azure Activity Log
    Show answer

    D. Azure Activity Log

    The Azure Activity Log (formerly Azure Audit Logs) records all control plane operations performed on Azure resources, including resource creations, deletions, updates, and role assignment changes. This log is specifically designed to track who did what, when, and where for management operations, making it ideal for investigating changes to resources and role assignments.

  4. 4. A global organization uses Microsoft Defender for Cloud to manage its security posture across multiple Azure subscriptions and AWS accounts. They need to ensure that their custom regulatory compliance standards, which include specific controls not covered by default standards, are continuously assessed. What is the most efficient way to incorporate these custom standards into Defender for Cloud?

    Manage security operations

    • A. Create a custom regulatory compliance standard within Defender for Cloud.
    • B. Manually check resources against custom standards.
    • C. Create a custom policy initiative in Azure Policy and assign it.
    • D. Export Defender for Cloud recommendations and analyze them externally.
    Show answer

    A. Create a custom regulatory compliance standard within Defender for Cloud.

    Microsoft Defender for Cloud allows creating custom regulatory compliance standards by importing existing Azure Policy initiatives. This directly integrates custom controls into the Defender for Cloud compliance dashboard.

  5. 5. A company is implementing a Zero Trust security model in Azure. They need to configure a mechanism that automatically revokes a user's administrative role assignment after a predefined time, requiring them to re-request access. This is essential for highly privileged roles. Which Azure Active Directory feature should be used to achieve this?

    Manage security operations

    • A. Access reviews
    • B. Conditional Access policies
    • C. Azure AD Identity Protection
    • D. Privileged Identity Management (PIM)
    Show answer

    D. Privileged Identity Management (PIM)

    Azure Active Directory Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources. It supports just-in-time (JIT) access, time-bound access, and approval workflows for privileged roles, automatically revoking access after a specified duration, perfectly matching the requirement.

  6. 6. A security engineer is configuring Azure Monitor to detect unusual network traffic patterns within a Virtual Network (VNet). They want to be alerted if the average inbound and outbound traffic for any VM within the VNet exceeds a specific threshold over a 5-minute period. Which type of alert rule should the engineer create?

    Manage security operations

    • A. Metric alert rule
    • B. Activity log alert rule
    • C. Azure Service Health alert rule
    • D. Log search alert rule
    Show answer

    A. Metric alert rule

    Metric alert rules are specifically designed to monitor numerical values collected from resources, such as network traffic, CPU utilization, or disk I/O, against defined thresholds.

  7. 7. A security engineer needs to configure Azure Monitor to alert when the CPU utilization of any virtual machine within a specific resource group exceeds 90% for more than 5 minutes. The alert should be sent to a specific email distribution list. Which alert type and configuration combination should the engineer use?

    Manage security operations

    • A. Activity log alert for 'CPU utilization exceeded' event, targeting the resource group.
    • B. Log search alert querying Azure Activity Log for high CPU events, with a 5-minute frequency.
    • C. Metric alert for 'Percentage CPU' metric, with a static threshold of 90% and email action group.
    • D. Smart detection alert configured for VM performance anomalies, with email notification.
    Show answer

    C. Metric alert for 'Percentage CPU' metric, with a static threshold of 90% and email action group.

    Metric alert rules are designed to monitor numerical metrics, such as CPU utilization. Configuring a metric alert for the 'Percentage CPU' metric with a static threshold of 90% and a 5-minute aggregation period directly addresses the requirement for detecting high CPU usage and sending notifications.

  8. 8. A security engineer is configuring Azure Security Center (now Microsoft Defender for Cloud) to protect SQL databases. They want to ensure that all SQL servers are continuously monitored for suspicious database activities, such as SQL injection attempts or unusual access patterns. Which specific Defender for Cloud plan should be enabled to provide this advanced threat protection for SQL databases?

    Manage security operations

    • A. Microsoft Defender for SQL
    • B. Microsoft Defender for Servers
    • C. Microsoft Defender for Storage
    • D. Microsoft Defender for App Service
    Show answer

    A. Microsoft Defender for SQL

    Microsoft Defender for SQL is a specific plan within Microsoft Defender for Cloud that provides a comprehensive set of security capabilities for SQL databases, including vulnerability assessment, advanced threat protection for SQL injection, unusual access, and other suspicious activities.

  9. 9. A security analyst is investigating a series of suspicious activities in Azure. They need to find all 'Delete' operations performed on Azure Key Vaults within the last 7 days across multiple subscriptions. Which Azure service should the analyst primarily use to query this information?

    Manage security operations

    • A. Azure Sentinel
    • B. Azure Resource Graph
    • C. Azure Monitor Activity Log
    • D. Azure Security Center (Microsoft Defender for Cloud)
    Show answer

    C. Azure Monitor Activity Log

    The Azure Activity Log records all control-plane operations (e.g., create, update, delete) performed on Azure resources. This is the primary source for investigating 'Delete' operations.

  10. 10. A security analyst is monitoring security alerts in Azure Security Center (now Microsoft Defender for Cloud). They notice a high-severity alert indicating 'Suspicious process executed in a container'. They need to quickly understand the scope of the attack, including affected resources and related events, to determine the appropriate response. Which feature in Security Center provides this consolidated view?

    Manage security operations

    • A. Asset inventory
    • B. Alert details page
    • C. Regulatory Compliance dashboard
    • D. Security recommendations
    Show answer

    B. Alert details page

    The alert details page in Microsoft Defender for Cloud provides comprehensive information about a specific security alert, including affected resources, related entities, attack kill chain details, and recommended actions, enabling quick incident response.

  11. 11. A security administrator needs to ensure that all virtual machines in a specific Azure subscription have their diagnostic settings configured to send audit logs to a Log Analytics workspace. This requirement must be enforced automatically for new VMs and audited for existing ones. Which Azure service should be used to implement this requirement?

    Manage security operations

    • A. Azure Monitor activity log
    • B. Azure Policy
    • C. Azure Sentinel
    • D. Azure Security Center (Microsoft Defender for Cloud)
    Show answer

    B. Azure Policy

    Azure Policy is the correct service for enforcing organizational standards and assessing compliance at scale. It can be used to audit existing resources for non-compliance and automatically remediate or enforce specific configurations, such as diagnostic settings, for new resources.

  12. 12. A security architect is designing a monitoring solution for a highly sensitive application hosted on Azure Kubernetes Service (AKS). They need to collect detailed security-related audit logs from the AKS control plane and worker nodes, specifically focusing on API server access and container runtime events, and send them to Microsoft Sentinel for analysis. Which data connector should be configured in Sentinel for this purpose?

    Manage security operations

    • A. Common Event Format (CEF) connector
    • B. Azure Activity Log connector
    • C. Azure Diagnostics connector
    • D. Azure Kubernetes Service (AKS) connector
    Show answer

    D. Azure Kubernetes Service (AKS) connector

    The Azure Kubernetes Service (AKS) data connector in Microsoft Sentinel is specifically designed to ingest AKS audit logs and other security-related data from both the control plane and worker nodes, providing comprehensive visibility for AKS environments.

  13. 13. A company is implementing a zero-trust security model and needs to enforce granular access policies for administrative roles. They want to ensure that privileged users only have access to specific resources for a limited time when performing critical tasks, and their access is automatically revoked afterward. Which Azure AD PIM feature should be configured to meet this requirement?

    Manage security operations

    • A. Access reviews
    • B. Self-service password reset
    • C. Just-in-Time (JIT) access
    • D. Conditional Access policies
    Show answer

    C. Just-in-Time (JIT) access

    Just-in-Time (JIT) access, provided by Azure AD Privileged Identity Management (PIM), allows privileged roles to be activated only when needed and for a limited duration. Once the time expires, access is automatically revoked, minimizing the window of exposure for privileged accounts.

  14. 14. A global organization uses Azure Monitor to collect logs from various Azure resources and on-premises servers. They have a strict requirement to retain security-related logs for 7 years for compliance purposes. However, due to cost considerations, they want to retain performance metrics and non-security diagnostic logs for only 90 days. How can this requirement be met efficiently within a single Log Analytics workspace?

    Manage security operations

    • A. Create separate Log Analytics workspaces for security logs and non-security logs, each with its own retention policy.
    • B. Export all logs to Azure Storage for long-term retention and configure different lifecycle policies in Storage.
    • C. Use Azure Data Explorer for security logs and Log Analytics for non-security logs.
    • D. Configure different retention policies for each data type in the Log Analytics workspace.
    Show answer

    D. Configure different retention policies for each data type in the Log Analytics workspace.

    Log Analytics workspaces allow for granular control over data retention. You can configure different retention periods for specific data types within the same workspace, enabling cost optimization and compliance with varying requirements.

  15. 15. A security operations center (SOC) team uses Microsoft Sentinel for threat detection and response. They want to ensure that all security incidents generated by Sentinel are automatically forwarded to their existing third-party ITSM (IT Service Management) system for ticketing and workflow management. Which Sentinel feature should they configure to achieve this automation?

    Manage security operations

    • A. Playbooks
    • B. Workbooks
    • C. Hunting Queries
    • D. Analytic Rules
    Show answer

    A. Playbooks

    Playbooks in Microsoft Sentinel are automated response procedures built on Azure Logic Apps. They can be triggered by incidents and perform actions like sending data to external systems.

  16. 16. A security auditor needs to verify that all Azure Key Vaults in a subscription are configured to enable purge protection, which prevents immediate deletion of the vault or its contents. They want to quickly identify any non-compliant Key Vaults. Which service in Azure should the auditor use to assess this configuration against a predefined security standard?

    Manage security operations

    • A. Azure Monitor
    • B. Azure Activity Log
    • C. Microsoft Defender for Cloud
    • D. Azure Network Watcher
    Show answer

    C. Microsoft Defender for Cloud

    Microsoft Defender for Cloud (formerly Azure Security Center) provides a centralized security posture management solution. It continuously assesses Azure resources against security best practices and regulatory standards, identifying misconfigurations like missing purge protection on Key Vaults and providing recommendations for remediation.

  17. 17. A company is implementing Microsoft Defender for Cloud and needs to ensure that all Azure subscriptions within their tenant are continuously monitored for security posture, regulatory compliance, and threat protection, even newly created ones. They want to avoid manually onboarding each subscription. How should they configure Defender for Cloud to meet this requirement?

    Manage security operations

    • A. Use Azure Policy to enforce Defender for Cloud enablement on subscriptions.
    • B. Onboard subscriptions through the Defender for Cloud pricing and settings blade.
    • C. Connect the Azure AD tenant root management group to Defender for Cloud.
    • D. Enable Defender for Cloud for each subscription individually.
    Show answer

    C. Connect the Azure AD tenant root management group to Defender for Cloud.

    Connecting the Azure AD tenant root management group to Defender for Cloud ensures that all current and future subscriptions under that tenant are automatically onboarded and monitored.

  18. 18. A company uses Azure Security Center (now Microsoft Defender for Cloud) to manage its security posture. They have several Azure subscriptions and want to ensure that all virtual machines across these subscriptions are configured with a specific set of security recommendations. Which feature should they use to centrally define and apply these security recommendations?

    Manage security operations

    • A. Azure Sentinel workbooks
    • B. Azure Monitor Log Analytics workspaces
    • C. Azure Network Watcher
    • D. Azure Policy
    Show answer

    D. Azure Policy

    Azure Policy allows organizations to create, assign, and manage policies that enforce specific rules and effects over their resources, ensuring compliance with security recommendations across multiple subscriptions.

  19. 19. A security engineer is configuring Azure Monitor to detect suspicious login activities. They need to create an alert rule that triggers when more than five failed login attempts occur from the same IP address within a 10-minute window. Which type of alert rule should the engineer configure?

    Manage security operations

    • A. Log search alert rule
    • B. Activity log alert rule
    • C. Metric alert rule
    • D. Application Insights alert rule
    Show answer

    A. Log search alert rule

    To detect patterns in log data, such as multiple failed login attempts from a specific IP address within a time window, a log search alert rule is the appropriate choice. This rule type allows for custom Kusto Query Language (KQL) queries against Log Analytics workspaces.

  20. 20. A security operations center (SOC) uses Azure Sentinel for monitoring. They have configured a custom analytics rule that uses a Kusto Query Language (KQL) query to detect unusual administrative logins. This rule generates a high volume of false positives due to legitimate, but infrequent, administrative activities. Which of the following is the most effective way to reduce false positives without missing actual threats?

    Manage security operations

    • A. Disable the analytics rule and rely on other built-in Sentinel rules.
    • B. Refine the KQL query to include additional filtering criteria or baselines for legitimate activity.
    • C. Decrease the query's lookback period to reduce the data analyzed.
    • D. Increase the alert threshold to require more events before triggering.
    Show answer

    B. Refine the KQL query to include additional filtering criteria or baselines for legitimate activity.

    Refining the KQL query to incorporate additional filtering criteria, baselines, or behavioral analytics (e.g., specific source IPs for administrators, time-of-day restrictions, or known administrative jump boxes) is the most effective way to reduce false positives while maintaining detection capability for actual threats. This makes the detection logic more precise.

  21. 21. A company has implemented Microsoft Defender for Cloud for server protection. They receive an alert labeled 'High severity - Anomalous SSH activity detected on VM-Prod-01'. The security team needs to quickly understand the scope of the attack, including other potentially affected resources and the attacker's tactics, techniques, and procedures (TTPs). Where in Microsoft Defender for Cloud should they look first for this consolidated information?

    Manage security operations

    • A. The 'Workload protections' blade, under 'Server protection'.
    • B. The 'Regulatory compliance' dashboard.
    • C. The 'Security alerts' blade, filtering for VM-Prod-01.
    • D. The specific alert's 'Incident' details page.
    Show answer

    D. The specific alert's 'Incident' details page.

    In Microsoft Defender for Cloud, related alerts are grouped into security incidents. The incident details page provides a consolidated view of all related alerts, affected resources, and often includes MITRE ATT&CK TTPs, making it the ideal starting point for understanding the scope of an attack.

  22. 22. A company is using Microsoft Sentinel for SIEM and SOAR. They have configured analytic rules to detect suspicious activities. They now want to automatically enrich incidents with threat intelligence data from a third-party feed and then send a notification to a Microsoft Teams channel. Which type of automated response should they implement?

    Manage security operations

    • A. Playbooks
    • B. Automation Rules
    • C. Hunting Queries
    • D. Workbooks
    Show answer

    A. Playbooks

    Playbooks (Azure Logic Apps) are used in Sentinel for complex automated responses, including integrating with external services like threat intelligence feeds and sending notifications to platforms like Microsoft Teams.

  23. 23. A security engineer is configuring Azure Monitor to detect unusual administrative activities within their Azure subscription. They want to receive an alert whenever a 'Delete Virtual Machine' operation is initiated by any user, excluding specific automated service principals. The alert should trigger within 5 minutes of the event occurring. Which type of alert rule should be created in Azure Monitor to meet these requirements?

    Manage security operations

    • A. Metric alert rule
    • B. Activity log alert rule
    • C. Log search alert rule
    • D. Smart detection alert rule
    Show answer

    B. Activity log alert rule

    Activity log alert rules in Azure Monitor are designed to trigger alerts based on specific events in the Azure Activity Log. They are ideal for monitoring administrative operations like 'Delete Virtual Machine' and can be configured with conditions to exclude specific users or service principals.

  24. 24. A company is using Azure Monitor and Log Analytics to collect security logs from various Azure resources. They want to create a custom alert that triggers when more than 5 failed login attempts occur within a 10-minute window from the same source IP address against any virtual machine. Which component of Azure Monitor is best suited for defining and managing this type of alert?

    Manage security operations

    • A. Azure Activity Log Alerts
    • B. Azure Monitor Metrics
    • C. Azure Monitor Workbooks
    • D. Log Analytics Queries (KQL) and Alert Rules
    Show answer

    D. Log Analytics Queries (KQL) and Alert Rules

    Log Analytics queries written in KQL (Kusto Query Language) can be used to analyze log data for specific patterns, such as multiple failed logins. These queries can then be integrated into Azure Monitor alert rules to trigger notifications when the specified conditions are met.

  25. 25. A security operations team uses Azure Monitor to collect diagnostic logs from Azure Key Vault. They need to create an alert that triggers specifically when a 'SecretGet' operation fails due to insufficient permissions. This alert should contain details about the caller, the Key Vault name, and the specific secret involved. Which Kusto Query Language (KQL) operator is most effective for extracting specific fields from a log entry and then filtering based on custom criteria?

    Manage security operations

    • A. project
    • B. join
    • C. summarize
    • D. parse
    Show answer

    A. project

    The 'project' operator in KQL is used to select specific columns, rename them, or add new calculated columns to the output. This is essential for extracting relevant fields like caller, Key Vault name, and secret from the diagnostic log entry after filtering for failed 'SecretGet' operations, ensuring the alert contains the necessary details.

Microsoft Certified: Azure Security Engineer Associate flashcards

Tap a card to flip it. 142 flashcards in the full deck.

  • Sentinel Scheduled Query Rules

    Flip card

    Analytic rules in Microsoft Sentinel that run custom Kusto Query Language (KQL) queries on a schedule to detect threats.

    • Enables detection of complex attack patterns and correlations.
    • Can be configured to generate incidents based on query results.
    • Supports various data sources ingested into Sentinel.
    Study this card →
  • Azure Activity Log

    Flip card

    A log in Azure Monitor that records events at the subscription level, detailing operations performed on resources, by whom, when, and their status.

    • Tracks control plane operations (management events).
    • Includes resource creation, deletion, updates, and RBAC changes.
    • Crucial for auditing, troubleshooting, and security investigations related to resource management.
    Study this card →
  • Defender for Cloud Custom Compliance

    Flip card

    Microsoft Defender for Cloud enables organizations to define and assess custom regulatory compliance standards by integrating custom Azure Policy initiatives directly into its compliance dashboard.

    • Extends Defender for Cloud's compliance capabilities.
    • Integrates custom Azure Policy initiatives.
    • Provides unified reporting with built-in standards.
    Study this card →
  • Azure AD Privileged Identity Management (PIM)

    Flip card

    An Azure AD feature that allows for managing, controlling, and monitoring access to important resources in Azure AD, Azure, and other Microsoft Online Services.

    • Enables just-in-time (JIT) privileged access.
    • Provides time-bound access to roles, with automatic revocation.
    • Supports approval workflows and audit trails for privileged operations.
    Study this card →
  • Azure Monitor Metric Alerts

    Flip card

    Azure Monitor Metric Alerts trigger when a numerical metric value, such as CPU usage or network traffic, crosses a predefined threshold for a specified period.

    • Monitors numerical data points collected over time.
    • Ideal for performance and usage monitoring.
    • Can aggregate data over different time granularities.
    Study this card →
  • Microsoft Defender for SQL

    Flip card

    Microsoft Defender for SQL is a security offering within Microsoft Defender for Cloud that protects Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure Virtual Machines. It includes vulnerability assessment and advanced threat protection capabilities.

    • Protects Azure SQL Database, Managed Instance, and SQL on VMs.
    • Includes vulnerability assessment.
    • Detects SQL injection, unusual access, and other threats.
    Study this card →
  • Microsoft Defender for Cloud Alert Details

    Flip card

    The alert details page within Microsoft Defender for Cloud provides a comprehensive breakdown of a specific security alert, offering context, affected resources, attack timeline, and recommended actions to facilitate investigation and response.

    • Consolidates all relevant information for a single alert.
    • Includes affected resources and related entities.
    • Shows attack kill chain details.
    Study this card →
  • Azure Policy

    Flip card

    A service in Azure that helps enforce organizational standards and assess compliance at scale. It enables you to create, assign, and manage policies that define rules for your resources.

    • Used for governance, compliance, and configuration management.
    • Can audit, deny, or modify resource creation/updates.
    • Supports built-in policies and custom policy definitions.
    Study this card →
  • Microsoft Sentinel AKS Connector

    Flip card

    The Microsoft Sentinel Azure Kubernetes Service (AKS) data connector enables the ingestion of detailed AKS audit logs, control plane logs, and other security data into Sentinel for comprehensive threat detection and analysis.

    • Collects audit logs from AKS control plane.
    • Gathers security events from worker nodes.
    • Provides deep visibility into containerized environments.
    Study this card →
  • Azure AD PIM Just-in-Time Access

    Flip card

    Azure AD Privileged Identity Management (PIM) provides Just-in-Time (JIT) access to minimize the window of exposure for privileged roles. Users activate their roles on demand, for a specific duration, and their permissions are automatically revoked when the time expires.

    • Grants temporary, time-bound access to privileged roles.
    • Access is activated on demand by the user.
    • Automatically revokes access after the specified duration.
    Study this card →
  • Log Analytics Data Retention

    Flip card

    The ability to configure how long different types of data are stored within an Azure Log Analytics workspace.

    • Retention can be configured at the workspace level, applying to all data.
    • Retention can also be configured per data type (table) for more granular control.
    • Granular retention helps manage costs and meet compliance requirements.
    Study this card →
  • Microsoft Sentinel Playbooks

    Flip card

    Microsoft Sentinel Playbooks are automated, orchestrated, and customizable response procedures (Azure Logic Apps) that can be triggered by incidents or alerts.

    • Built on Azure Logic Apps.
    • Automate security operations tasks.
    • Can interact with other Azure services and external systems via connectors.
    Study this card →
  • Microsoft Defender for Cloud Security Posture Management

    Flip card

    A unified security management system that strengthens the security posture of cloud resources and provides advanced threat protection.

    • Continuously assesses security configurations.
    • Provides security recommendations based on benchmarks and standards.
    • Offers a secure score to quantify security posture.
    Study this card →
  • Defender for Cloud Tenant Onboarding

    Flip card

    Onboarding the Azure AD tenant root management group to Microsoft Defender for Cloud automatically enables monitoring and protection for all current and future subscriptions within that tenant.

    • Provides tenant-wide visibility and control.
    • Simplifies onboarding for large organizations.
    • Ensures consistent security posture across all subscriptions.
    Study this card →
  • Azure Policy for Security

    Flip card

    Azure Policy helps enforce organizational standards and assess compliance at scale. Through its compliance dashboard, it provides an aggregated view to evaluate the overall state of the environment, with the ability to drill down to the per-resource, per-policy, and per-assignment detail.

    • Enforces organizational standards.
    • Assesses compliance at scale.
    • Integrates with Azure Security Center (Microsoft Defender for Cloud).
    Study this card →
  • Log Search Alert Rule

    Flip card

    An Azure Monitor alert rule that triggers based on the results of a Kusto Query Language (KQL) query run against log data in a Log Analytics workspace.

    • Used for detecting patterns, specific events, or thresholds in log data.
    • Requires a KQL query to define the alert condition.
    • Can be configured with various aggregations and time windows.
    Study this card →
  • Sentinel KQL Query Optimization

    Flip card

    The process of improving Kusto Query Language (KQL) queries in Azure Sentinel analytics rules to enhance detection accuracy, reduce false positives, and improve performance.

    • Involves adding specific filters, exclusions, or behavioral baselines.
    • Aims to distinguish between legitimate activity and malicious behavior.
    • Crucial for maintaining an effective and actionable SIEM.
    Study this card →
  • Defender for Cloud Security Incidents

    Flip card

    A feature in Microsoft Defender for Cloud (and Sentinel) that groups related security alerts into a single, comprehensive view to facilitate investigation and response.

    • Correlates alerts across different resources and services.
    • Provides a timeline of events and affected entities.
    • Often includes MITRE ATT&CK TTPs for context.
    Study this card →
  • Sentinel Playbooks for SOAR

    Flip card

    Microsoft Sentinel Playbooks, powered by Azure Logic Apps, enable Security Orchestration, Automation, and Response (SOAR) by automating complex workflows, integrating with external systems, and performing actions based on incidents.

    • Built on Azure Logic Apps.
    • Automate incident response and enrichment.
    • Connect to external services via connectors.
    Study this card →
  • Azure Monitor Activity Log Alerts

    Flip card

    Alert rules in Azure Monitor that trigger based on events recorded in the Azure Activity Log, which tracks control plane operations.

    • Monitors administrative operations (e.g., resource creation, deletion, updates).
    • Can filter by resource, resource group, subscription, event level, caller, etc.
    • Ideal for detecting unauthorized changes or critical administrative actions.
    Study this card →
  • Log Alerts in Azure Monitor

    Flip card

    Azure Monitor log alerts use Kusto Query Language (KQL) to evaluate resources logs at a specified frequency. If the query results indicate a specific condition, an alert is triggered, notifying users or initiating automated actions.

    • Uses KQL for flexible log pattern matching.
    • Evaluates logs from Log Analytics workspaces.
    • Can trigger alerts based on count, average, minimum, maximum, total, or unique count.
    Study this card →
  • KQL 'project' operator

    Flip card

    The Kusto Query Language (KQL) 'project' operator selects the columns to include in the output, renames columns, or adds new computed columns. It is fundamental for shaping query results to display only the relevant information needed for analysis or alerting.

    • Selects specific columns from a table.
    • Can rename columns.
    • Can add new computed columns.
    Study this card →
  • Azure Policy 'DeployIfNotExists' Effect

    Flip card

    An Azure Policy effect that deploys a template when a condition is met (e.g., a resource is missing a required configuration) and the resource does not exist or is not compliant.

    • Used for automatic remediation and configuration enforcement.
    • Requires a deployment template (ARM template) within the policy definition.
    • Ideal for ensuring baseline configurations like diagnostic settings or security features.
    Study this card →
  • Log Analytics for Security

    Flip card

    Azure Monitor Log Analytics workspaces serve as a central hub for collecting and analyzing operational and security logs from a wide array of Azure resources, hybrid environments, and other cloud providers. Its Kusto Query Language (KQL) enables powerful correlation and analysis for security investigations.

    • Centralized log collection from diverse sources.
    • Uses Kusto Query Language (KQL) for advanced querying.
    • Essential for security investigations and threat hunting.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.