1. A security operations center (SOC) team uses Microsoft Sentinel for SIEM. They want to create a custom rule to detect a specific type of attack pattern involving multiple failed login attempts followed by a successful login from a new, untrusted IP address within a 10-minute window. This requires correlating events from Azure AD sign-in logs. Which type of analytic rule in Microsoft Sentinel is best suited for this scenario?
Manage security operations
A.Fusion
B.Microsoft security
C.Anomaly
D.Scheduled query
Show answerAnswer
D. Scheduled query
A 'Scheduled query' analytic rule allows you to define a custom Kusto Query Language (KQL) query that runs at specified intervals. This is ideal for correlating multiple events over a time window, such as failed logins and subsequent successful logins from a new IP, to detect complex attack patterns.
2. A security operations team uses Azure Sentinel (now Microsoft Sentinel) for SIEM. They have integrated various data sources, including Azure Active Directory (Azure AD) sign-in logs and activity logs. To detect sophisticated threats that involve multiple stages and different data sources, they need to create custom detection rules that correlate events. Which type of rule in Sentinel is designed for this advanced correlation?
Manage security operations
A.Scheduled query rules
B.Machine learning behavior analytics rules
C.Basic analytics rules
D.Fusion rules
Show answerAnswer
A. Scheduled query rules
Scheduled query rules in Microsoft Sentinel allow security analysts to write custom Kusto Query Language (KQL) queries that run on a schedule across multiple data sources. This enables the correlation of events from different logs to detect complex attack patterns or multi-stage threats.
3. A security engineer is investigating a potential insider threat. They need to analyze changes made to Azure resources by a specific user account over the last week, focusing on any resource deletions, role assignment changes, or modifications to network security group (NSG) rules. Which Azure Monitor log source should the engineer query to find this information?
Manage security operations
A.Azure Active Directory audit logs
B.Azure Network Watcher flow logs
C.Diagnostic logs from individual resources
D.Azure Activity Log
Show answerAnswer
D. Azure Activity Log
The Azure Activity Log (formerly Azure Audit Logs) records all control plane operations performed on Azure resources, including resource creations, deletions, updates, and role assignment changes. This log is specifically designed to track who did what, when, and where for management operations, making it ideal for investigating changes to resources and role assignments.
4. A global organization uses Microsoft Defender for Cloud to manage its security posture across multiple Azure subscriptions and AWS accounts. They need to ensure that their custom regulatory compliance standards, which include specific controls not covered by default standards, are continuously assessed. What is the most efficient way to incorporate these custom standards into Defender for Cloud?
Manage security operations
A.Create a custom regulatory compliance standard within Defender for Cloud.
B.Manually check resources against custom standards.
C.Create a custom policy initiative in Azure Policy and assign it.
D.Export Defender for Cloud recommendations and analyze them externally.
Show answerAnswer
A. Create a custom regulatory compliance standard within Defender for Cloud.
Microsoft Defender for Cloud allows creating custom regulatory compliance standards by importing existing Azure Policy initiatives. This directly integrates custom controls into the Defender for Cloud compliance dashboard.
5. A company is implementing a Zero Trust security model in Azure. They need to configure a mechanism that automatically revokes a user's administrative role assignment after a predefined time, requiring them to re-request access. This is essential for highly privileged roles. Which Azure Active Directory feature should be used to achieve this?
Manage security operations
A.Access reviews
B.Conditional Access policies
C.Azure AD Identity Protection
D.Privileged Identity Management (PIM)
Show answerAnswer
D. Privileged Identity Management (PIM)
Azure Active Directory Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources. It supports just-in-time (JIT) access, time-bound access, and approval workflows for privileged roles, automatically revoking access after a specified duration, perfectly matching the requirement.
6. A security engineer is configuring Azure Monitor to detect unusual network traffic patterns within a Virtual Network (VNet). They want to be alerted if the average inbound and outbound traffic for any VM within the VNet exceeds a specific threshold over a 5-minute period. Which type of alert rule should the engineer create?
Manage security operations
A.Metric alert rule
B.Activity log alert rule
C.Azure Service Health alert rule
D.Log search alert rule
Show answerAnswer
A. Metric alert rule
Metric alert rules are specifically designed to monitor numerical values collected from resources, such as network traffic, CPU utilization, or disk I/O, against defined thresholds.
7. A security engineer needs to configure Azure Monitor to alert when the CPU utilization of any virtual machine within a specific resource group exceeds 90% for more than 5 minutes. The alert should be sent to a specific email distribution list. Which alert type and configuration combination should the engineer use?
Manage security operations
A.Activity log alert for 'CPU utilization exceeded' event, targeting the resource group.
B.Log search alert querying Azure Activity Log for high CPU events, with a 5-minute frequency.
C.Metric alert for 'Percentage CPU' metric, with a static threshold of 90% and email action group.
D.Smart detection alert configured for VM performance anomalies, with email notification.
Show answerAnswer
C. Metric alert for 'Percentage CPU' metric, with a static threshold of 90% and email action group.
Metric alert rules are designed to monitor numerical metrics, such as CPU utilization. Configuring a metric alert for the 'Percentage CPU' metric with a static threshold of 90% and a 5-minute aggregation period directly addresses the requirement for detecting high CPU usage and sending notifications.
8. A security engineer is configuring Azure Security Center (now Microsoft Defender for Cloud) to protect SQL databases. They want to ensure that all SQL servers are continuously monitored for suspicious database activities, such as SQL injection attempts or unusual access patterns. Which specific Defender for Cloud plan should be enabled to provide this advanced threat protection for SQL databases?
Manage security operations
A.Microsoft Defender for SQL
B.Microsoft Defender for Servers
C.Microsoft Defender for Storage
D.Microsoft Defender for App Service
Show answerAnswer
A. Microsoft Defender for SQL
Microsoft Defender for SQL is a specific plan within Microsoft Defender for Cloud that provides a comprehensive set of security capabilities for SQL databases, including vulnerability assessment, advanced threat protection for SQL injection, unusual access, and other suspicious activities.
9. A security analyst is investigating a series of suspicious activities in Azure. They need to find all 'Delete' operations performed on Azure Key Vaults within the last 7 days across multiple subscriptions. Which Azure service should the analyst primarily use to query this information?
Manage security operations
A.Azure Sentinel
B.Azure Resource Graph
C.Azure Monitor Activity Log
D.Azure Security Center (Microsoft Defender for Cloud)
Show answerAnswer
C. Azure Monitor Activity Log
The Azure Activity Log records all control-plane operations (e.g., create, update, delete) performed on Azure resources. This is the primary source for investigating 'Delete' operations.
10. A security analyst is monitoring security alerts in Azure Security Center (now Microsoft Defender for Cloud). They notice a high-severity alert indicating 'Suspicious process executed in a container'. They need to quickly understand the scope of the attack, including affected resources and related events, to determine the appropriate response. Which feature in Security Center provides this consolidated view?
Manage security operations
A.Asset inventory
B.Alert details page
C.Regulatory Compliance dashboard
D.Security recommendations
Show answerAnswer
B. Alert details page
The alert details page in Microsoft Defender for Cloud provides comprehensive information about a specific security alert, including affected resources, related entities, attack kill chain details, and recommended actions, enabling quick incident response.
11. A security administrator needs to ensure that all virtual machines in a specific Azure subscription have their diagnostic settings configured to send audit logs to a Log Analytics workspace. This requirement must be enforced automatically for new VMs and audited for existing ones. Which Azure service should be used to implement this requirement?
Manage security operations
A.Azure Monitor activity log
B.Azure Policy
C.Azure Sentinel
D.Azure Security Center (Microsoft Defender for Cloud)
Show answerAnswer
B. Azure Policy
Azure Policy is the correct service for enforcing organizational standards and assessing compliance at scale. It can be used to audit existing resources for non-compliance and automatically remediate or enforce specific configurations, such as diagnostic settings, for new resources.
12. A security architect is designing a monitoring solution for a highly sensitive application hosted on Azure Kubernetes Service (AKS). They need to collect detailed security-related audit logs from the AKS control plane and worker nodes, specifically focusing on API server access and container runtime events, and send them to Microsoft Sentinel for analysis. Which data connector should be configured in Sentinel for this purpose?
Manage security operations
A.Common Event Format (CEF) connector
B.Azure Activity Log connector
C.Azure Diagnostics connector
D.Azure Kubernetes Service (AKS) connector
Show answerAnswer
D. Azure Kubernetes Service (AKS) connector
The Azure Kubernetes Service (AKS) data connector in Microsoft Sentinel is specifically designed to ingest AKS audit logs and other security-related data from both the control plane and worker nodes, providing comprehensive visibility for AKS environments.
13. A company is implementing a zero-trust security model and needs to enforce granular access policies for administrative roles. They want to ensure that privileged users only have access to specific resources for a limited time when performing critical tasks, and their access is automatically revoked afterward. Which Azure AD PIM feature should be configured to meet this requirement?
Manage security operations
A.Access reviews
B.Self-service password reset
C.Just-in-Time (JIT) access
D.Conditional Access policies
Show answerAnswer
C. Just-in-Time (JIT) access
Just-in-Time (JIT) access, provided by Azure AD Privileged Identity Management (PIM), allows privileged roles to be activated only when needed and for a limited duration. Once the time expires, access is automatically revoked, minimizing the window of exposure for privileged accounts.
14. A global organization uses Azure Monitor to collect logs from various Azure resources and on-premises servers. They have a strict requirement to retain security-related logs for 7 years for compliance purposes. However, due to cost considerations, they want to retain performance metrics and non-security diagnostic logs for only 90 days. How can this requirement be met efficiently within a single Log Analytics workspace?
Manage security operations
A.Create separate Log Analytics workspaces for security logs and non-security logs, each with its own retention policy.
B.Export all logs to Azure Storage for long-term retention and configure different lifecycle policies in Storage.
C.Use Azure Data Explorer for security logs and Log Analytics for non-security logs.
D.Configure different retention policies for each data type in the Log Analytics workspace.
Show answerAnswer
D. Configure different retention policies for each data type in the Log Analytics workspace.
Log Analytics workspaces allow for granular control over data retention. You can configure different retention periods for specific data types within the same workspace, enabling cost optimization and compliance with varying requirements.
15. A security operations center (SOC) team uses Microsoft Sentinel for threat detection and response. They want to ensure that all security incidents generated by Sentinel are automatically forwarded to their existing third-party ITSM (IT Service Management) system for ticketing and workflow management. Which Sentinel feature should they configure to achieve this automation?
Manage security operations
A.Playbooks
B.Workbooks
C.Hunting Queries
D.Analytic Rules
Show answerAnswer
A. Playbooks
Playbooks in Microsoft Sentinel are automated response procedures built on Azure Logic Apps. They can be triggered by incidents and perform actions like sending data to external systems.
16. A security auditor needs to verify that all Azure Key Vaults in a subscription are configured to enable purge protection, which prevents immediate deletion of the vault or its contents. They want to quickly identify any non-compliant Key Vaults. Which service in Azure should the auditor use to assess this configuration against a predefined security standard?
Manage security operations
A.Azure Monitor
B.Azure Activity Log
C.Microsoft Defender for Cloud
D.Azure Network Watcher
Show answerAnswer
C. Microsoft Defender for Cloud
Microsoft Defender for Cloud (formerly Azure Security Center) provides a centralized security posture management solution. It continuously assesses Azure resources against security best practices and regulatory standards, identifying misconfigurations like missing purge protection on Key Vaults and providing recommendations for remediation.
17. A company is implementing Microsoft Defender for Cloud and needs to ensure that all Azure subscriptions within their tenant are continuously monitored for security posture, regulatory compliance, and threat protection, even newly created ones. They want to avoid manually onboarding each subscription. How should they configure Defender for Cloud to meet this requirement?
Manage security operations
A.Use Azure Policy to enforce Defender for Cloud enablement on subscriptions.
B.Onboard subscriptions through the Defender for Cloud pricing and settings blade.
C.Connect the Azure AD tenant root management group to Defender for Cloud.
D.Enable Defender for Cloud for each subscription individually.
Show answerAnswer
C. Connect the Azure AD tenant root management group to Defender for Cloud.
Connecting the Azure AD tenant root management group to Defender for Cloud ensures that all current and future subscriptions under that tenant are automatically onboarded and monitored.
18. A company uses Azure Security Center (now Microsoft Defender for Cloud) to manage its security posture. They have several Azure subscriptions and want to ensure that all virtual machines across these subscriptions are configured with a specific set of security recommendations. Which feature should they use to centrally define and apply these security recommendations?
Manage security operations
A.Azure Sentinel workbooks
B.Azure Monitor Log Analytics workspaces
C.Azure Network Watcher
D.Azure Policy
Show answerAnswer
D. Azure Policy
Azure Policy allows organizations to create, assign, and manage policies that enforce specific rules and effects over their resources, ensuring compliance with security recommendations across multiple subscriptions.
19. A security engineer is configuring Azure Monitor to detect suspicious login activities. They need to create an alert rule that triggers when more than five failed login attempts occur from the same IP address within a 10-minute window. Which type of alert rule should the engineer configure?
Manage security operations
A.Log search alert rule
B.Activity log alert rule
C.Metric alert rule
D.Application Insights alert rule
Show answerAnswer
A. Log search alert rule
To detect patterns in log data, such as multiple failed login attempts from a specific IP address within a time window, a log search alert rule is the appropriate choice. This rule type allows for custom Kusto Query Language (KQL) queries against Log Analytics workspaces.
20. A security operations center (SOC) uses Azure Sentinel for monitoring. They have configured a custom analytics rule that uses a Kusto Query Language (KQL) query to detect unusual administrative logins. This rule generates a high volume of false positives due to legitimate, but infrequent, administrative activities. Which of the following is the most effective way to reduce false positives without missing actual threats?
Manage security operations
A.Disable the analytics rule and rely on other built-in Sentinel rules.
B.Refine the KQL query to include additional filtering criteria or baselines for legitimate activity.
C.Decrease the query's lookback period to reduce the data analyzed.
D.Increase the alert threshold to require more events before triggering.
Show answerAnswer
B. Refine the KQL query to include additional filtering criteria or baselines for legitimate activity.
Refining the KQL query to incorporate additional filtering criteria, baselines, or behavioral analytics (e.g., specific source IPs for administrators, time-of-day restrictions, or known administrative jump boxes) is the most effective way to reduce false positives while maintaining detection capability for actual threats. This makes the detection logic more precise.
21. A company has implemented Microsoft Defender for Cloud for server protection. They receive an alert labeled 'High severity - Anomalous SSH activity detected on VM-Prod-01'. The security team needs to quickly understand the scope of the attack, including other potentially affected resources and the attacker's tactics, techniques, and procedures (TTPs). Where in Microsoft Defender for Cloud should they look first for this consolidated information?
Manage security operations
A.The 'Workload protections' blade, under 'Server protection'.
B.The 'Regulatory compliance' dashboard.
C.The 'Security alerts' blade, filtering for VM-Prod-01.
D.The specific alert's 'Incident' details page.
Show answerAnswer
D. The specific alert's 'Incident' details page.
In Microsoft Defender for Cloud, related alerts are grouped into security incidents. The incident details page provides a consolidated view of all related alerts, affected resources, and often includes MITRE ATT&CK TTPs, making it the ideal starting point for understanding the scope of an attack.
22. A company is using Microsoft Sentinel for SIEM and SOAR. They have configured analytic rules to detect suspicious activities. They now want to automatically enrich incidents with threat intelligence data from a third-party feed and then send a notification to a Microsoft Teams channel. Which type of automated response should they implement?
Manage security operations
A.Playbooks
B.Automation Rules
C.Hunting Queries
D.Workbooks
Show answerAnswer
A. Playbooks
Playbooks (Azure Logic Apps) are used in Sentinel for complex automated responses, including integrating with external services like threat intelligence feeds and sending notifications to platforms like Microsoft Teams.
23. A security engineer is configuring Azure Monitor to detect unusual administrative activities within their Azure subscription. They want to receive an alert whenever a 'Delete Virtual Machine' operation is initiated by any user, excluding specific automated service principals. The alert should trigger within 5 minutes of the event occurring. Which type of alert rule should be created in Azure Monitor to meet these requirements?
Manage security operations
A.Metric alert rule
B.Activity log alert rule
C.Log search alert rule
D.Smart detection alert rule
Show answerAnswer
B. Activity log alert rule
Activity log alert rules in Azure Monitor are designed to trigger alerts based on specific events in the Azure Activity Log. They are ideal for monitoring administrative operations like 'Delete Virtual Machine' and can be configured with conditions to exclude specific users or service principals.
24. A company is using Azure Monitor and Log Analytics to collect security logs from various Azure resources. They want to create a custom alert that triggers when more than 5 failed login attempts occur within a 10-minute window from the same source IP address against any virtual machine. Which component of Azure Monitor is best suited for defining and managing this type of alert?
Manage security operations
A.Azure Activity Log Alerts
B.Azure Monitor Metrics
C.Azure Monitor Workbooks
D.Log Analytics Queries (KQL) and Alert Rules
Show answerAnswer
D. Log Analytics Queries (KQL) and Alert Rules
Log Analytics queries written in KQL (Kusto Query Language) can be used to analyze log data for specific patterns, such as multiple failed logins. These queries can then be integrated into Azure Monitor alert rules to trigger notifications when the specified conditions are met.
25. A security operations team uses Azure Monitor to collect diagnostic logs from Azure Key Vault. They need to create an alert that triggers specifically when a 'SecretGet' operation fails due to insufficient permissions. This alert should contain details about the caller, the Key Vault name, and the specific secret involved. Which Kusto Query Language (KQL) operator is most effective for extracting specific fields from a log entry and then filtering based on custom criteria?
Manage security operations
A.project
B.join
C.summarize
D.parse
Show answerAnswer
A. project
The 'project' operator in KQL is used to select specific columns, rename them, or add new calculated columns to the output. This is essential for extracting relevant fields like caller, Key Vault name, and secret from the diagnostic log entry after filtering for failed 'SecretGet' operations, ensuring the alert contains the necessary details.
Microsoft Defender for Cloud enables organizations to define and assess custom regulatory compliance standards by integrating custom Azure Policy initiatives directly into its compliance dashboard.
Extends Defender for Cloud's compliance capabilities.
Integrates custom Azure Policy initiatives.
Provides unified reporting with built-in standards.
An Azure AD feature that allows for managing, controlling, and monitoring access to important resources in Azure AD, Azure, and other Microsoft Online Services.
Enables just-in-time (JIT) privileged access.
Provides time-bound access to roles, with automatic revocation.
Supports approval workflows and audit trails for privileged operations.
Azure Monitor Metric Alerts trigger when a numerical metric value, such as CPU usage or network traffic, crosses a predefined threshold for a specified period.
Monitors numerical data points collected over time.
Ideal for performance and usage monitoring.
Can aggregate data over different time granularities.
Microsoft Defender for SQL is a security offering within Microsoft Defender for Cloud that protects Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure Virtual Machines. It includes vulnerability assessment and advanced threat protection capabilities.
Protects Azure SQL Database, Managed Instance, and SQL on VMs.
Includes vulnerability assessment.
Detects SQL injection, unusual access, and other threats.
The alert details page within Microsoft Defender for Cloud provides a comprehensive breakdown of a specific security alert, offering context, affected resources, attack timeline, and recommended actions to facilitate investigation and response.
Consolidates all relevant information for a single alert.
A service in Azure that helps enforce organizational standards and assess compliance at scale. It enables you to create, assign, and manage policies that define rules for your resources.
Used for governance, compliance, and configuration management.
Can audit, deny, or modify resource creation/updates.
Supports built-in policies and custom policy definitions.
The Microsoft Sentinel Azure Kubernetes Service (AKS) data connector enables the ingestion of detailed AKS audit logs, control plane logs, and other security data into Sentinel for comprehensive threat detection and analysis.
Collects audit logs from AKS control plane.
Gathers security events from worker nodes.
Provides deep visibility into containerized environments.
Azure AD Privileged Identity Management (PIM) provides Just-in-Time (JIT) access to minimize the window of exposure for privileged roles. Users activate their roles on demand, for a specific duration, and their permissions are automatically revoked when the time expires.
Grants temporary, time-bound access to privileged roles.
Access is activated on demand by the user.
Automatically revokes access after the specified duration.
Microsoft Sentinel Playbooks are automated, orchestrated, and customizable response procedures (Azure Logic Apps) that can be triggered by incidents or alerts.
Built on Azure Logic Apps.
Automate security operations tasks.
Can interact with other Azure services and external systems via connectors.
Onboarding the Azure AD tenant root management group to Microsoft Defender for Cloud automatically enables monitoring and protection for all current and future subscriptions within that tenant.
Provides tenant-wide visibility and control.
Simplifies onboarding for large organizations.
Ensures consistent security posture across all subscriptions.
Azure Policy helps enforce organizational standards and assess compliance at scale. Through its compliance dashboard, it provides an aggregated view to evaluate the overall state of the environment, with the ability to drill down to the per-resource, per-policy, and per-assignment detail.
Enforces organizational standards.
Assesses compliance at scale.
Integrates with Azure Security Center (Microsoft Defender for Cloud).
An Azure Monitor alert rule that triggers based on the results of a Kusto Query Language (KQL) query run against log data in a Log Analytics workspace.
Used for detecting patterns, specific events, or thresholds in log data.
Requires a KQL query to define the alert condition.
Can be configured with various aggregations and time windows.
The process of improving Kusto Query Language (KQL) queries in Azure Sentinel analytics rules to enhance detection accuracy, reduce false positives, and improve performance.
Involves adding specific filters, exclusions, or behavioral baselines.
Aims to distinguish between legitimate activity and malicious behavior.
Crucial for maintaining an effective and actionable SIEM.
A feature in Microsoft Defender for Cloud (and Sentinel) that groups related security alerts into a single, comprehensive view to facilitate investigation and response.
Correlates alerts across different resources and services.
Provides a timeline of events and affected entities.
Microsoft Sentinel Playbooks, powered by Azure Logic Apps, enable Security Orchestration, Automation, and Response (SOAR) by automating complex workflows, integrating with external systems, and performing actions based on incidents.
Azure Monitor log alerts use Kusto Query Language (KQL) to evaluate resources logs at a specified frequency. If the query results indicate a specific condition, an alert is triggered, notifying users or initiating automated actions.
Uses KQL for flexible log pattern matching.
Evaluates logs from Log Analytics workspaces.
Can trigger alerts based on count, average, minimum, maximum, total, or unique count.
The Kusto Query Language (KQL) 'project' operator selects the columns to include in the output, renames columns, or adds new computed columns. It is fundamental for shaping query results to display only the relevant information needed for analysis or alerting.
An Azure Policy effect that deploys a template when a condition is met (e.g., a resource is missing a required configuration) and the resource does not exist or is not compliant.
Used for automatic remediation and configuration enforcement.
Requires a deployment template (ARM template) within the policy definition.
Ideal for ensuring baseline configurations like diagnostic settings or security features.
Azure Monitor Log Analytics workspaces serve as a central hub for collecting and analyzing operational and security logs from a wide array of Azure resources, hybrid environments, and other cloud providers. Its Kusto Query Language (KQL) enables powerful correlation and analysis for security investigations.
Centralized log collection from diverse sources.
Uses Kusto Query Language (KQL) for advanced querying.
Essential for security investigations and threat hunting.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.