Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy
A security engineer is configuring Azure Monitor to detect suspicious login activities. They need to create an alert rule that triggers when more than five failed login attempts occur from the same IP address within a 10-minute window. Which type of alert rule should the engineer configure?
- ALog search alert rule
- BActivity log alert rule
- CMetric alert rule
- DApplication Insights alert rule
Show answer & explanationAnswer & explanation
Correct answer: A. Log search alert rule
To detect patterns in log data, such as multiple failed login attempts from a specific IP address within a time window, a log search alert rule is the appropriate choice. This rule type allows for custom Kusto Query Language (KQL) queries against Log Analytics workspaces.
Why the other options are wrong
- B. Activity log alerts focus on operations performed on Azure resources, not detailed login attempts within a system.
- C. Metric alerts are based on numerical values of metrics, not patterns in log data.
- D. Application Insights alerts are specific to application performance and availability, not general security logs.
Log Search Alert Rule
An Azure Monitor alert rule that triggers based on the results of a Kusto Query Language (KQL) query run against log data in a Log Analytics workspace.
- Used for detecting patterns, specific events, or thresholds in log data.
- Requires a KQL query to define the alert condition.
- Can be configured with various aggregations and time windows.
Memory trick: MALAS: Metrics, Activity, Logs, Application, Security