Microsoft Azure Security Engineer Certification Azure Security Operations and Monitoring 1 — Questions and Answers
Question 1: What is Microsoft Sentinel primarily classified as in the security operations space?
- Vulnerability scanner and patch manager
- Cloud-native SIEM and SOAR platform (Correct answer)
- Identity governance and access management tool
- Network firewall and DDoS protection service
Correct answer: Cloud-native SIEM and SOAR platform
Microsoft Sentinel is a cloud-native Security Information and Event Management and Security Orchestration, Automation, and Response platform.
Question 2: What is the role of Microsoft Sentinel data connectors?
- Define detection rule logic in KQL
- Ingest security logs from Microsoft and third-party sources into the workspace (Correct answer)
- Deploy Azure Firewall policies to connected subscriptions
- Synchronize threat intelligence feeds only
Correct answer: Ingest security logs from Microsoft and third-party sources into the workspace
Data connectors pull log data from sources such as Azure AD, Microsoft Defender, Syslog, and third-party security products into Sentinel.
Question 3: Which Microsoft Sentinel component contains KQL-based detection logic that runs on a schedule and generates alerts when triggered?
- Workbooks
- Analytics rules (Correct answer)
- Playbooks
- Hunting queries
Correct answer: Analytics rules
Scheduled analytics rules run KQL queries against ingested data at defined intervals and create incidents when the query returns results.
Question 4: What technology underpins a Microsoft Sentinel playbook that automates incident response actions?
- Azure Functions with HTTP triggers
- Azure Logic Apps with Sentinel connectors (Correct answer)
- PowerShell runbooks in Azure Automation
- GitHub Actions workflows
Correct answer: Azure Logic Apps with Sentinel connectors
Sentinel playbooks are Azure Logic Apps that can be triggered automatically by automation rules or manually from an incident.
Question 5: Which Microsoft Defender for Cloud workload protection plan provides threat detection and EDR integration for Azure and on-premises VMs?
- Defender for Containers
- Defender for Storage
- Defender for Servers (Correct answer)
- Defender for Key Vault
Correct answer: Defender for Servers
Microsoft Defender for Servers provides behavioral analytics, threat detection, and Microsoft Defender for Endpoint EDR integration for VMs.
Question 6: What does the Secure Score in Microsoft Defender for Cloud represent?
- A DDoS attack risk probability rating
- A percentage reflecting how many security recommendations have been implemented (Correct answer)
- An industry compliance certification status
- A threat intelligence confidence level for alerts
Correct answer: A percentage reflecting how many security recommendations have been implemented
Secure Score aggregates the results of all security assessments into a single percentage showing your overall security posture.
What is Microsoft Sentinel primarily classified as in the security operations space?