The SOC wants detections for suspicious resource deployments on lock-lab subscriptions. What should the Azure security engineer do in Microsoft Sentinel?
Select an answer to reveal the explanation.
Short Explanation
You don’t need a KQL novel for day-one detections. Flip on a built-in analytics rule from the Azure Activity or Defender for Cloud content—scheduled or NRT—and let Sentinel create the incidents.
Full Explanation
AZ-500 expects enabling built-in Microsoft Sentinel analytics rules (scheduled or near-real-time as provided) from relevant Content Hub solutions such as Azure Activity or Microsoft Defender for Cloud. Authoring lengthy custom KQL is not the core exam skill. Disabling required ingestion or substituting Security Copilot prompts removes the analytics-rule path.