exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 4 question 104 discussion

Actual exam question from Microsoft's AZ-500
Question #: 104
Topic #: 4
[All AZ-500 Questions]

HOTSPOT
-

On Monday, you configure an email notification in Microsoft Defender for Cloud to notify [email protected] about alerts that have a severity level of Low, Medium, or High.

On Tuesday, Microsoft Defender for Cloud generates the security alerts shown in the following table.



How many email notifications will [email protected] receive on Tuesday? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alexbz
Highly Voted 1 year, 9 months ago
Given answer is correct. To avoid alert fatigue, Defender for Cloud limits the volume of outgoing mails. For each subscription, Defender for Cloud sends: approximately four emails per day for high-severity alerts approximately two emails per day for medium-severity alerts approximately one email per day for low-severity alerts https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications
upvoted 16 times
[Removed]
8 months, 3 weeks ago
With this, 3 and 7 shall be the answer.
upvoted 2 times
...
Ofenomeno
1 year, 8 months ago
so 3 and 7 then, not 4 and 7 as total is already reached before the 4rth rdp alert at 16:01
upvoted 9 times
Nava702
1 year ago
The first RDP alert is Medium severity. So it's 4
upvoted 1 times
...
...
...
wingcheuk
Highly Voted 1 year, 3 months ago
High-severity alerts: 01:01 - Successful RDP brute force attack 06:10 - Suspicious process executed 09:00 - Malicious SQL activity 13:30 - Suspicious process executed 16:01 - Successful RDP brute force attack 23:25 - Modified system binary discovered in dump file 23:30 - Malicious SQL activity RDP related: 2 Overall: 4 (due to the limit) Medium-severity alerts: 01:00 - Failed RDP brute force attack 14:00 - Failed RDP brute force attack RDP related: 2 Overall: 2 Low-severity alerts: 11:15 - Network communication with a malicious machine detected 23:20 - Possible outgoing spam activity detected RDP related: 0 Overall: 1 (due to the limit) So the answer is: RDP = 2 + 2 + 0 = 4 Overall = 4 + 2 +1 = 7
upvoted 9 times
...
Sabr_
Most Recent 2 weeks, 3 days ago
Exam question 6th April 2025
upvoted 1 times
...
epomatti
1 year, 3 months ago
Box1: 4 Box2: 7
upvoted 1 times
...
OrangeSG
1 year, 5 months ago
Refer to screenshot of Configure email notifications (URL below): You will receive a maximum of one email per 6 hours for high-severity alerts, one email per 12 hours for medium- severity alerts, and one email per 24 hours for low-severity alerts. https://learn.microsoft.com/en-us/azure/defender-for-cloud/media/configure-email-notifications/email-notification-settings.png Answer: Box 1: 4 Box 2: 7
upvoted 3 times
Mnguyen0503
1 year, 3 months ago
Based on the logic you provided, we only receive a high alert every 6 hours and a medium alert every 12 hours. Starting at 0:00 till 6:00 you get 1 high and 1 med alert for RDP. After 12:00, since the suspicious activity alert fired first at 13:30, it raises a high alert already, leaving only 1 med alert available for use by RDP event. The high alert RDP won't fire between 12:00 and 18:00. So the answer is 3 and 7.
upvoted 1 times
...
...
TheProfessor
1 year, 6 months ago
Based on this- https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications, the answer should be 3 and 7
upvoted 2 times
...
Catlyn
1 year, 6 months ago
In exam aug,2023
upvoted 3 times
...
BooMz
1 year, 8 months ago
Shouldn't the answer be 3 and 7? High alert email has already been used up (4) times on 13:30, making 16:01 not being sent out.
upvoted 6 times
...
kuskumar
1 year, 9 months ago
3 and 7
upvoted 4 times
...
erikdran
1 year, 10 months ago
I think 11 in box 2. Because it's all alerts including bruteforce alerts?
upvoted 1 times
bohneee
1 year, 1 month ago
there is something called "avoiding alert fatigue" (https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications)
upvoted 1 times
...
...
billo79152718
1 year, 11 months ago
Repeat. Box1: 4 Box2: 7 Is correct.
upvoted 9 times
billo79152718
1 year, 11 months ago
Same as question 56. Just updated with MD instead of Security Center
upvoted 2 times
...
TheProfessor
1 year, 6 months ago
Based on this- https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications, the answer should be 3 and 7
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago