QuestionQ54

Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

HOTSPOT -

You have an Azure subscription containing the resources shown in the following table.

Question Image

VM1 and VM2 are stopped.

You create an alert rule with these settings:

  • Resource: RG1
  • Condition: All Administrative operations
  • Actions: Action groups configured for this alert rule: ActionGroup1
  • Alert rule name: Alert1

You create an action rule with these settings:

  • Scope: VM1
  • Filter criteria: Resource Type = "Virtual Machines"
  • Define on this scope: Suppression
  • Suppression config: From now (always)
  • Name: ActionRule1

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Yes or No
StatementsYesNo
If you start VM1, an alert is triggered.
If you start VM2, an alert is triggered.
If you add a tag to RG1, an alert is triggered.
Explanation

Administrative Activity Log events include Resource Manager create, update, delete, and action operations. Starting either virtual machine and updating RG1 by adding a tag meet the activity-log alert condition within RG1. The always-on suppression rule applies only to alerts for VM1 and removes their action groups; it does not stop the fired alert from being visible or created.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!