nerdexam
Microsoft

AZ-500 · Question #27

You create a new Azure subscription. You need to ensure that you can create custom alert rules in Azure Security Center. Which two actions should you perform? Each correct answer presents part of…

The correct answer is D. Create an Azure Log Analytics workspace. E. Upgrade the pricing tier of Security Center to Standard. Explanation Creating custom alert rules in Azure Security Center requires two foundational components: a Log Analytics workspace (Option D) to store and query security data, and the Standard pricing tier (Option E), since custom alert rules are a premium feature not available…

Submitted by miguelv· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You create a new Azure subscription. You need to ensure that you can create custom alert rules in Azure Security Center. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AOnboard Azure Active Directory (Azure AD) Identity Protection.
  • BCreate an Azure Storage account.
  • CImplement Azure Advisor recommendations.
  • DCreate an Azure Log Analytics workspace.
  • EUpgrade the pricing tier of Security Center to Standard.

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    4% (1)
  • D
    79% (19)

Explanation

Explanation

Creating custom alert rules in Azure Security Center requires two foundational components: a Log Analytics workspace (Option D) to store and query security data, and the Standard pricing tier (Option E), since custom alert rules are a premium feature not available in the free tier. These two work together - the workspace provides the data foundation for defining custom detection logic, while the Standard tier unlocks the advanced alerting capabilities.

Why the distractors are wrong:

  • Option A (Azure AD Identity Protection) handles identity-based risk detection independently and is not a prerequisite for Security Center custom alerts.
  • Option B (Storage account) is not required for custom alert rules; Log Analytics, not Blob Storage, is the relevant data store here.
  • Option C (Azure Advisor) provides cost, performance, and reliability recommendations - it has no role in enabling Security Center alert functionality.

Memory Tip

Think "Workspace + Wallet" - you need a place to store/query the data (Log Analytics workspace) and you need to pay for the premium features (Standard tier). Custom alerts are a premium feature that requires both the infrastructure and the investment.

Topics

#Microsoft Defender for Cloud#Custom Alerts#Log Analytics#Pricing Tiers

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice