nerdexam
MicrosoftMicrosoft

AZ-500 · Question #28

AZ-500 Question #28: Real Exam Question with Answer & Explanation

Sign in or unlock AZ-500 to reveal the answer and full explanation for question #28. The question stem and answer options stay visible for context.

Submitted by klara.se· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure subscription named Sub1 that contains an Azure Log Analytics workspace named LAW1. You have 100 on-premises servers that run Windows Server 2012 R2 and Windows Server 2016. The servers connect to LAW1. LAW1 is configured to collect security-related performance counters from the connected servers. You need to configure alerts based on the data collected by LAW1. The solution must meet the following requirements: - Alert rules must support dimensions. - The time it takes to generate an alert must be minimized. - Alert notifications must be generated only once when the alert is generated and once when the alert is resolved. Which signal type should you use when you create the alert rules?

Options

  • ALog
  • BLog (Saved Query)
  • CMetric
  • DActivity Log

Unlock AZ-500 to see the answer

You've previewed enough free AZ-500 questions. Unlock AZ-500 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Azure Monitor Alerts#Metric Alerts#Log Analytics#Performance Counters
Full AZ-500 PracticeBrowse All AZ-500 Questions