nerdexam
Microsoft

AZ-500 · Question #339

After creating a new Azure subscription, you are tasked with making sure that custom alert rules can be created in Azure Security Center. You have created an Azure Storage account. Which of the…

The correct answer is C. You should create an Azure Log Analytics workspace. Explanation Creating an Azure Log Analytics workspace is the required prerequisite for setting up custom alert rules in Azure Security Center, because Security Center relies on Log Analytics as its underlying data store to collect, query, and analyze security telemetry…

Submitted by helene.fr· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

After creating a new Azure subscription, you are tasked with making sure that custom alert rules can be created in Azure Security Center. You have created an Azure Storage account. Which of the following is the action you should take?

Options

  • AYou should make sure that Azure Active Directory (Azure AD) Identity Protection is removed.
  • BYou should create a DLP policy.
  • CYou should create an Azure Log Analytics workspace.
  • DYou should make sure that Security Center has the necessary tier configured.

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    11% (5)
  • C
    82% (36)
  • D
    5% (2)

Explanation

Explanation

Creating an Azure Log Analytics workspace is the required prerequisite for setting up custom alert rules in Azure Security Center, because Security Center relies on Log Analytics as its underlying data store to collect, query, and analyze security telemetry - without it, custom detection rules cannot be defined or triggered.

Why the distractors are wrong:

  • Option A is incorrect because removing Azure AD Identity Protection would reduce security capabilities, not enable custom alerts in Security Center.
  • Option B is incorrect because a Data Loss Prevention (DLP) policy is used for protecting sensitive data classification, not for configuring Security Center alert rules.
  • Option D is partially relevant (the Standard/Defender tier does unlock more features), but the specific action needed to enable custom alert rules is the Log Analytics workspace - without it, even the correct tier cannot support custom alerts.

Memory Tip

Think of Log Analytics as the "brain" behind Security Center's alerts - Security Center needs somewhere to store and analyze logs before it can fire off custom alerts. No workspace = no custom rules. Remember: "Log first, Alert second."

Topics

#Microsoft Defender for Cloud#Azure Log Analytics#Custom Alert Rules#Security Monitoring

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice