nerdexam
MicrosoftMicrosoft

AZ-500 · Question #460

AZ-500 Question #460: Real Exam Question with Answer & Explanation

This question tests understanding of Microsoft Defender for Cloud's email notification throttling behavior, specifically how many emails are sent per alert severity level per day.

Submitted by weili_xi· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

Hotspot Question On Monday, you configure an email notification in Microsoft Defender for Cloud to notify [email protected] about alerts that have a severity level of Low, Medium, or High. On Tuesday, Microsoft Defender for Cloud generates the security alerts shown in the following table. How many email notifications will [email protected] receive on Tuesday? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Options

  • __typehotspot
  • variantdropdown

Explanation

This question tests understanding of Microsoft Defender for Cloud's email notification throttling behavior, specifically how many emails are sent per alert severity level per day.

Approach. Microsoft Defender for Cloud throttles email notifications to prevent alert fatigue. It sends a maximum of one email notification per severity level per day, regardless of how many alerts of that severity are generated. If the table shows alerts of Low, Medium, and High severity on Tuesday, [email protected] would receive at most 3 emails total (one per severity level). However, since the exact table is not visible here, the key rule is: count the number of distinct severity levels (Low, Medium, High) that have at least one alert generated - that equals the number of emails received, capped at one email per severity per day. For example, if all three severity levels had alerts triggered, the answer would be 3 emails.

Concept tested. Microsoft Defender for Cloud email notification throttling - the platform limits email alerts to one notification per severity level (Low, Medium, High) per 24-hour period to avoid overwhelming recipients, regardless of the total number of individual alerts generated within that severity.

Reference. https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications

Topics

#Microsoft Defender for Cloud#security alerts#email notifications#alert severity

Community Discussion

No community discussion yet for this question.

Full AZ-500 PracticeBrowse All AZ-500 Questions