MicrosoftMicrosoft Azure Solutions Architect Expert AZ-305 Certification ·EN ·Updated 10 Aug 2026

A SOC team needs to detect risky sign-in behaviors (such as impossible travel) based on Azure AD sign-in logs and Microsoft 365 audit data, and to correlate endpoint alerts from Microsoft Defender for Endpoint. When a high-fidelity alert fires, the account should be disabled automatically and a ServiceNow incident opened. You are designing Microsoft Sentinel for this scenario. Which two configurations should you implement? Each correct answer presents part of the solution.

Choose an answer

Tap an option to check your answer.

Pass your exam — without the endless answer hunt

Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.

Pass your exam faster No card needed
✓ Verified by ExamRoll editorial · Updated 10 August 2026
All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product