After creating an Azure subscription and an Azure Storage account, what additional action is required to enable creation of custom alert rules in Azure Security Center?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Azure Log Analytics workspace..
Why this is the answer
To create custom alert rules in Azure Security Center (now Microsoft Defender for Cloud), you need an Azure Log Analytics workspace. This workspace acts as a central repository for logs and data collected by Defender for Cloud, including security events. Custom alert rules are built upon queries against this collected data. Without a Log Analytics workspace, Defender for Cloud cannot store the necessary data to evaluate your custom alert conditions. Removing Azure Active Directory Identity Protection is irrelevant. Creating a DLP policy is for data governance, not custom security alerts. While having the appropriate Defender for Cloud tier is necessary for advanced features, a Log Analytics workspace is a fundamental prerequisite for custom alert rule creation itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed