Question 71

You have a Microsoft Sentinel workspace that has an Azure Active Directory (Azure AD) connector and an Office 365 connector.
From the workspace, you plan to create an analytics rule that will be based on a custom query and will run a security play.
You need to ensure that you can add the security playbook and the custom query to the rule.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 72

You have a Microsoft 365 subscription.
You identify the following data loss prevention (DLP) requirements:
Send notifications to users if they attempt to send attachments that contain EU social security numbers Prevent any email messages that contain credit card numbers from being sent outside your organization Block the external sharing of Microsoft OneDrive content that contains EU passport numbers Send administrators email alerts if any rule matches occur.
What is the minimum number of DLP policies and rules you must create to meet the requirements? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 73

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an on-premises Active Directory domain named contoso.com.
You install and run Azure AD Connect on a server named Server1 that runs Windows Server.
You need to view Azure AD Connect events.
You use the System event log on Server1.
Does that meet the goal?
  • Question 74

    Note: This question is part of a series of questions thatpresent the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a questionin this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have a Microsoft 365 subscription that contains the users shown in the following table.

    You discover that all the users in the subscription can access Compliance Manager reports.
    The Compliance Manager Reader role is not assigned to any users.
    You need to recommend a solution to prevent a user named User5 from accessing the Compliance Manager reports.
    Solution: You recommendremoving User1 from the Compliance Manager Contributor role.
    Does that meet the goal?
  • Question 75

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have a Microsoft 365 subscription that contains the users shown in the following table.

    You discover that all the users in the subscription can access Compliance Manager reports.
    The Compliance Manager Reader role is not assigned to any users.
    You need to recommend a solution to prevent a user named User5 from accessing the Compliance Manager reports.
    Solution: You recommend assigning the Compliance Manager Reader role to User5.
    Does this meet the goal?