Question 116
You have a Microsoft 365 subscription. Auditing is enabled.
A user named User1 is a member of a dynamic security group named Group1.
You discover that User1 is no longer a member of Group1.
You need to search the audit log to identify why User1 was removed from Group1.
Which two actions should you use in the search? To answer, select the appropriate activities in the answer area.
NOTE: Each correct selection is worth one point.

A user named User1 is a member of a dynamic security group named Group1.
You discover that User1 is no longer a member of Group1.
You need to search the audit log to identify why User1 was removed from Group1.
Which two actions should you use in the search? To answer, select the appropriate activities in the answer area.
NOTE: Each correct selection is worth one point.

Question 117
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.
You receive the following alerts:
* Suspected Netlogon privilege elevation attempt
* Suspected Kerberos SPN exposure
* Suspected DCSync attack
To which stage of the cyber-attack kill chain does each alert map? To answer, drag the appropriate alerts to the correct stages. Each alert may be used once. more than once, or rot at all. You may need to drag the split bar between panes or scroll to view content

You receive the following alerts:
* Suspected Netlogon privilege elevation attempt
* Suspected Kerberos SPN exposure
* Suspected DCSync attack
To which stage of the cyber-attack kill chain does each alert map? To answer, drag the appropriate alerts to the correct stages. Each alert may be used once. more than once, or rot at all. You may need to drag the split bar between panes or scroll to view content

Question 118
You have a Microsoft 365 E5 subscription and 5,000 users.
You create several alert policies that are triggered every time activities match rules.
You need to create an alert policy that is triggered when the volume of matched activities becomes unusual.
What should you do first?
You create several alert policies that are triggered every time activities match rules.
You need to create an alert policy that is triggered when the volume of matched activities becomes unusual.
What should you do first?
Question 119
You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) connector and a Microsoft Office 365 connector.
You need to assign built-in role-based access control (RBAC) roles to achieve the following tasks:
* Create and run playbooks.
* Manage incidents.
The solution must use the principle of least privilege.
Which two roles should you assign? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
You need to assign built-in role-based access control (RBAC) roles to achieve the following tasks:
* Create and run playbooks.
* Manage incidents.
The solution must use the principle of least privilege.
Which two roles should you assign? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Question 120
You need to recommend a solution for the user administrators that meets the security requirements for auditing.
Which blade should you recommend using from the Azure Active Directory admin center?
Which blade should you recommend using from the Azure Active Directory admin center?





