Question 51

Your company wants to optimize using Microsoft Defender for Endpoint to protect its resources against ransomware based on Microsoft Security Best Practices.
You need to prepare a post-breach response plan for compromised computers based on the Microsoft Detection and Response Team (DART) approach in Microsoft Security Best Practices.
What should you include in the response plan?
  • Question 52

    You need to design a solution to provide administrators with secure remote access to the virtual machines. The solution must meet the following requirements:
    * Prevent the need to enable ports 3389 and 22 from the internet.
    * Only provide permission to connect the virtual machines when required.
    * Ensure that administrators use the Azure portal to connect to the virtual machines.
    Which two actions should you include in the solution? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
  • Question 53

    You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance. You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance.
    Solution: You recommend access restrictions based on HTTP headers that have the Front Door ID.
    Does this meet the goal?
  • Question 54

    Your company is migrating data to Azure. The data contains Personally Identifiable Information (Pll). The company plans to use Microsoft Information Protection for the Pll data store in Azure. You need to recommend a solution to discover Pll data at risk in the Azure resources.
    What should you include in the recommendation? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 55

    You have an Azure AD tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Azure AD tenant and are managed by using Microsoft Intune.
    You are designing a privileged access strategy based on the rapid modernization plan (RaMP). The strategy will include the following configurations:
    * Each user in Group1 will be assigned a Windows 11 device that will be configured as a privileged access device.
    * The Security Administrator role will be mapped to the privileged access security level.
    * The users in Group1 will be assigned the Security Administrator role.
    * The users in Group2 will manage the privileged access devices.
    You need to configure the local Administrators group for each privileged access device. The solution must follow the principle of least privilege.
    What should you include in the solution?