Question 11

You use Azure Sentinel to monitor irregular Azure activity.
You create custom analytics rules to detect threats as shown in the following exhibit.

You do NOT define any incident settings as part of the rule definition.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Question 12

The issue for which team can be resolved by using Microsoft Defender for Office 365?
  • Question 13

    You use Azure Defender.
    You have an Azure Storage account that contains sensitive information.
    You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • Question 14

    You need to assign a role-based access control (RBAC) role to admin1 to meet the Azure Sentinel requirements and the business requirements.
    Which role should you assign?
  • Question 15

    You need to create an advanced hunting query to investigate the executive team issue.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.