Question 21

You deploy Azure Sentinel.
You need to implement connectors in Azure Sentinel to monitor Microsoft Teams and Linux virtual machines in Azure. The solution must minimize administrative effort.
Which data connector type should you use for each workload? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 22

Your company uses Azure Sentinel.
A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?
  • Question 23

    You plan to create a custom Azure Sentinel query that will provide a visual representation of the security alerts generated by Azure Security Center.
    You need to create a query that will be used to display a bar graph. What should you include in the query?
  • Question 24

    You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.
    What should you include in the solution? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 25

    You recently deployed Azure Sentinel.
    You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled.
    You need to ensure that the Fusion rule can generate alerts.
    What should you do?