Question 26

Your company stores the data for every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant.
Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription.
You deploy Azure Sentinel to a new Azure subscription.
You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • Question 27

    You plan to create a custom Azure Sentinel query that will track anomalous Azure Active Directory (Azure AD) sign-in activity and present the activity as a time chart aggregated by day.
    You need to create a query that will be used to display the time chart.
    What should you include in the query?
  • Question 28

    Your company uses Azure Sentinel.
    A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel.
    You need to resolve the issue for the analyst. The solution must use the principle of least privilege.
    Which role should you assign to the analyst?
  • Question 29

    You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
    What should you use?
  • Question 30

    The issue for which team can be resolved by using Microsoft Defender for Endpoint?