Question 36

You have an Azure Sentinel deployment in the East US Azure region.
You create a Log Analytics workspace named LogsWest in the West US Azure region.
You need to ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest.
What should you do first?
  • Question 37

    A company uses Azure Sentinel.
    You need to create an automated threat response.
    What should you use?
  • Question 38

    You are configuring Azure Sentinel.
    You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.
    Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • Question 39

    You have an Azure Sentinel workspace.
    You need to test a playbook manually in the Azure portal.
    From where can you run the test in Azure Sentinel?
  • Question 40

    Your company uses Azure Sentinel.
    A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?