Question 51

You need to configure the Azure Sentinel integration to meet the Azure Sentinel requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 52

You have an Azure Sentinel deployment in the East US Azure region.
You create a Log Analytics workspace named LogsWest in the West US Azure region.
You need to ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest.
What should you do first?
  • Question 53

    You need to create a query for a workbook. The query must meet the following requirements:
    List all incidents by incident number.
    Only include the most recent log for each incident.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 54

    A company uses Azure Sentinel.
    You need to create an automated threat response.
    What should you use?
  • Question 55

    You have an Azure subscription that contains a Log Analytics workspace.
    You need to enable just-in-time (JIT) VM access and network detections for Azure resources.
    Where should you enable Azure Defender?