Question 71

You are configuring Azure Sentinel.
You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.
Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • Question 72

    You need to create a query for a workbook. The query must meet the following requirements:
    List all incidents by incident number.
    Only include the most recent log for each incident.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 73

    You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.
    What should you recommend for each threat? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 74

    You need to configure DC1 to meet the business requirements.
    Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Question 75

    You have an Azure Sentinel deployment in the East US Azure region.
    You create a Log Analytics workspace named LogsWest in the West US Azure region.
    You need to ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest.
    What should you do first?