Question 96

You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?
  • Question 97

    You need to implement the Azure Information Protection requirements.
    What should you configure first?
  • Question 98

    You create a new Azure subscription and start collecting logs for Azure Monitor.
    You need to configure Azure Security Center to detect possible threats related to sign-ins from suspicious IP addresses to Azure virtual machines. The solution must validate the configuration.
    Which three actions should you perform in a sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.

    Question 99

    You have a Microsoft Sentinel workspace that contains the following incident.
    Brute force attack against Azure Portal analytics rule has been triggered.
    You need to identify the geolocation information that corresponds to the incident.
    What should you do?
  • Question 100

    Your company uses Azure Sentinel.
    A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?