Question 6

You use Azure Defender.
You have an Azure Storage account that contains sensitive information.
You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • Question 7

    You plan to create a custom Azure Sentinel query that will track anomalous Azure Active Directory (Azure AD) sign-in activity and present the activity as a time chart aggregated by day.
    You need to create a query that will be used to display the time chart.
    What should you include in the query?
  • Question 8

    You need to modify the anomaly detection policy settings to meet the Cloud App Security requirements. Which policy should you modify?
  • Question 9

    You receive a security bulletin about a potential attack that uses an image file.
    You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent the attack.
    Which indicator type should you use?
  • Question 10

    You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.
    What should you recommend for each threat? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.