Question 16

You purchase a Microsoft 365 subscription.
You plan to configure Microsoft Cloud App Security.
You need to create a custom template-based policy that detects connections to Microsoft 365 apps that originate from a botnet network.
What should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 17

You need to implement the Azure Information Protection requirements. What should you configure first?
  • Question 18

    You are investigating a potential attack that deploys a new ransomware strain.
    You plan to perform automated actions on a group of highly valuable machines that contain sensitive information.
    You have three custom device groups.
    You need to be able to temporarily group the machines to perform actions on the devices. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
  • Question 19

    You are responsible for responding to Azure Defender for Key Vault alerts.
    During an investigation of an alert, you discover unauthorized attempts to access a key vault from a Tor exit node.
    What should you configure to mitigate the threat?
  • Question 20

    You have a custom analytics rule to detect threats in Azure Sentinel.
    You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED.
    What is a possible cause of the issue?