Question 21

You create a custom analytics rule to detect threats in Azure Sentinel.
You discover that the rule fails intermittently.
What are two possible causes of the failures? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • Question 22

    Your company uses line-of-business apps that contain Microsoft Office VBA macros.
    You plan to enable protection against downloading and running additional payloads from the Office VBA macros as additional child processes.
    You need to identify which Office VBA macros might be affected.
    Which two commands can you run to achieve the goal? Each correct answer presents a complete solution.
    NOTE: Each correct selection is worth one point.
  • Question 23

    A company uses Azure Sentinel.
    You need to create an automated threat response.
    What should you use?
  • Question 24

    You need to remediate active attacks to meet the technical requirements.
    What should you include in the solution?
  • Question 25

    You deploy Azure Sentinel.
    You need to implement connectors in Azure Sentinel to monitor Microsoft Teams and Linux virtual machines in Azure. The solution must minimize administrative effort.
    Which data connector type should you use for each workload? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.