Question 31

Your company uses line-of-business apps that contain Microsoft Office VBA macros.
You plan to enable protection against downloading and running additional payloads from the Office VBA macros as additional child processes.
You need to identify which Office VBA macros might be affected.
Which two commands can you run to achieve the goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
  • Question 32

    You have a Microsoft Sentinel workspace named sws1.
    You need to create a hunting query to identify users that list storage keys of multiple Azure Storage accounts. The solution must exclude users that list storage keys for a single storage account.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 33

    You have an Azure subscription that has Azure Defender enabled for all supported resource types.
    You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution.
    To which service should you export the alerts?
  • Question 34

    You have a Microsoft 365 subscription that uses Microsoft 365 Defender and contains a user named User1.
    You are notified that the account of User1 is compromised.
    You need to review the alerts triggered on the devices to which User1 signed in.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 35

    You need to create an advanced hunting query to investigate the executive team issue.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.