Question 6

You are configuring Azure Sentinel.
You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.
Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • Question 7

    From Azure Sentinel, you open the Investigation pane for a high-severity incident as shown in the following exhibit.

    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
    NOTE: Each correct selection is worth one point.

    Question 8

    You have an Azure Sentinel deployment.
    You need to query for all suspicious credential access activities.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Question 9

    You have an Azure subscription linked to an Azure Active Directory (Azure AD) tenant. The tenant contains two users named User1 and User2.
    You plan to deploy Azure Defender.
    You need to enable User1 and User2 to perform tasks at the subscription level as shown in the following table.

    The solution must use the principle of least privilege.
    Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

    Question 10

    You have a Microsoft 365 subscription that has Microsoft 365 Defender enabled.
    You need to identify all the changes made to sensitivity labels during the past seven days.
    What should you use?