Question 116

You have 50 Microsoft Sentinel workspaces.
You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort.
Which page should you use in the Azure portal?
  • Question 117

    You create a new Azure subscription and start collecting logs for Azure Monitor.
    You need to configure Azure Security Center to detect possible threats related to sign-ins from suspicious IP addresses to Azure virtual machines. The solution must validate the configuration.
    Which three actions should you perform in a sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.

    Question 118

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The solution must ensure that you can use the results to initiate device isolation for the affected devices.
    What should you use in the Microsoft 365 Defender portal?
  • Question 119

    You purchase a Microsoft 365 subscription.
    You plan to configure Microsoft Cloud App Security.
    You need to create a custom template-based policy that detects connections to Microsoft 365 apps that originate from a botnet network.
    What should you use? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 120

    You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.
    What should you include in the solution? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.