Question 121

You have an Azure subscription that has Azure Defender enabled for all supported resource types.
You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution.
To which service should you export the alerts?
  • Question 122

    You need to use an Azure Resource Manager template to create a workflow automation that will trigger an automatic remediation when specific security alerts are received by Azure Security Center.
    How should you complete the portion of the template that will provision the required Azure resources? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 123

    Your on-premises network contains 100 servers that run Windows Server.
    You have an Azure subscription that uses Microsoft Sentinel.
    You need to upload custom logs from the on-premises servers to Microsoft Sentinel.
    What should you do? To answer, select the appropriate options m the answer area.

    Question 124

    You need to add notes to the events to meet the Azure Sentinel requirements.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.

    Question 125

    You have an Azure subscription.
    You need to delegate permissions to meet the following requirements:
    Enable and disable Azure Defender.
    Apply security recommendations to resource.
    The solution must use the principle of least privilege.
    Which Azure Security Center role should you use for each requirement? To answer, drag the appropriate roles to the correct requirements. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.