Question 131

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.
You need to add threat indicators for all the IP addresses in a range of 171.23.3432-171.2334.63. The solution must minimize administrative effort.
What should you do in the Microsoft 365 Defender portal?
  • Question 132

    You have a Microsoft Sentinel workspace.
    You have a query named Query1 as shown in the following exhibit.

    You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1. What should you do first?
  • Question 133

    You have an Azure subscription that has Azure Defender enabled for all supported resource types.
    You create an Azure logic app named LA1.
    You plan to use LA1 to automatically remediate security risks detected in Defenders for Cloud.
    You need to test LA1 in Defender for Cloud.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 134

    You receive an alert from Azure Defender for Key Vault.
    You discover that the alert is generated from multiple suspicious IP addresses.
    You need to reduce the potential of Key Vault secrets being leaked while you investigate the issue. The solution must be implemented as soon as possible and must minimize the impact on legitimate users.
    What should you do first?
  • Question 135

    DRAG DROP
    You are informed of a new common vulnerabilities and exposures (CVE) vulnerability that affects your environment.
    You need to use Microsoft Defender Security Center to request remediation from the team responsible for the affected systems if there is a documented active exploit available.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
    Select and Place: