Question 146

Your company uses Microsoft Sentinel
A new security analyst reports that she cannot assign and resolve incidents in Microsoft Sentinel.
You need to ensure that the analyst can assign and resolve incidents. The solution must use the principle of least privilege.
Which role should you assign to the analyst?
  • Question 147

    You have a Microsoft Sentinel workspace named sws1.
    You need to create a query that will detect when a user creates an unusually large numbers of Azure AD user accounts.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 148

    You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
    What should you include in the solution? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 149

    You create an Azure subscription named sub1.
    In sub1, you create a Log Analytics workspace named workspace1.
    You enable Azure Security Center and configure Security Center to use workspace1.
    You need to ensure that Security Center processes events from the Azure virtual machines that report to workspace1.
    What should you do?
  • Question 150

    You have a Microsoft Sentinel workspace.
    You receive multiple alerts for failed sign in attempts to an account.
    You identify that the alerts are false positives.
    You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements.
    * Ensure that failed sign-in alerts are generated for other accounts.
    * Minimize administrative effort
    What should do?