Question 206

You have an Azure Sentinel deployment.
You need to query for all suspicious credential access activities.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question 207

You have a Microsoft Sentinel workspace named Workspaces
You configure Workspace1 to c
ollect DNS events and deploy the Advanced Security information Model (ASIM) unifying parser for the DNS schema.
You need to query the ASIM DNS schema to list all the DNS events from the last 24 hours that have a response code of 'NXDOMAIN' and were aggregated by the source IP address in 15-minute intervals. The solution must maximize query performance.
How should you complete the query? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.

Question 208

You need to identify which mean time metrics to use to meet the Microsoft Sentinel requirements. Which workbook should you use?
  • Question 209

    You have an Azure subscription that contains the users shown in the following table.

    You need to delegate the following tasks:
    * Enable Microsoft Defender for Servers on virtual machines.
    * Review security recommendations and enable server vulnerability scans.
    The solution must use the principle of least privilege.
    Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    Question 210

    You have a Microsoft 365 subscription that uses Microsoft 365 Defender and contains a user named User1.
    You are notified that the account of User1 is compromised.
    You need to review the alerts triggered on the devices to which User1 signed in.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.