Question 216

You have a Microsoft Sentinel workspace.
You have a query named Query1 as shown in the following exhibit.

You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1. What should you do first?
  • Question 217

    You have a Microsoft 365 E5 subscription.
    You plan to perform cross-domain investigations by using Microsoft 365 Defender.
    You need to create an advanced hunting query to identify devices affected by a malicious email attachment.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 218

    You are investigating an incident by using Microsoft 365 Defender.
    You need to create an advanced hunting query to detect failed sign-in authentications on three devices named CFOLaptop, CEOLaptop, and COOLaptop.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 219

    You have an Azure subscription.
    You need to delegate permissions to meet the following requirements:
    Enable and disable Azure Defender.
    Apply security recommendations to resource.
    The solution must use the principle of least privilege.
    Which Azure Security Center role should you use for each requirement? To answer, drag the appropriate roles to the correct requirements. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    Question 220

    You need to configure the Azure Sentinel integration to meet the Azure Sentinel requirements.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.