Question 136

You need to create an advanced hunting query to investigate the executive team issue.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 137

You need to remediate active attacks to meet the technical requirements.
What should you include in the solution?
  • Question 138

    You need to add notes to the events to meet the Azure Sentinel requirements.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.

    Question 139

    You use Azure Sentinel to monitor irregular Azure activity.
    You create custom analytics rules to detect threats as shown in the following exhibit.

    You do NOT define any incident settings as part of the rule definition.
    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
    NOTE: Each correct selection is worth one point.

    Question 140

    You use Azure Defender.
    You have an Azure Storage account that contains sensitive information.
    You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.