Question 156

Your company deploys the following services:
* Microsoft Defender for Identity
* Microsoft Defender for Endpoint
* Microsoft Defender for Office 365
You need to provide a security analyst with the ability to use the Microsoft 365 security center. The analyst must be able to approve and reject pending actions generated by Microsoft Defender for Endpoint. The solution must use the principle of least privilege.
Which two roles should assign to the analyst? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • Question 157

    You have an Azure Sentinel deployment.
    You need to query for all suspicious credential access activities.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Question 158

    The issue for which team can be resolved by using Microsoft Defender for Endpoint?
  • Question 159

    You are investigating an incident by using Microsoft 365 Defender.
    You need to create an advanced hunting query to detect failed sign-in authentications on three devices named CFOLaptop, CEOLaptop, and COOLaptop.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 160

    You have a Microsoft 365 subscription that uses Microsoft Purview and Microsoft Teams.
    You have a team named Team1 that has a project named Project 1.
    You need to identify any Project1 files that were stored on the team site of Team1 between February 1, 2023, and February 10, 2023.
    Which KQL query should you run?