Question 26

You need to complete the query for failed sign-ins to meet the technical requirements.
Where can you find the column name to complete the where clause?
  • Question 27

    You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled.
    You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1.
    What should you do first?
  • Question 28

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint You need to create a query that will link the Alertlnfo, AlertEvidence, and DeviceLogonEvents tables. The solution must return all the rows in the tables.
    Which operator should you use?
  • Question 29

    You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
    You deploy Azure Sentinel.
    You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
  • Question 30

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender 36S.
    Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD.
    You need to identify the 100 most recent sign-in attempts recorded on devices and AD DS domain controllers.
    How should you complete The KQL query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.