Question 1

You have an Azure subscription that uses Azure Defender.
You plan to use Azure Security Center workflow automation to respond to Azure Defender threat alerts.
You need to create an Azure policy that will perform threat remediation automatically.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 2

You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
What should you use?
  • Question 3

    You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.
    What should you recommend for each threat? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 4

    You have an Azure Storage account that will be accessed by multiple Azure Function apps during the development of an application.
    You need to hide Azure Defender alerts for the storage account.
    Which entity type and field should you use in a suppression rule? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 5

    You have a Microsoft Sentinel workspace.
    You have a query named Query1 as shown in the following exhibit.

    You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1. What should you do first?