Question 46

You need to remediate active attacks to meet the technical requirements.
What should you include in the solution?
  • Question 47

    Your company uses Azure Security Center and Azure Defender.
    The security operations team at the company informs you that it does NOT receive email notifications for security alerts.
    What should you configure in Security Center to enable the email notifications?
  • Question 48

    You need to visualize Microsoft Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
    What should you use?
  • Question 49

    Hotspot Question
    You have a Microsoft Sentinel workspace.
    You need to configure the Fusion analytics rule to temporarily suppress incidents generated by a Microsoft Defender connector. The solution must meet the following requirements:
    - Minimize impact on the ability to detect multistage attacks.
    - Minimize administrative effort.
    How should you configure the rule? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 50

    You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server.
    You need to configure Defender for Cloud to collect event data from the virtual machines. The solution must minimize administrative effort and costs.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.