Question 61

You have a Microsoft 365 E5 subscription that uses Microsoft SharePoint Online.
You delete users from the subscription.
You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.
What should you use?
  • Question 62

    You have an Azure subscription that uses Microsoft Defender for Cloud.
    You need to configure Defender for Cloud to mitigate the following risks:
    * Vulnerabilities within the application source code
    * Exploitation toolkits in declarative templates
    * Operations from malicious IP addresses
    * Exposed secrets
    Which two Defender for Cloud services should you use? Each correct answer presents part of the solution.
    NOTE: Each correct answer is worth one point.
  • Question 63

    You have a Microsoft Sentinel workspace named Workspaces
    You configure Workspace1 to c
    ollect DNS events and deploy the Advanced Security information Model (ASIM) unifying parser for the DNS schema.
    You need to query the ASIM DNS schema to list all the DNS events from the last 24 hours that have a response code of 'NXDOMAIN' and were aggregated by the source IP address in 15-minute intervals. The solution must maximize query performance.
    How should you complete the query? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.

    Question 64

    You have a Microsoft Sentinel workspace.
    A Microsoft Sentinel incident is generated as shown in the following exhibit.

    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in [the graphic.
    NOTE: Each correct selection is worth one point.

    Question 65

    You need to recommend a solution to meet the technical requirements for the Azure virtual machines. What should you include in the recommendation?