Question 86

You use Microsoft Sentinel.
You need to receive an alert in near real-time whenever Azure Storage account keys are enumerated. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point
  • Question 87

    Hotspot Question
    You have an Azure subscription that uses Microsoft Defender for Cloud.
    You need to use an Azure Resource Manager (ARM) template to create a workflow automation that will trigger a logic app when specific alerts are received by Microsoft Defender for Cloud.
    How should you complete the template? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 88

    You deploy Azure Sentinel.
    You need to implement connectors in Azure Sentinel to monitor Microsoft Teams and Linux virtual machines in Azure. The solution must minimize administrative effort.
    Which data connector type should you use for each workload? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 89

    You have a Microsoft Sentinel workspace.
    You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant:
    * App name: App1
    * IP address: 192.168.1.2
    * Computer name: Device1
    * Used client app: Microsoft Edge
    * Email address: [email protected]
    * Sign-in URL: https://www.company.com
    Which entities can be investigated by using UEBA?
  • Question 90

    You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.
    What should you recommend for each threat? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.