Question 96

You need to implement the Microsoft Sentinel NRT rule for monitoring the designated break glass account.
The solution must meet the Microsoft Sentinel requirements.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 97

You purchase a Microsoft 365 subscription.
You plan to configure Microsoft Cloud App Security.
You need to create a custom template-based policy that detects connections to Microsoft 365 apps that originate from a botnet network.
What should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 98

You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365.
You need to ensure that you can investigate threats by using data in the unified audit log of Microsoft Defender for Cloud Apps.
What should you configure first?
  • Question 99

    Hotspot Question
    You have an Azure subscription that has Microsoft Defender for Cloud enabled for all supported resource types.
    You create an Azure logic app named LA1.
    You plan to use LA1 to automatically remediate security risks detected in Defender for Cloud.
    You need to test LA1 in Defender for Cloud.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 100

    You have an Azure subscription that uses Microsoft Sentinel and contains 100 Linux virtual machines.
    You need to monitor the virtual machines by using Microsoft Sentinel. The solution must meet the fallowing requirements:
    * Minimize administrative effort
    * Minimize the parsing required to read log data
    What should you configure?