Question 116

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You have a Microsoft Sentinel workspace.
Microsoft Sentinel connectors are configured as shown in the following table.

You use Microsoft Sentinel to investigate suspicious Microsoft Graph API activity related to Conditional Access policies. You need to search for the following activities:
* Downloads of the Conditional Access policies by using PowerShell
* Updates to the Conditional Access policies by using the Microsoft Entra admin center Which tables should you query for each activity? lo answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 117

You have a Microsoft 365 E5 subscription.
You plan to perform cross-domain investigations by using Microsoft 365 Defender.
You need to create an advanced hunting query to identify devices affected by a malicious email attachment.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 118

You have a Microsoft 365 B5 subscription that uses Microsoft Defender XDR. You are investigating an incident You need to review the incident tasks that were performed. What can you use on the Incident page?
  • Question 119

    Hotspot Question
    You have an Azure subscription that contains a Microsoft Sentinel workspace.
    You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:
    - Identifies an anomalous number of changes to the rules of a network
    security group (NSG) made by the same security principal.
    - Automatically associates the security principal with a Microsoft
    Sentinel entity.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 120

    You have a Microsoft Sentinel workspace.
    You need to configure the Fusion analytics rule to temporarily supress incidents generated by a Microsoft Defender connector. The solution must meet the following requirements:
    * Minimize impact on the ability to detect multistage attacks.
    * Minimize administrative effort.
    How should you configure the rule? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.