Question 131

You have the resources shown in the following table.

You need to prevent duplicate events from occurring in SW1.
What should you use for each action? To answer, drag the appropriate resources to the correct actions. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Question 132

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You have a custom detection rule named Rule1 that generates an alert if more than five antivirus detections are identified on a device. Rule1 has a loopback period of 12 hours.
You need to change the loopback period to 48 hours.
What should you modify for Rule1?
  • Question 133

    You have a Microsoft 365 E5 subscription that contains a device named Device1.
    From the Microsoft Defender portal, you discover that an alert was triggered for Device1.
    From the Device inventory page, you isolate Device1.
    You need to collect a list of installed programs on Device1.
    What should you do?
  • Question 134

    You have a Microsoft Sentinel workspace named SW1.
    You need to identify which anomaly rules are enabled in SW1.
    What should you review in Microsoft Sentine1?
  • Question 135

    Hotspot Question
    You have a Microsoft 365 E5 subscription that uses Microsoft 365 Defender for Endpoint.
    You need to ensure that you can initiate remote shell connections to Windows servers by using the Microsoft 365 Defender portal.
    What should you configure? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.