Question 136

You need to configure the Azure Sentinel integration to meet the Azure Sentinel requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 137

You have a Microsoft Sentinel playbook that is triggered by using the Azure Activity connector.
You need to create a new near-real-time (NRT) analytics rule that will use the playbook.
What should you configure for the rule?
  • Question 138

    You have a Microsoft Sentinel workspace.
    You have a query named Query1 as shown in the following exhibit.

    You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1. What should you do first?
  • Question 139

    Hotspot Question
    You have an Azure subscription that uses Microsoft Sentinel and contains a user named User1.
    You need to ensure that User1 can enable User and Entity Behavior Analytics (UEBA) for entity behavior in Azure AD. The solution must use the principle of least privilege.
    Which roles should you assign to User1? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 140

    You have a Microsoft Sentinel workspace.
    You need to configure the Fusion analytics rule to temporarily supress incidents generated by a Microsoft Defender connector. The solution must meet the following requirements:
    * Minimize impact on the ability to detect multistage attacks.
    * Minimize administrative effort.
    How should you configure the rule? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.