Question 141

You have a Microsoft 365 subscription that uses Microsoft Copilot for Security.
You create a promptbook named Book1.
For Book1, you need to create a prompt that contains an input named IncidentID.
How should you format IncidentID?
  • Question 142

    Drag and Drop Question
    You have an Azure subscription linked to an Azure Active Directory (Azure AD) tenant. The tenant contains two users named User1 and User2.
    You plan to deploy Azure Defender.
    You need to enable User1 and User2 to perform tasks at the subscription level as shown in the following table.

    The solution must use the principle of least privilege.
    Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

    Question 143

    You have an Azure Sentinel deployment.
    You need to query for all suspicious credential access activities.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Question 144

    You have an Azure subscription that has Azure Defender enabled for all supported resource types.
    You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution.
    To which service should you export the alerts?
  • Question 145

    You need to meet the Microsoft Sentinel requirements for collecting Windows Security event logs. What should you do? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point.