Question 151

You are investigating an incident in Azure Sentinel that contains more than 127 alerts.
You discover eight alerts in the incident that require further investigation.
You need to escalate the alerts to another Azure Sentinel administrator.
What should you do to provide the alerts to the administrator?
  • Question 152

    DRAG DROP
    You are investigating an incident by using Microsoft 365 Defender.
    You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop, CEOLaptop, and COOLaptop.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.
    Select and Place:

    Question 153

    You are configuring Azure Sentinel.
    You need to send a Microsoft Teams message to a channel whenever a sign-in from a suspicious IP address is detected.
    Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • Question 154

    You are informed of a new common vulnerabilities and exposures (CVE) vulnerability that affects your environment.
    You need to use Microsoft Defender Security Center to request remediation from the team responsible for the affected systems if there is a documented active exploit available.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Question 155

    You have an Azure subscription that use Microsoft Defender for Cloud and contains a user named User1.
    You need to ensure that User1 can modify Microsoft Defender for Cloud security policies. The solution must use the principle of least privilege.
    Which role should you assign to User1?