Question 166

You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?
  • Question 167

    You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
    What should you use?
  • Question 168

    You have a third-party security information and event management (SIEM) solution.
    You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign- events in near real time.
    What should you do to route events to the SIEM solution?
  • Question 169

    Hotspot Question
    You have a Microsoft Sentinel workspace named Workspace1 that contains a table named CommonSecurityLog.
    You ingest logs into CommonSecurityLog. CommonSecurityLog has an average log ingestion time of five minutes.
    You need to create an analytics rule that has a lookback period of seven minutes and uses the data in the CommonSecurityLog table. The solution must meet the following requirements:
    - Prevent the same event from being processed twice.
    - Minimize the number of missed events due to log ingestion delays.
    How should you complete the KQL query that defines the rule? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 170

    You have an Azure Storage account that will be accessed by multiple Azure Function apps during the development of an application.
    You need to hide Azure Defender alerts for the storage account.
    Which entity type and field should you use in a suppression rule? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.