Question 176
You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 177
You have an Azure subscription. The subscription contains 10 virtual machines that are onboarded to Microsoft Defender for Cloud.
You need to ensure that when Defender for Cloud detects digital currency mining behavior on a virtual machine, you receive an email notification. The solution must generate a test email.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You need to ensure that when Defender for Cloud detects digital currency mining behavior on a virtual machine, you receive an email notification. The solution must generate a test email.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question 178
You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 179
Hotspot Question
You have a Microsoft Sentinel workspace that is connected to the Microsoft Sentinel data lake.
Newly ingested data can take up to 15 minutes to become queryable in the data lake.
You need to schedule a KQL job that runs daily at 12:10 AM and populates a summary table used by threat hunters. The solution must meet the following requirements:
- Each run must query a fixed 24-hour window that ends 15 minutes
before the job runtime.
- Double-counting must be prevented across the daily runs.
- late-arriving records must be included in the summary.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft Sentinel workspace that is connected to the Microsoft Sentinel data lake.
Newly ingested data can take up to 15 minutes to become queryable in the data lake.
You need to schedule a KQL job that runs daily at 12:10 AM and populates a summary table used by threat hunters. The solution must meet the following requirements:
- Each run must query a fixed 24-hour window that ends 15 minutes
before the job runtime.
- Double-counting must be prevented across the daily runs.
- late-arriving records must be included in the summary.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 180
You are investigating a potential attack that deploys a new ransomware strain.
You plan to perform automated actions on a group of highly valuable machines that contain sensitive information.
You have three custom device groups.
You need to be able to temporarily group the machines to perform actions on the devices. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You plan to perform automated actions on a group of highly valuable machines that contain sensitive information.
You have three custom device groups.
You need to be able to temporarily group the machines to perform actions on the devices. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.






