Question 186

You have a playbook in Azure Sentinel.
When you trigger the playbook, it sends an email to a distribution group.
You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
What should you do?
  • Question 187

    You have a Microsoft Sentinel workspace that uses the Microsoft 365 Defender data connector.
    From Microsoft Sentinel, you investigate a Microsoft 365 incident.
    You need to update the incident to include an alert generated by Microsoft Defender for Cloud Apps.
    What should you use?
  • Question 188

    You have an Azure subscription named Sub1 and a Microsoft 365 subscription. Sub1 is linked to an Azure Active Directory (Azure AD) tenant named contoso.com.
    You create an Azure Sentinel workspace named workspace1. In workspace1, you activate an Azure AD connector for contoso.com and an Office 365 connector for the Microsoft 365 subscription.
    You need to use the Fusion rule to detect multi-staged attacks that include suspicious sign-ins to contoso.com followed by anomalous Microsoft Office 365 activity.
    Which two actions should you perform? Each correct answer present part of the solution. create a KQL query that will i create a KQL query that will i NOTE: Each correct selection is worth one point.
  • Question 189

    You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.
    What should you include in the solution? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 190

    You have the following advanced hunting query in Microsoft 365 Defender.

    You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.