Question 201
Hotspot Question
Your on-premises network contains a Hyper-V cluster. The cluster contains the virtual machines shown in the following table.

You have a Microsoft Sentinel workspace named SW1.
You have a data collection rule (DCR) that has the following configurations:
- Name: DCR1
- Destination: SW1
- Platform type: All
- Data collection endpoint: None
- Data source: Windows event logs, Linux syslog
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Your on-premises network contains a Hyper-V cluster. The cluster contains the virtual machines shown in the following table.

You have a Microsoft Sentinel workspace named SW1.
You have a data collection rule (DCR) that has the following configurations:
- Name: DCR1
- Destination: SW1
- Platform type: All
- Data collection endpoint: None
- Data source: Windows event logs, Linux syslog
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Question 202
You have an Azure subscription that contains the users shown in the following table.

You need to delegate the following tasks:
* Enable Microsoft Defender for Servers on virtual machines.
* Review security recommendations and enable server vulnerability scans.
The solution must use the principle of least privilege.
Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.


You need to delegate the following tasks:
* Enable Microsoft Defender for Servers on virtual machines.
* Review security recommendations and enable server vulnerability scans.
The solution must use the principle of least privilege.
Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Question 203
You need to create an advanced hunting query to i nvestigate the executive team issue.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 204
You have a Microsoft Sentinel workspace that has Microsoft Sentinel data lake enabled for long- term retention.
You have a Microsoft Security Operations Center (SOC) that uses Jupyter notebooks for advanced investigations.
You run a weekly, hypothesis-driven hunting query to detect potential lateral movement. The query looks for multiple failed sign-ins followed by a successful sign-in.
You need to offload heavy computation for the query and persist the processed results to the data lake.
What should you do?
You have a Microsoft Security Operations Center (SOC) that uses Jupyter notebooks for advanced investigations.
You run a weekly, hypothesis-driven hunting query to detect potential lateral movement. The query looks for multiple failed sign-ins followed by a successful sign-in.
You need to offload heavy computation for the query and persist the processed results to the data lake.
What should you do?
Question 205
You have a Microsoft 365 subscription that has Microsoft 365 Defender enabled.
You need to identify all the changes made to sensitivity labels during the past seven days.
What should you use?
You need to identify all the changes made to sensitivity labels during the past seven days.
What should you use?



