Question 271

You have a Microsoft Sentinel workspace named Workspace1 that is connected to the Microsoft Sentinel data lake. Workspace1 retains 12 years of historical data in the data lake tier.
You plan to run an advanced hunting query that uses join across multiple tables and directly accesses the data in the data lake.
You need to ensure that you can run the query on demand during investigations and on a schedule. The solution must ensure that the query can run asynchronously.
What should you use?
  • Question 272

    You need to use an Azure Sentinel analytics rule to search for specific criteria in Amazon Web Services (AWS) logs and to generate incidents.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
    a Microsoft 365 E5

    Question 273

    Hotspot Question
    You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains a Windows device named Device1.
    You initiate a live response session on Device1 and launch an executable file named File1.exe in the background.
    You need to perform the following actions:
    - Identify the command ID of File1.exe.
    - Interact with File1.exe.
    Which live response command should you run for each action? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 274

    You have a Microsoft 365 subscription that contains 1,000 Windows 10 devices. The devices have Microsoft Office 365 installed.
    You need to mitigate the following device threats:
    Microsoft Excel macros that download scripts from untrusted websites
    Users that open executable attachments in Microsoft Outlook
    Outlook rules and forms exploits
    What should you use?
  • Question 275

    Hotspot Question
    Your on-premises network contains 100 servers that run Windows Server.
    You have an Azure subscription that uses Microsoft Sentinel.
    You need to upload custom logs from the on-premises servers to Microsoft Sentinel.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.