Question 21
Hotspot Question
You have a Microsoft 365 E5 subscription.
You need to configure Microsoft Sentinel to collect logs from Microsoft Entra.
Which two nodes should you use in the Microsoft Defender portal? To answer, select the appropriate nodes in the answer area.
NOTE: Each correct answer is worth one point.

You have a Microsoft 365 E5 subscription.
You need to configure Microsoft Sentinel to collect logs from Microsoft Entra.
Which two nodes should you use in the Microsoft Defender portal? To answer, select the appropriate nodes in the answer area.
NOTE: Each correct answer is worth one point.

Question 22
Hotspot Question
You have a custom detection rule that includes the following KQL query.

For each of the following statements, select Yes if True. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have a custom detection rule that includes the following KQL query.

For each of the following statements, select Yes if True. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Question 23
Hotspot Question
You have a Microsoft Sentinel workspace named Workspace1 that contains a table named CommonSecurityLog.
You ingest logs into CommonSecurityLog. CommonSecurityLog has an average log ingestion time of five minutes.
You need to create an analytics rule that has a lookback period of seven minutes and uses the data in the CommonSecurityLog table. The solution must meet the following requirements:
- Prevent the same event from being processed twice.
- Minimize the number of missed events due to log ingestion delays.
How should you complete the KQL query that defines the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft Sentinel workspace named Workspace1 that contains a table named CommonSecurityLog.
You ingest logs into CommonSecurityLog. CommonSecurityLog has an average log ingestion time of five minutes.
You need to create an analytics rule that has a lookback period of seven minutes and uses the data in the CommonSecurityLog table. The solution must meet the following requirements:
- Prevent the same event from being processed twice.
- Minimize the number of missed events due to log ingestion delays.
How should you complete the KQL query that defines the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 24
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You are investigating an incident.
You need to review the incident tasks that were performed. The solution must include a query that will display the incidents in a workbook, and then display the tasks of each incident in another grid.
Which table should you target in the query?
You are investigating an incident.
You need to review the incident tasks that were performed. The solution must include a query that will display the incidents in a workbook, and then display the tasks of each incident in another grid.
Which table should you target in the query?
Question 25
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You have a Microsoft Sentinel workspace.
Microsoft Sentinel connectors are configured as shown in the following table.

You use Microsoft Sentinel to investigate suspicious Microsoft Graph API activity related to Conditional Access policies. You need to search for the following activities:
* Downloads of the Conditional Access policies by using PowerShell
* Updates to the Conditional Access policies by using the Microsoft Entra admin center Which tables should you query for each activity? lo answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft Sentinel workspace.
Microsoft Sentinel connectors are configured as shown in the following table.

You use Microsoft Sentinel to investigate suspicious Microsoft Graph API activity related to Conditional Access policies. You need to search for the following activities:
* Downloads of the Conditional Access policies by using PowerShell
* Updates to the Conditional Access policies by using the Microsoft Entra admin center Which tables should you query for each activity? lo answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.






