Question 31

You have a Microsoft 365 E5 subscription that uses Microsoft Defender and an Azure subscription that uses Azure Sentinel.
You need to identify all the devices that contain files in emails sent by a known malicious email sender. The query will be based on the match of the SHA256 hash.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 32

You have an Azure subscription that contains a Microsoft Sentinel workspace. The workspace contains a Microsoft Defender for Cloud data connector. You need to customize which details will be included when an alert is created for a specific event. What should you do?
  • Question 33

    You have a Microsoft 365 E5 subscription that uses Microsoft 365 Defender.
    You need to review new attack techniques discovered by Microsoft and identify vulnerable resources in the subscription. The solution must minimize administrative effort Which blade should you use in the Microsoft 365 Defender portal?
  • Question 34

    You need to use an Azure Resource Manager template to create a workflow automation that will trigger an automatic remediation when specific security alerts are received by Azure Security Center.
    How should you complete the portion of the template that will provision the required Azure resources? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 35

    Hotspot Question
    You have a Microsoft 365 subscription that uses Microsoft 365 Defender and contains a user named User1.
    You are notified that the account of User1 is compromised.
    You need to review the alerts triggered on the devices to which User1 signed in.
    How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.