Topic 3: Misc. Questions
You have a custom analytics rule to detect threats in Azure Sentinel.
You discover that the analytics rule stopped running. The rule was disabled, and the rule
name has a prefix of AUTO DISABLED.
What is a possible cause of the issue?
A.
There are connectivity issues between the data sources and Log Analytics.
B.
The number of alerts exceeded 10,000 within two minutes.
C.
The rule query takes too long to run and times out.
D.
Permissions to one of the data sources of the rule query were modified
Permissions to one of the data sources of the rule query were modified
You have an Azure subscription that uses Microsoft Defender for Cloud and contains a
storage account named storage1. You receive an alert that there was an unusually high
volume of delete operations on the blobs in storage1.
You need to identify which blobs were deleted.
What should you review?
A.
the Azure Storage Analytics logs
B.
the activity logs of storage1
C.
the alert details
D.
the related entities of the alert
the activity logs of storage1
You have an Azure subscription that uses Microsoft Sentinel.
You need to create a custom report that will visualise sign-in information over time.
What should you create first?
A.
a workbook
B.
a hunting query
C.
a notebook
D.
a playbook
a workbook
Explanation:
A workbook is a data-driven interactive report in Microsoft Sentinel. You can use
workbooks to create custom reports based on data from your Azure subscription.
Reference: https://docs.microsoft.com/en-us/azure/sentinel/workbooks-overview
You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the
rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?
A.
Disable, and then enable the rule.
B.
Add data connectors
C.
Create a new machine learning analytics rule
D.
Add a hunting bookmark.
Add data connectors
Your company stores the data for every project in a different Azure subscription. All the
subscriptions use the same Azure Active Directory (Azure AD) tenant.
Every project consists of multiple Azure virtual machines that run Windows Server. The
Windows events of the virtual machines are stored in a Log Analytics workspace in each
machine’s respective subscription.
You deploy Azure Sentinel to a new Azure subscription.
You need to perform hunting queries in Azure Sentinel to search across all the Log
Analytics workspaces of all the subscriptions.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A.
Add the Security Events connector to the Azure Sentinel workspace.
B.
Create a query that uses the workspace expression and the union operator.
C.
Use the alias statement.
D.
Create a query that uses the resource expression and the alias operator.
E.
Add the Azure Sentinel solution to each workspace.
Create a query that uses the workspace expression and the union operator.
Add the Azure Sentinel solution to each workspace.
You have a Microsoft 365 subscription that uses Microsoft 365 Defender A remediation
action for an automated investigation quarantines a file across multiple devices. You need
to mark the file as safe and remove the file from quarantine on the devices. What should
you use m the Microsoft 365 Defender portal?
A.
From Threat tracker, review the queries.
B.
From the History tab in the Action center, revert the actions
C.
From the investigation page, review the AIR processes.
D.
From Quarantine from the Review page, modify the rules.
From the History tab in the Action center, revert the actions
You have an Azure Sentinel workspace.
You need to test a playbook manually in the Azure portal. From where can you run the test
in Azure Sentinel?
A.
Playbooks
B.
Analytics
C.
Threat intelligence
D.
Incidents
Incidents
You have an Azure subscription that has Azure Defender enabled for all supported
resource types.
You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution.
To which service should you export the alerts?
A.
Azure Cosmos DB
B.
Azure Event Grid
C.
Azure Event Hubs
D.
Azure Data Lake
Azure Event Hubs
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.
You need to add threat indicators for all the IP addresses in a range of 171.23.3432-
171.2334.63. The solution must minimize administrative effort.
What should you do in the Microsoft 365 Defender portal?
A.
Create an import file that contains the IP address of 171.23.34.32/27. Select Import
and import the file.
B.
Select Add indicator and set the IP address to 171.2334.32-171.23.34.63.
C.
Select Add indicator and set the IP address to 171.23.34.32/27
D.
Create an import file that contains the individual IP addresses in the range. Select
Import and import the file.
Select Add indicator and set the IP address to 171.23.34.32/27
Explanation: This will add all the IP addresses in the range of 171.23.34.32/27 as threat
indicators. This is the simplest and most efficient way to add all the IP addresses in the
range.
Reference: [1] https://docs.microsoft.com/en-us/windows/security/threatprotection/
microsoft-defender-atp/threat-intelligence-manage-indicators
You use Azure Sentinel.
You need to receive an immediate alert whenever Azure Storage account keys are
enumerated. Which two actions should you perform? Each correct answer presents part of
the solution.
NOTE: Each correct selection is worth one point.
A.
Create a livestream
B.
Add a data connector
C.
Create an analytics rule
D.
Create a hunting query
E.
Create a bookmark.
Add a data connector
Create an analytics rule
Explanation:
B: To add a data connector, you would use the Azure Sentinel data connectors feature to
connect to your Azure subscription and to configure log data collection for Azure Storage
account key enumeration events.
C: After adding the data connector, you need to create an analytics rule to analyze the log
data from the Azure storage connector, looking for the specific event of Azure storage
account keys enumeration. This rule will trigger an alert when it detects the specific event,
allowing you to take immediate action.
Page 3 out of 16 Pages |
Previous |