You have a Microsoft 365 E5 subscription that includes a database server named DB1. DB1 is onboarded to Microsoft Defender XDR.
You need to ensure that DB1 is shown on the attack surface map.
What should you configure?
Aan asset rule
Ba critical asset rule
Ca sensitive entity tag
Da honeytoken entity tag
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.
You have Microsoft SharePoint Online sites containing sensitive documents. The documents contain customer account numbers, each consisting of 32 alphanumeric characters.
You need to create a data loss prevention (DLP) policy to protect the sensitive documents.
What should you use to identify which documents are sensitive?
ASharePoint search
Ba hunting query in Microsoft 365 Defender
CAzure Information Protection
DRegEx pattern matching
You have a Microsoft 365 E5 subscription that uses Microsoft Teams.
You must perform a content search of a user’s Teams chats by using the Microsoft Purview compliance portal. The solution must minimize the search scope.
How should you configure the content search?
Select
Locations:
Keywords:
You have a Microsoft 365 subscription that contains a Windows device named Device1. Device1 is onboarded to Microsoft Defender for Endpoint.
You initiate a live response session on Device1.
You need to execute a long-running script while ensuring that you can run additional commands during the session. How should you complete the live response command?
Select
script1.ps1
QuestionQ6
Manage incident response
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Configure protections and detections
QuestionQ8
Configure protections and detections
QuestionQ9
Manage incident response
QuestionQ10
Configure protections and detections
QuestionQ11
Manage incident response
QuestionQ12
Manage incident response
QuestionQ13
Configure protections and detections
QuestionQ14
Manage a security operations environment
QuestionQ15
Configure protections and detections
QuestionQ16
Configure protections and detections
QuestionQ17
Configure protections and detections
QuestionQ18
Configure protections and detections
QuestionQ19
Configure protections and detections
QuestionQ20
Manage incident response
QuestionQ21
Manage incident response
QuestionQ22
Configure protections and detections
QuestionQ23
Configure protections and detections
QuestionQ24
Configure protections and detections
QuestionQ25
Manage incident response
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
You have a Microsoft 365 E5 subscription that includes a device named Device1.
In the Microsoft Defender portal, you discover that an alert was triggered for Device1.
From the Device inventory page, you isolate Device1.
You need to obtain a list of the programs installed on Device1.
What should you do?
AInitiate an automated investigation and view the results in the Action center.
BCollect an investigation package and download the results from the Action center.
CRun an advanced hunting query against the DeviceTvmInfoGathering table.
DRun an advanced hunting query against the DeviceProcessEvents table.
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You must create a KQL hunting query that meets these requirements:
Identify devices that received an email with an attachment named File1.pdf in the past 12 hours and opened the attachment.
Minimize the resources needed to run the query.
How should you complete the query?
Select
EmailAttachmentInfo
| where Timestamp > ago(12h)
| where Subject == "Document Attachment" and FileName == "File1.pdf"
| join kind= (DeviceFileEvents | where Timestamp > ago(12h)) on
You have a Microsoft 365 subscription that uses Microsoft Security Copilot.
You plan to configure a custom GPT plugin for Copilot.
Which GPT model is appropriate to use?
Agpt-4o
Bo1-mini
Cdavinci-002
Dgpt-35-turbo
You have an Azure subscription that uses Microsoft Sentinel.
You need to minimize the administrative effort required to respond to the incidents and remediate the security threats detected by Microsoft Sentinel.
Which two features should you use? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Choose two
AMicrosoft Sentinel workbooks
BAzure Automation runbooks
CMicrosoft Sentinel automation rules
DMicrosoft Sentinel playbooks
EAzure Functions apps
You purchase a Microsoft 365 subscription.
You plan to configure Microsoft Cloud App Security.
You need to create a custom template-based policy that detects connections to Microsoft 365 apps originating from a botnet network.
What should you use?
Select
Policy template type:
Filter based on:
You have a Windows 11 device named Device1 that is onboarded to Microsoft Defender for Endpoint, with tamper protection enabled.
A user reports that Microsoft Defender Antivirus blocks installation of a line-of-business (LOB) application.
You enable troubleshooting mode on Device1.
You need to retrieve the logs and setting snapshots that Defender for Endpoint collects while Device1 is in troubleshooting mode. The solution must minimize administrative effort.
What should you do?
AInitiate an automated investigation.
BCollect the Microsoft Defender Antivirus troubleshooting diagnostic files.
CInitiate a live response session.
DCollect an investigation package.
Your on-premises network has two Active Directory Domain Services (AD DS) domains named contoso.com and fabrikam.com. Contoso.com has a group named Group1. Fabrikam.com has a group named Group2.
You have a Microsoft Sentinel workspace named WS1 that contains a scheduled query rule named Rule1. Rule1 creates alerts in response to anomalous AD DS security events. Every alert creates an incident.
You need to implement an incident-triage solution that meets the following requirements:
Security incidents from contoso.com must be assigned to Group1.
Security incidents from fabrikam.com must be assigned to Group2.
Administrative effort must be minimized.
What should you include in the solution?
Aa playbook that is triggered by the creation of an incident
Ba playbook that is triggered by the creation of an alert
Cone automation rule assigned to Rule1
Dtwo automation rules assigned to Rule1
You have an Azure subscription containing a Microsoft Sentinel workspace and a virtual machine named VM1. VM1 runs Linux and hosts a log forwarder that receives Syslog and Common Event Format (CEF) messages from network appliances on TCP/UDP port 514. VM1 has the Azure Monitor Agent installed and is associated with one data collection rule (DCR) that collects Syslog facilities.
You find that when the appliances send CEF messages by using the local0 facility, the events are ingested into both the CommonSecurityLog table and the Syslog table.
You need to prevent the CEF messages from being ingested into the Syslog table. The solution must ensure that the CEF messages continue to be ingested into CommonSecurityLog.
What should you use?
Aa KQL function
Ban analytics rule in Microsoft Sentinel
Can ingestion-time transformation
Da table-level retention setting
You have a Microsoft 365 E5 subscription that includes a device named Device1.
In the Microsoft Defender portal, you find that an alert has been triggered for Device1.
From the Device inventory page, you isolate Device1.
You need to obtain a list of the programs installed on Device1.
What should you do?
ARun an advanced hunting query against the DeviceProcessEvents table.
BRun an advanced hunting query against the DeviceTvmSoftwareInventory table.
CInitiate an automated investigation and view the results in the Action center.
DInitiate a live response session and run the processes command.
You have an Azure subscription with Azure Defender enabled for every supported resource type.
You need to configure continuous export of high-severity alerts so that a third-party security information and event management (SIEM) solution can retrieve them.
To which service should the alerts be exported?
AAzure Cosmos DB
BAzure Event Grid
CAzure Event Hubs
DAzure Data Lake
You have an Azure subscription containing a Log Analytics workspace named Workspace1.
You configure Azure activity logs and Microsoft Entra ID logs to forward to Workspace1.
You need to identify the Azure resources that risky users queried or modified.
Complete the KQL query by selecting the appropriate options in the answer area.
You need to implement the Azure Information Protection requirements.
What should you configure first?
ADevice health and compliance reports settings in Microsoft Defender Security Center
Bscanner clusters in Azure Information Protection from the Azure portal
Ccontent scan jobs in Azure Information Protection from the Azure portal
DAdvanced features from Settings in Microsoft Defender Security Center
You have three Azure subscriptions, each containing multiple virtual machines running Windows Server.
You have a Microsoft Sentinel workspace.
You need to ensure that failed sign-in attempts from every virtual machine can be analyzed by using Microsoft Sentinel. The solution must minimize administrative effort.
What should you do first?
AFrom the Microsoft Defender portal, install the Windows Security Events solution.
BOn each virtual machine, create an event subscription.
COn each virtual machine, install the Azure Connected Machine agent.
DFrom the Microsoft Defender portal, install the Syslog solution.
You have multiple Azure subscriptions containing multiple Microsoft Sentinel workspaces.
You are creating a Microsoft Sentinel workbook that includes references to the AzureActivity table.
You need a KQL query that performs these actions:
Check whether the AzureActivity table exists in every workspace.
When the table exists, return one row whose isMissing column is set to 0.
When the table does not exist, return one row whose isMissing column is set to 1.
How should you complete the query?
Select
let mTable = (isMissing:int) [1];
union mTable, (AzureActivity | getschema | summarize c=count() | project isMissing=iff(c > 0, 0, 1))
| top 1
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and includes a Windows device named Device1.
Twenty files on Device1 were quarantined by custom indicators as part of an investigation.
You need to release the 20 files from quarantine.
How should you complete the command?
Select
-Name EUS:Win32/CustomEnterpriseBlock -All
You have an Azure subscription that includes two users, User1 and User2, and a Microsoft Sentinel workspace.
You need each user to perform the following actions:
User1: Triage incident detections for well-known attack techniques and manage incident status.
User2: Investigate complex incidents and create indicators, hunting rules, and workbooks.
The solution must comply with the principle of least privilege.
Which role should you assign to each user?
Select
User1:
User2:
You have a Microsoft Sentinel workspace that includes Common Event Format (CEF) data.
You need to run a query on the CEF data.
Which table should you query?
ASyslog
BSecurityEvent
CCommonSecurityLog
DTrreatIntelligentIndicator
You need to build a KQL query in a Microsoft Sentinel workspace. The query must return the SecurityEvent record for accounts whose latest record has an EventID value of 4624.
How should you complete the query?
Select
SecurityEvent
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2. The subscription includes 1,000 Windows 11 devices running third-party antivirus software with Smart App Control enabled.
You need to ensure that, if Defender for Endpoint detects a malicious artifact missed by the third-party software, it automatically remediates that artifact.
What should you configure?
Aendpoint detection and response (EDR) in block mode
BAllow or block file
CAutomatically resolve alerts
Dtamper protection
You have 1,000 on-premises Windows 11 Pro devices that are onboarded to Microsoft Defender for Endpoint.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You discover that an attacker performed the following actions on a device:
Modified the file system path of a registry-based antivirus exclusion
Downloaded a malicious file to that file system path
You initiate a live response session on the device.
Community Discussion