<< Prev Question Next Question >>

Question 12/45

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring Azure Sentinel.
You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.
Solution: You create a Microsoft incident creation rule for a data connector.
Does this meet the goal?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (45q)
Question 1: You need to visualize Azure Sentinel data and enrich the dat...
Question 2: You plan to create a custom Azure Sentinel query that will t...
Question 3: You need to receive a security alert when a user attempts to...
Question 4: You have five on-premises Linux servers. You have an Azure s...
Question 5: You use Azure Security Center. You receive a security alert ...
Question 6: You have a Microsoft 365 tenant that uses Microsoft Exchange...
Question 7: You have a Microsoft 365 subscription that uses Microsoft De...
Question 8: You need to configure the Azure Sentinel integration to meet...
Question 9: You have an Azure subscription that contains a virtual machi...
Question 10: You have an Azure subscription that uses Microsoft Defender ...
Question 11: You have an Azure Storage account that will be accessed by m...
Question 12: Note: This question is part of a series of questions that pr...
Question 13: You implement Safe Attachments policies in Microsoft Defende...
Question 14: You need to complete the query for failed sign-ins to meet t...
Question 15: You have a Microsoft Sentinel workspace named workspace1 tha...
Question 16: You have a playbook in Azure Sentinel. When you trigger the ...
Question 17: A security administrator receives email alerts from Azure De...
Question 18: You purchase a Microsoft 365 subscription. You plan to confi...
Question 19: You have resources in Azure and Google cloud. You need to in...
Question 20: You have a Microsoft Sentinel workspace named sws1. You need...
Question 21: Note: This question is part of a series of questions that pr...
Question 22: Note: This question is part of a series of questions that pr...
Question 23: Note: This question is part of a series of questions that pr...
1 commentQuestion 24: You have a third-party security information and event manage...
Question 25: You are investigating a potential attack that deploys a new ...
Question 26: You are informed of an increase in malicious email being rec...
Question 27: You deploy Azure Sentinel. You need to implement connectors ...
Question 28: You have a Microsoft 365 subscription that uses Microsoft 36...
Question 29: You use Azure Defender. You have an Azure Storage account th...
Question 30: Your company uses Azure Security Center and Azure Defender. ...
Question 31: You manage the security posture of an Azure subscription tha...
Question 32: You create an Azure subscription named sub1. In sub1, you cr...
Question 33: You have a Microsoft Sentinel workspace that contains the fo...
Question 34: You have the resources shown in the following table. (Exhibi...
Question 35: You are configuring Microsoft Cloud App Security. You have a...
Question 36: You have an Azure subscription linked to an Azure Active Dir...
Question 37: The issue for which team can be resolved by using Microsoft ...
Question 38: You have an Azure subscription. You need to delegate permiss...
Question 39: You are configuring Azure Sentinel. You need to send a Micro...
Question 40: You plan to connect an external solution that will send Comm...
Question 41: Note: This question is part of a series of questions that pr...
Question 42: You create an Azure subscription. You enable Azure Defender ...
Question 43: Your company uses Azure Sentinel to manage alerts from more ...
Question 44: You use Azure Sentinel. You need to receive an immediate ale...
Question 45: You are investigating an incident in Azure Sentinel that con...