<< Prev Question

Question 114/114

You are investigating an incident in Azure Sentinel that contains more than 127 alerts.
You discover eight alerts in the incident that require further investigation.
You need to escalate the alerts to another Azure Sentinel administrator.
What should you do to provide the alerts to the administrator?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (114q)
Question 1: You have an Azure subscription that has Microsoft Defender f...
Question 2: You have a Microsoft 365 E5 subscription that uses Microsoft...
Question 3: You have an Azure subscription that has Azure Defender enabl...
Question 4: You have an Azure subscription named Sub1 that uses Microsof...
Question 5: You have an Azure subscription. You plan to implement an Mic...
Question 6: You need to implement the Azure Information Protection requi...
Question 7: You have a Microsoft 365 E5 subscription that uses Microsoft...
Question 8: You need to assign role-based access control (RBAQ roles to ...
Question 9: You have an Azure subscription that contains a quest user na...
Question 10: You have a Microsoft Sentinel workspace named workspace1 and...
Question 11: You have a Microsoft 365 subscription that uses Microsoft Pu...
Question 12: You need to correlate data from the SecurityEvent Log Anaryt...
Question 13: Your company stores the data for every project in a differen...
Question 14: Your on-premises network contains an Active Directory Domain...
Question 15: You need to implement the ASIM query for DNS requests. The s...
Question 16: You have a Microsoft 365 E5 subscription that uses Microsoft...
Question 17: You need to implement Microsoft Sentinel queries for Contoso...
Question 18: You have an Azure subscription that uses Microsoft Defender ...
Question 19: You have a Microsoft 365 subscription that uses Microsoft Pu...
Question 20: You have an Azure Sentinel deployment. You need to query for...
Question 21: You haw the resources shown in the following Table. (Exhibit...
Question 22: You have an existing Azure logic app that is used to block A...
Question 23: You have an Azure subscription that contains a virtual machi...
Question 24: You have an Azure subscription that contains an Microsoft Se...
Question 25: You have a Microsoft 365 tenant that uses Microsoft Exchange...
Question 26: You use Azure Defender. You have an Azure Storage account th...
Question 27: You have an Azure subscription that contains an Azure logic ...
Question 28: You have an Azure subscription that has Microsoft Defender f...
Question 29: You have an Azure DevOps organization that uses Microsoft De...
Question 30: You have a Microsoft 365 E5 subscription that contains 100 L...
Question 31: You have a Microsoft Sentinel workspace that contains the fo...
Question 32: You have an Azure subscription that contains a resource grou...
Question 33: You need to implement Azure Defender to meet the Azure Defen...
Question 34: You have an Azure subscription that has Azure Defender enabl...
Question 35: You create a hunting query in Azure Sentinel. You need to re...
Question 36: You need to recommend remediation actions for the Azure Defe...
Question 37: You are informed of a new common vulnerabilities and exposur...
Question 38: You need to use an Azure Resource Manager template to create...
Question 39: You have an Azure subscription that uses Microsoft Defender ...
Question 40: You have a custom detection rule that includes the following...
Question 41: You have an Azure subscription that is linked to a hybrid Az...
Question 42: You use Azure Sentinel. You need to use a built-in role to p...
Question 43: You need to create the analytics rule to meet the Azure Sent...
Question 44: You are investigating a potential attack that deploys a new ...
Question 45: From Azure Sentinel, you open the Investigation pane for a h...
Question 46: You have a Microsoft 365 subscription that contains the foll...
Question 47: You need to monitor the password resets. The solution must m...
Question 48: You have a Microsoft Sentinel workspace named Workspace1. Yo...
Question 49: You have a Microsoft Sentinel workspace that uses the Micros...
Question 50: You recently deployed Azure Sentinel. You discover that the ...
Question 51: You have a Microsoft Sentinel workspace that contains a cust...
Question 52: You have an Azure subscription that contains a Microsoft Sen...
Question 53: You have an Azure subscription that uses Azure Defender. You...
Question 54: You are configuring Azure Sentinel. You need to send a Micro...
Question 55: You have a Microsoft Sentinel workspace named workspace1 tha...
Question 56: You have a Microsoft 365 subscription that uses Azure Defend...
Question 57: You need to receive a security alert when a user attempts to...
Question 58: You have the resources shown in the following table. (Exhibi...
Question 59: You need to configure DC1 to meet the business requirements....
Question 60: You have a Microsoft 365 E5 subscription that contains two u...
Question 61: You have an Azure subscription that contains the following r...
Question 62: Which rule setting should you configure to meet the Microsof...
Question 63: You have a Microsoft 365 E5 subscription that uses Microsoft...
Question 64: Note: This question is part of a series of questions that pr...
Question 65: You have resources in Azure and Google cloud. You need to in...
Question 66: You have an Azure subscription that use Microsoft Defender f...
Question 67: You have five on-premises Linux servers. You have an Azure s...
Question 68: You have an Azure Storage account that will be accessed by m...
Question 69: You need to ensure that you can run hunting queries to meet ...
Question 70: Your on-premises network contains 100 servers that run Windo...
Question 71: You create an Azure subscription named sub1. In sub1, you cr...
Question 72: You have a Microsoft Sentinel workspace that contains a cust...
Question 73: You have an Azure subscription that uses Microsoft Sentinel....
Question 74: You have a Microsoft 365 subscription that uses Microsoft Pu...
Question 75: You need to ensure that the Group1 members can meet the Micr...
Question 76: You are investigating an incident by using Microsoft 365 Def...
Question 77: You have an Azure subscription that uses Microsoft Defender ...
Question 78: You are informed of an increase in malicious email being rec...
Question 79: You have a Microsoft Sentinel workspace named Workspace1 and...
Question 80: You create a new Azure subscription and start collecting log...
Question 81: You have a Microsoft 365 E5 subscription. You need to create...
Question 82: You are responsible for responding to Azure Defender for Key...
Question 83: You have an Azure subscription. The subscription contains 10...
Question 84: The issue for which team can be resolved by using Microsoft ...
Question 85: You have a playbook in Azure Sentinel. When you trigger the ...
Question 86: You manage the security posture of an Azure subscription tha...
Question 87: Your network contains an on-premises Active Directory Domain...
Question 88: You have a Microsoft Sentinel workspace. You need to create ...
Question 89: You have an Azure subscription that uses Microsoft Sentinel ...
Question 90: You have a Microsoft Sentinel workspace You develop a custom...
Question 91: You need to implement Azure Sentinel queries for Contoso and...
Question 92: You have a Microsoft 365 E5 subscription that uses Microsoft...
Question 93: You have an Azure subscription that uses Microsoft Defender ...
Question 94: You have an Azure subscription that uses Microsoft Defender ...
Question 95: You have an Azure subscription that has Azure Defender enabl...
Question 96: You create a custom analytics rule to detect threats in Azur...
Question 97: You have a Microsoft Sentinel workspace named SW1. In SW1. y...
Question 98: You need to configure the Microsoft Sentinel integration to ...
Question 99: A security administrator receives email alerts from Azure De...
Question 100: Note: This question is part of a series of questions that pr...
Question 101: You have a Microsoft 365 subscription that uses Microsoft De...
Question 102: You need to create a query to investigate DNS-related activi...
Question 103: You have a Microsoft 365 E5 subscription that uses Microsoft...
Question 104: You need to implement the scheduled rule for incident genera...
Question 105: You have an Azure Sentinel deployment in the East US Azure r...
Question 106: You create a new Azure subscription and start collecting log...
Question 107: You have a Microsoft Sentinel workspace that has User and En...
Question 108: Your company has an on-premises network that uses Microsoft ...
Question 109: Note: This question is part of a series of questions that pr...
Question 110: You have an Azure subscription that has the enhanced securit...
Question 111: You have an Azure subscription that uses Microsoft Defender ...
Question 112: You have a custom analytics rule to detect threats in Azure ...
Question 113: You have a Microsoft Sentinel workspace named sws1. You need...
Question 114: You are investigating an incident in Azure Sentinel that con...