Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: estly75

You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.

You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent ' s Microsoft Entra service principal.

You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement The solution must minimize administrative effort.

What should you do?

A.

From Advanced hunting, create a query against the IdentityLogonEvents table to list all the sign-ins performed by the identity.

B.

From Attack paths, select the identity and view the blast radius.

C.

From AI Observability in Microsoft Purview Data Security Posture Management (DSPM), review the agent activity.

D.

From Microsoft Purview Audit, query the audit logs for all the role assignments granted to the identity.

E.

From Incidents, review incidents related to OAuth events reported by Microsoft Defender for Cloud Apps.

You are configuring a new Microsoft Sentinel workspace named Workspace1.

You have an external IT Service Management (ITSM) system that is NOT supported by any Microsoft Sentinel solutions in Azure Marketplace.

You need to ensure that Workspace1 creates service tickets in the ITSM system for all new security incidents.

What should you create?

A.

A playbook

B.

A workbook

C.

A watchlist

D.

An analytics rule

You have a Microsoft Entra tenant that contains a user named Admin1 and is linked to an Azure subscription named Sub1.

Admin1 reports that the Custom recommendation option is unavailable in Microsoft Defender for Cloud as shown in the following exhibit.

You need to ensure that Admin1 can create a custom recommendation. The solution must follow the principle of least privilege. What should you do?

A.

Enable the Resource Manager Cloud Workload Protection (CWP) plan.

B.

Enable the Defender Cloud Security Posture Management (CSPM) plan.

C.

Assign Admin the Contributor role for Sub1.

D.

Assign Admin1 the Owner role for Sub1.

You have an Azure subscription named Sub1 that contains 50 virtual machines. Sub1 has Microsoft Defender for Cloud enabled.

Sub1 contains an Azure key vault named KV1 and an Azure policy that enforces storing all secrets in KV1.

Occasionally, the developers at your company store plaintext tokens and SSH private keys on the virtual machines.

You need to configure Defender for Cloud to detect plaintext secrets on the virtual machines. The solution must minimize administrative changes to the virtual machines.

How should you configure Defender for Cloud? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.

You use Microsoft Security Copilot.

You need to update Plugin settings. the solution must meet the following requirements:

• Allow contributors to use custom plug-ins without affecting either UMTS

• Limit publishing of custom plug-ins for other users to Owners only.

Which Plugin settings option should you configure for each requirement? To answer, drag the appropriate settings lo the correct requirements. Each setting may be used once, more than once., or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

You have an Azure subscription that has the Microsoft Defender for Cloud Foundational Cloud Security Posture Management (CSPM) plan enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud for posture management.

In Defender for Cloud, security recommendations for the resources in Azure and AWS have a risk level of Not evaluated.

You need to ensure that Defender for Cloud assigns a risk level to the recommendations.

What should you do?

A.

Onboard all the virtual machines in the AWS account to Azure Arc.

B.

Enable Microsoft Defender for Servers Plan 2.

C.

Assign the CIS AWS Foundations v3.0.0 standard to the AWS account.

D.

Enable the Defender CSPM plan.

You have two management groups named MG1 and MG2 that contain multiple Azure subscriptions. The subscriptions are linked to a Microsoft Entra tenant.

You have a user named User1 and a global administrator named Admin 1

You are informed that User1 created an Azure subscription named Sub1 under the MG2 management group and is the only owner of the subscription.

You need to ensure that Admin1 can remove the Owner role from User1 for Sub1.

What should you do first?

A.

Move Sub1 to MG1.

B.

Assign Admin1 the User Access Administrator role for Sub1.

C.

Instruct Admin1 to use Privileged Identity Management (PIM) to request the Security Administrator role.

D.

Instruct Admin1 to enable Access management for Azure resources.

You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource that discovers internet-facing assets for a company named Contoso, Ltd.

You need to classify the assets lo meet the following requirements.

• Third-party infrastructure assets must be tracked separately from assets owned by Contoso.

• Assets with unconfirmed ownership must remain outside the owned inventory until ownership is verified.

How should you classify the assets? To answer, drag the appropriate asset states to the correct assets. Each state may be used once, more than once or not at all. You may need to drag the split bar between panes or scroll to view content.

You have a Microsoft Sentinel-enabled Log Analytics workspace named Workspace1.

Your company receives JSON security events from a software as a service (SaaS) application.

You plan to create a custom Microsoft Sentinel data connector.

You need to prepare Workspace1 for the incoming JSON data.

What should you do first?

A.

Configure a diagnostic setting for the SaaS application.

B.

Install a built-in Microsoft Sentinel data connector.

C.

Create a custom log table in Workspace1.

D.

Create an analytics rule in Microsoft Sentinel.

You have an Azure subscription that contains the virtual networks shown in the following table.

NSG1 and NSG2 both have default rules only.

The subscription contains the virtual machines shown in the following table.