You have a Microsoft Sentinel-enabled Log Analytics workspace named Workspace1.
Your company receives JSON security events from a software as a service (SaaS) application.
You plan to create a custom Microsoft Sentinel data connector.
You need to prepare Workspace1 for the incoming JSON data.
What should you do first?
A. Configure a diagnostic setting for the SaaS application.
B. Install a built-in Microsoft Sentinel data connector.
C. Create a custom log table in Workspace1.
D. Create an analytics rule in Microsoft Sentinel.
Show Answer
Correct Answer: C
Explanation: Create a custom log table in Workspace1 first so the incoming JSON events have a destination schema in Log Analytics. The custom data connector can then send data to that table.
Question 22
DRAG DROP
You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource that discovers internet-facing assets for a company named Contoso, Ltd.
You need to classify the assets to meet the following requirements:
• Third-party infrastructure assets must be tracked separately from assets owned by Contoso.
• Assets with unconfirmed ownership must remain outside the owned inventory until ownership is verified.
How should you classify the assets? To answer, drag the appropriate asset states to the correct assets. Each state may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Explanation: Dependency tracks third-party infrastructure separately. Candidate keeps assets with unconfirmed ownership outside the approved inventory pending verification.
Question 23
You create a new Microsoft Sentinel workspace named Workspace1.
Workspace1 ingests Azure Firewall logs that are used only occasionally during investigations.
You need to retain the logs for seven years at the lowest cost. The solution must ensure that investigators can search the retained data when needed.
What should you do?
A. Archive the logs to an Azure Storage account.
B. Configure the table in Workspace1 that stores the logs to use the data lake tier.
C. Configure the table in Workspace1 that stores the logs to use the analytics tier.
D. Increase the analytics retention period of Workspace1 to seven years.
Show Answer
Correct Answer: B
Explanation: Configure the Azure Firewall log table to use the data lake tier. It provides lower-cost, long-term retention while allowing investigators to search the retained data when needed. The analytics tier is intended for data that needs frequent, operational use, and extending analytics retention to seven years would cost more.
Question 24
HOTSPOT
You need to deploy the Phishing Triage Agent in Microsoft Security Copilot to manage phishing incidents in Microsoft Defender XDR.
The solution must meet the following requirements:
• Manage the phishing incidents.
• Enable the Phishing Triage Agent.
• Follow the principle of least privilege.
Which roles should you assign? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: To enable the agent: Security Administrator in Microsoft Entra and Security Copilot Owner
To manage the phishing incidents: Security Operator in Microsoft Entra and Security Copilot Contributor
Explanation: Enabling the agent requires administrative permissions. Managing incidents is an operational task, so the Security Operator and Contributor roles provide the least privilege needed.
Question 25
You have a Microsoft Security Copilot workspace named Workspace1 that is used by Security Operations Center (SOC) analysts and security administrators.
The SOC analysts use only the Security Copilot standalone experience, and the security administrators access Security Copilot from the Microsoft Defender portal.
A new Security Copilot workspace named Workspace2 is created for the security administrators. Workspace2 is assigned a capacity of five security compute units.
You need to ensure that Security Copilot usage for the SOC analysts is allocated to Workspace1 and Security Copilot usage for the security administrators is allocated to Workspace2.
What should you do?
A. Configure Workspace2 for embedded agent traffic.
B. Increase the capacity of Workspace2.
C. Assign the Workspace1 capacity to Workspace2.
D. Configure Workspace1 for embedded agent traffic.
Show Answer
Correct Answer: A
Explanation: Configure Workspace2 for embedded agent traffic. The administrators’ access through the Defender portal is embedded usage, which can be routed to Workspace2. The SOC analysts’ standalone usage remains allocated to Workspace1.
Question 26
DRAG DROP
You use Azure Virtual Network Manager to manage multiple virtual networks organized into two network groups named Production and Development.
You need to configure Virtual Network Manager to meet the following requirements:
• Allow traffic between all the virtual networks in Production.
• Block traffic between Development and Production.
What should you use for each requirement? To answer, drag the components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Allow traffic within Production: A connectivity configuration
Block traffic between Development and Production: A security admin configuration
Explanation: A connectivity configuration connects virtual networks in a network group. A security admin configuration applies rules that can deny traffic between network groups.
Question 27
You have an Azure subscription that contains a resource group named RG1 and has Microsoft Defender for Cloud enabled.
You connect an Amazon Web Services (AWS) account to Defender for Cloud by creating the AWS connector in RG1.
You have a Microsoft Entra group named Group1 that contains the user accounts of the security analysts at your company.
You need to ensure that the members of Group1 can view multicloud recommendations and security alerts for the connected AWS account. The solution must follow the principle of least privilege.
Which role should you assign to Group1 for RG1?
A. Security Reader
B. Reader
C. Owner
D. Security Administrator
Show Answer
Correct Answer: A
Explanation: Assign **Security Reader** to Group1 on RG1. It provides read-only access to Microsoft Defender for Cloud security information, including recommendations and alerts, without granting permissions to change settings or manage resources.
Question 28
HOTSPOT
You have three on-premises apps named App1, App2, and App3 that are configured in Microsoft Entra Private Access as shown in the following table.
You have the users shown in the following table.
The Global Secure Access client is deployed to all user devices.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User2 can connect to https://10.20.30.40: No
User3 can connect to https://intranet.corp.contoso.com: Yes
User1 can connect to https://intranet.corp.contoso.com:8443: No
Explanation: Access requires an assigned app whose segment matches both the destination and port. User2’s IP assignment permits only port 8443. App1 covers intranet.corp.contoso.com on port 443, but not port 8443.
Question 29
You have an Azure subscription that contains the resources shown in the following table.
VM1 contains an application that accesses storage1. Another application accesses storage1 from a public IP address of xxx.xxx.xx.xx.
For storage1, you set Public network access to Enabled from selected virtual networks and IP addresses. You add an IP network rule for xxx.xxx.xx.xx.
After the configuration, only connections from xxx.xxx.xx.xx succeed.
You need to ensure that both VM1 and xxx.xxx.xx.xx.can access storage1 over the public endpoint, while preventing all other access.
What should you do?
A. Set Public network access to Enabled from all networks.
B. Enable a private endpoint for storage1.
C. Add a public IP address to VM1.
D. Enable the Microsoft.Storage service endpoint for Subnet1.
Show Answer
Correct Answer: D
Explanation: Enable the Microsoft.Storage service endpoint on Subnet1 so VM1’s traffic can reach storage1 through its public endpoint and be governed by the storage account’s selected-network rules. The public IP rule continues to allow xxx.xxx.xx.xx; access from other networks remains blocked. Ensure Subnet1 is also included as a virtual-network rule for storage1.
Question 30
You have an Azure virtual network named VNet1 that contains a subnet named Subnet1.
You create a storage account named storage1.
You need to ensure that access to storage1 can be managed only by a network security group (NSG) linked to Subnet1.
What should you use?
A. an Azure Private link service
B. a service endpoint
C. a private endpoint
D. a user-defined route (UDR)
Show Answer
Correct Answer: C
Explanation: A private endpoint gives storage1 a private IP address in the virtual network. With private endpoint network policies enabled on Subnet1, the NSG linked to that subnet can control traffic to the endpoint. Disable public network access to prevent traffic from bypassing that path.
$19
Get all 100 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.