1What is the primary purpose of an Azure Log Analytics workspace?
Create Log Analytics workspace
Easy
A.To create private network connections
B.To host virtual machines and applications
C.To manage user passwords and permissions
D.To store and analyze collected log data
Correct Answer: To store and analyze collected log data
Explanation:
A Log Analytics workspace is a central location for storing and querying log and monitoring data.
Incorrect! Try again.
2Which Azure service is commonly used to query data in a Log Analytics workspace?
Create Log Analytics workspace
Easy
A.Azure Virtual Desktop
B.Azure Load Balancer
C.Azure Monitor Logs
D.Azure App Service
Correct Answer: Azure Monitor Logs
Explanation:
Azure Monitor Logs uses Log Analytics workspaces to store and query monitoring data.
Incorrect! Try again.
3Which query language is used to analyze data in a Log Analytics workspace?
Create Log Analytics workspace
Easy
A.Structured Query Language
B.Hypertext Markup Language
C.Cascading Style Sheets
D.Kusto Query Language
Correct Answer: Kusto Query Language
Explanation:
Kusto Query Language (KQL) is used to search, filter, and analyze log data.
Incorrect! Try again.
4Which information must be selected when creating a Log Analytics workspace?
Create Log Analytics workspace
Easy
A.Virtual machine and disk size
B.Subscription and resource group
C.Username and login password
D.Firewall rule and public port
Correct Answer: Subscription and resource group
Explanation:
A Log Analytics workspace must belong to an Azure subscription and a resource group.
Incorrect! Try again.
5How can a Data Collection Rule use a Log Analytics workspace?
Create Log Analytics workspace
Easy
A.As a manager of storage access keys
B.As a destination for collected data
C.As a source of virtual machine images
D.As a provider of domain names
Correct Answer: As a destination for collected data
Explanation:
A Data Collection Rule can send selected monitoring data to a Log Analytics workspace.
Incorrect! Try again.
6What is an Azure Storage account used for?
Azure Storage account
Easy
A.Creating identity access policies
B.Running operating system updates
C.Monitoring network security alerts
D.Storing cloud-based data objects
Correct Answer: Storing cloud-based data objects
Explanation:
An Azure Storage account provides cloud storage for blobs, files, queues, and tables.
Incorrect! Try again.
7Which Azure Storage service is designed for unstructured object data?
Azure Storage account
Easy
A.Azure Table Storage
B.Azure Blob Storage
C.Azure Queue Storage
D.Azure File Storage
Correct Answer: Azure Blob Storage
Explanation:
Azure Blob Storage is designed for unstructured data such as images, documents, and logs.
Incorrect! Try again.
8Which naming rule applies to an Azure Storage account?
Azure Storage account
Easy
A.The name must contain spaces
B.The name must include uppercase letters
C.The name must begin with a number
D.The name must be globally unique
Correct Answer: The name must be globally unique
Explanation:
Each Azure Storage account requires a globally unique name across Azure.
Incorrect! Try again.
9Which redundancy option keeps multiple copies of data within one Azure region?
Azure Storage account
Easy
A.Geo-redundant storage
B.Locally redundant storage
C.Geo-zone-redundant storage
D.Read-access geo-redundant storage
Correct Answer: Locally redundant storage
Explanation:
Locally redundant storage (LRS) keeps multiple copies of data within a single Azure region.
Incorrect! Try again.
10Which characters are allowed in an Azure Storage account name?
Azure Storage account
Easy
A.Uppercase letters and numbers
B.Lowercase letters and numbers
C.Uppercase letters and underscores
D.Lowercase letters and hyphens
Correct Answer: Lowercase letters and numbers
Explanation:
Storage account names can contain only lowercase letters and numbers.
Incorrect! Try again.
11What is the main purpose of Microsoft Defender for Cloud?
Configure Microsoft Defender for Cloud
Easy
A.To create database table structures
B.To design application interfaces
C.To register internet domain names
D.To improve cloud security posture
Correct Answer: To improve cloud security posture
Explanation:
Microsoft Defender for Cloud helps assess security posture and protect cloud workloads.
Incorrect! Try again.
12What does Secure Score in Microsoft Defender for Cloud represent?
Configure Microsoft Defender for Cloud
Easy
A.The overall security posture
B.The cost of deployed resources
C.The speed of network traffic
D.The number of active users
Correct Answer: The overall security posture
Explanation:
Secure Score summarizes how well an environment follows recommended security controls.
Incorrect! Try again.
13What does Microsoft Defender for Cloud provide when it identifies a security weakness?
Configure Microsoft Defender for Cloud
Easy
A.Security recommendations
B.Network IP addresses
C.Application source files
D.Storage access keys
Correct Answer: Security recommendations
Explanation:
Defender for Cloud provides recommendations that help administrators address security weaknesses.
Incorrect! Try again.
14Where can Defender plans be enabled for an Azure subscription?
Configure Microsoft Defender for Cloud
Easy
A.Deployment history
B.Environment settings
C.Cost analysis
D.Resource visualizer
Correct Answer: Environment settings
Explanation:
Defender plans can be configured for subscriptions through Environment settings in Defender for Cloud.
Incorrect! Try again.
15Which type of resource can Microsoft Defender for Cloud help protect?
Configure Microsoft Defender for Cloud
Easy
A.Cloud workloads
B.Local keyboards
C.Office furniture
D.Printed documents
Correct Answer: Cloud workloads
Explanation:
Defender for Cloud helps protect workloads such as virtual machines, containers, databases, and storage.
Incorrect! Try again.
16What type of service is Microsoft Sentinel?
Microsoft Sentinel
Easy
A.A cloud-based file storage service
B.A relational database management service
C.A virtual machine hosting service
D.A cloud-native SIEM and SOAR service
Correct Answer: A cloud-native SIEM and SOAR service
Explanation:
Microsoft Sentinel provides cloud-native security information, event management, and automated response.
Incorrect! Try again.
17What does Microsoft Sentinel use to bring data from external services into the platform?
Microsoft Sentinel
Easy
A.Data connectors
B.Storage containers
C.Resource locks
D.Virtual networks
Correct Answer: Data connectors
Explanation:
Data connectors allow Microsoft Sentinel to collect security data from supported sources.
Incorrect! Try again.
18Which Azure resource is used to store Microsoft Sentinel log data?
Microsoft Sentinel
Easy
A.Application security group
B.Azure managed disk
C.Virtual network gateway
D.Log Analytics workspace
Correct Answer: Log Analytics workspace
Explanation:
Microsoft Sentinel stores and analyzes its security data in a Log Analytics workspace.
Incorrect! Try again.
19What is the purpose of an analytics rule in Microsoft Sentinel?
Microsoft Sentinel
Easy
A.To create storage accounts
B.To resize virtual machines
C.To assign software licenses
D.To detect suspicious activity
Correct Answer: To detect suspicious activity
Explanation:
Analytics rules examine collected data to detect threats and create security alerts or incidents.
Incorrect! Try again.
20What is a playbook in Microsoft Sentinel used for?
Microsoft Sentinel
Easy
A.Storing operating system files
B.Automating security responses
C.Designing network diagrams
D.Calculating monthly cloud costs
Correct Answer: Automating security responses
Explanation:
A playbook automates security investigation and response actions in Microsoft Sentinel.
Incorrect! Try again.
21An organization operates resources in two Azure regions and wants centralized monitoring. What is the most appropriate design for a Log Analytics workspace?
Create Log Analytics workspace
Medium
A.Create one workspace in each region only
B.Create one centralized workspace and connect resources to it
C.Create a workspace inside every resource group
D.Create one workspace only for virtual machines
Correct Answer: Create one centralized workspace and connect resources to it
Explanation:
A centralized workspace simplifies querying, alerting, and retention management across resources in multiple regions, subject to compliance and data-residency requirements.
Incorrect! Try again.
22A security team needs to retain sign-in logs for 180 days, while application logs should be retained for only 30 days. Which approach best meets this requirement?
Create Log Analytics workspace
Medium
A.Store all logs in Azure Storage without workspace retention
B.Use one workspace with a 30-day retention period
C.Use separate workspaces with different retention settings
D.Use one workspace with a 180-day retention period
Correct Answer: Use separate workspaces with different retention settings
Explanation:
Separate workspaces allow different retention policies when the required retention periods cannot be applied appropriately to the same workspace.
Incorrect! Try again.
23A Log Analytics workspace must be created for production monitoring. Which configuration should be selected to support access control based on Azure resource permissions?
Create Log Analytics workspace
Medium
A.Resource-context access control
B.Workspace-context access control
C.Anonymous workspace access
D.Storage-account access control
Correct Answer: Resource-context access control
Explanation:
Resource-context access control lets users view logs associated with resources they are authorized to access without automatically granting access to all workspace data.
Incorrect! Try again.
24An administrator creates a Log Analytics workspace but cannot find diagnostic logs from a virtual network resource. What should be checked first?
Create Log Analytics workspace
Medium
A.Whether the virtual network uses a premium SKU
B.Whether the workspace has a public IP address
C.Whether diagnostic settings send logs to the workspace
D.Whether the workspace is linked to Azure Storage
Correct Answer: Whether diagnostic settings send logs to the workspace
Explanation:
Resources do not automatically send all diagnostic data to a workspace. Diagnostic settings must be configured with the workspace as a destination.
Incorrect! Try again.
25A company wants to control Log Analytics costs while keeping frequently queried security data available. Which action is most suitable?
Create Log Analytics workspace
Medium
A.Delete the workspace after each investigation
B.Collect only required tables and set suitable retention
C.Send every log category to the workspace
D.Disable all data collection during nonbusiness hours
Correct Answer: Collect only required tables and set suitable retention
Explanation:
Controlling collected tables and retention reduces ingestion and storage costs while preserving the data needed for operational and security investigations.
Incorrect! Try again.
26An application stores frequently accessed transaction files and requires high availability within a region. Which redundancy option is generally the best starting choice?
Azure Storage account
Medium
A.Read-access geo-redundant storage only
B.Locally redundant storage
C.Geo-redundant storage only
D.Zone-redundant storage
Correct Answer: Zone-redundant storage
Explanation:
Zone-redundant storage synchronously replicates data across availability zones in a region, improving resilience against a zone failure while supporting regional access.
Incorrect! Try again.
27A storage account contains sensitive audit exports. The security team wants to prevent access through public endpoints. Which configuration best supports this requirement?
Azure Storage account
Medium
A.Use a storage account with a shorter name
B.Enable anonymous blob access
C.Allow access from all networks
D.Use private endpoints and restrict network access
Correct Answer: Use private endpoints and restrict network access
Explanation:
Private endpoints provide private connectivity to the storage account, while network rules can block unauthorized public access.
Incorrect! Try again.
28A company must prevent audit blobs from being modified or deleted during a required retention period. Which Azure Storage capability should be used?
Azure Storage account
Medium
A.Blob soft delete only
B.Lifecycle management with immediate deletion
C.Immutable blob storage with a retention policy
D.Public read access with metadata
Correct Answer: Immutable blob storage with a retention policy
Explanation:
Immutable blob storage supports write-once, read-many behavior and can enforce retention periods that prevent modification or deletion.
Incorrect! Try again.
29A security engineer needs to grant an automation process access to one blob container without distributing account keys. Which method is most appropriate?
Azure Storage account
Medium
A.Share the storage account access key
B.Place the account name in the automation script
C.Assign an Azure role to the automation identity
D.Enable anonymous access to the container
Correct Answer: Assign an Azure role to the automation identity
Explanation:
Microsoft Entra ID authentication with Azure RBAC avoids long-lived account keys and allows permissions to be scoped to the required storage resource.
Incorrect! Try again.
30An organization wants old log files moved to a cooler storage tier after 30 days and deleted after one year. Which feature should be configured?
Azure Storage account
Medium
A.Azure Resource Graph queries
B.Blob index tags only
C.Azure Front Door routing
D.Storage lifecycle management
Correct Answer: Storage lifecycle management
Explanation:
Lifecycle management policies can automatically transition blobs between access tiers and delete them after specified conditions.
Incorrect! Try again.
31A security team wants Defender for Cloud to identify missing operating system updates and insecure configurations across virtual machines. Which capability should be enabled?
Configure Microsoft Defender for Cloud
Medium
A.Azure Storage lifecycle management
B.Microsoft Defender for Storage only
C.Azure Cost Management
D.Microsoft Defender for Servers
Correct Answer: Microsoft Defender for Servers
Explanation:
Defender for Servers provides security assessment and threat protection capabilities for virtual machines, including vulnerability and configuration insights.
Incorrect! Try again.
32After enabling a Defender for Cloud plan, an administrator wants to prioritize the most important security improvements. Which feature should be used?
Configure Microsoft Defender for Cloud
Medium
A.Secure Score recommendations
B.Workspace retention settings
C.Storage access tiers
D.Azure subscription renaming
Correct Answer: Secure Score recommendations
Explanation:
Secure Score recommendations identify security weaknesses and provide prioritized actions to improve the security posture.
Incorrect! Try again.
33A company wants to receive alerts when a storage account shows suspicious access patterns. Which Defender for Cloud plan is most directly relevant?
Configure Microsoft Defender for Cloud
Medium
A.Microsoft Defender for DNS only
B.Microsoft Purview Data Map
C.Microsoft Defender for Servers only
D.Microsoft Defender for Storage
Correct Answer: Microsoft Defender for Storage
Explanation:
Microsoft Defender for Storage detects threats and suspicious activity involving Azure Storage accounts and their data services.
Incorrect! Try again.
34A regulatory requirement states that all newly created resources must be evaluated against approved security settings. Which Defender for Cloud feature supports this goal?
Configure Microsoft Defender for Cloud
Medium
A.Application Gateway caching
B.Blob versioning only
C.Regulatory compliance dashboard
D.Data transfer acceleration
Correct Answer: Regulatory compliance dashboard
Explanation:
The regulatory compliance dashboard maps security assessments to standards and helps monitor compliance with required controls.
Incorrect! Try again.
35A security operations team wants Defender for Cloud alerts to be investigated in Microsoft Sentinel. What integration should be configured?
Configure Microsoft Defender for Cloud
Medium
A.A storage lifecycle rule for Sentinel
B.An access key rotation schedule only
C.A Sentinel data connector for Defender for Cloud
D.A new virtual network for each alert
Correct Answer: A Sentinel data connector for Defender for Cloud
Explanation:
The Microsoft Defender for Cloud connector forwards relevant alerts to Sentinel for centralized investigation, correlation, and response.
Incorrect! Try again.
36Microsoft Sentinel is deployed for a subscription, but no sign-in data appears in its queries. What is the most likely missing configuration?
Microsoft Sentinel
Medium
A.A second Sentinel workspace
B.A storage account access tier
C.A Microsoft Entra ID data connector
D.A Defender for Storage plan
Correct Answer: A Microsoft Entra ID data connector
Explanation:
Sentinel requires the appropriate data connector to ingest Microsoft Entra ID sign-in and audit logs into its Log Analytics workspace.
Incorrect! Try again.
37An analyst wants Sentinel to create an incident when multiple failed sign-ins are followed by a successful sign-in from an unusual location. Which Sentinel feature should be configured?
Microsoft Sentinel
Medium
A.Analytics rule
B.Storage replication policy
C.Workbook theme
D.Data retention lock
Correct Answer: Analytics rule
Explanation:
Analytics rules evaluate incoming data using conditions and queries, then generate incidents when suspicious activity matches the defined logic.
Incorrect! Try again.
38A security team wants a visual view of incident trends, alert sources, and investigation metrics. Which Sentinel feature is most suitable?
Microsoft Sentinel
Medium
A.Workbooks
B.Data connectors only
C.Automation rules only
D.Storage containers
Correct Answer: Workbooks
Explanation:
Sentinel workbooks provide interactive dashboards that visualize security data, incidents, trends, and operational metrics.
Incorrect! Try again.
39When a high-severity incident is created, the organization wants to notify the on-call team and create a service ticket automatically. Which Sentinel capability should be used?
Microsoft Sentinel
Medium
A.A workspace naming convention
B.A storage access policy
C.Automation rules with a playbook
D.A workbook visualization
Correct Answer: Automation rules with a playbook
Explanation:
Automation rules can trigger actions for incidents, while playbooks use Azure Logic Apps to send notifications and integrate with ticketing systems.
Incorrect! Try again.
40An organization wants to identify whether a suspicious IP address appears across firewall, identity, and endpoint logs. Which Sentinel capability best supports this investigation?
Microsoft Sentinel
Medium
A.Blob lifecycle management
B.Incident investigation and entity correlation
C.Storage account replication
D.Log Analytics workspace creation
Correct Answer: Incident investigation and entity correlation
Explanation:
Sentinel correlates entities such as IP addresses across connected data sources, helping analysts understand related activity during an investigation.
Incorrect! Try again.
41A company must keep security logs within Germany. Its virtual machines run in several Azure regions, and Microsoft Sentinel will analyze all collected logs centrally. Which workspace design best satisfies the residency requirement?
Create Log Analytics workspace
Hard
A.Create the workspace in each virtual machine's region and replicate its tables to Germany automatically
B.Create one Log Analytics workspace in an approved German region and associate the required DCRs with it
C.Create one workspace in any EU region because Log Analytics data is always stored across the entire EU
D.Create a global workspace and select Germany as the destination region in each analytics rule
Correct Answer: Create one Log Analytics workspace in an approved German region and associate the required DCRs with it
Explanation:
A workspace's region determines where its log data is stored. DCRs can collect from supported resources in other regions, subject to service-specific regional constraints.
Incorrect! Try again.
42A central SOC needs access to all workspace data, while application teams must query only logs generated by Azure resources they manage. Which access model best supports both requirements?
Create Log Analytics workspace
Hard
A.Use workspace access keys for the SOC and DCR association permissions for application teams
B.Use shared access signatures for the SOC and storage account RBAC for application teams
C.Use workspace-context access for the SOC and resource-context access with Azure RBAC for application teams
D.Use resource-context access for the SOC and grant application teams the workspace Contributor role
Correct Answer: Use workspace-context access for the SOC and resource-context access with Azure RBAC for application teams
Explanation:
Workspace-context access supports broad SOC queries, while resource-context access limits users to data from resources for which they have appropriate Azure RBAC permissions.
Incorrect! Try again.
43A workspace has a default retention period of 30 days, but the SecurityEvent table has a table-level retention setting of 180 days. Assuming no archive configuration changes the result, how long are rows in SecurityEvent retained?
Create Log Analytics workspace
Hard
A.They are retained for 210 days because workspace and table retention periods are cumulative
B.They are retained for 180 days because the table-level setting overrides the workspace default
C.They are retained for 30 days because workspace retention always overrides table-level retention
D.They are retained indefinitely because a table-level setting disables automatic data deletion
Correct Answer: They are retained for 180 days because the table-level setting overrides the workspace default
Explanation:
A supported table-specific retention configuration overrides the workspace default for that table; the two retention periods are not added together.
Incorrect! Try again.
44A DCR transformation renames Computer to HostName, but the destination custom table contains a Computer column and no HostName column. Ingestion fails schema validation. What is the correct remediation?
Create Log Analytics workspace
Hard
A.Configure the workspace to accept dynamic schemas for all records sent through the DCR
B.Add a query-time function that renames HostName to Computer after ingestion completes
C.Modify the transformation or destination table so the output column names and types match the table schema
D.Enable legacy agent compatibility so Log Analytics automatically restores the original column name
Correct Answer: Modify the transformation or destination table so the output column names and types match the table schema
Explanation:
The output of an ingestion-time transformation must match the destination table schema. Query-time functions cannot repair records that were rejected during ingestion.
Incorrect! Try again.
45After migrating servers to Azure Monitor Agent, the SOC observes two nearly identical copies of each Windows security event in the same workspace. Each server is associated with two DCRs that collect the same event stream. What is the most appropriate correction?
Create Log Analytics workspace
Hard
A.Remove the overlapping event collection from one DCR or redesign the DCR associations
B.Change one DCR to use resource-context access while leaving both collection definitions unchanged
C.Enable workspace deduplication and retain both DCR associations for collection resilience
D.Reduce workspace retention so the duplicate records are deleted immediately after correlation
Correct Answer: Remove the overlapping event collection from one DCR or redesign the DCR associations
Explanation:
Overlapping DCRs can collect the same data more than once. Log Analytics does not provide a general ingestion deduplication switch for such records.
Incorrect! Try again.
46A diagnostic setting for a regional Azure resource is configured to archive logs to a storage account, but deployment validation rejects the destination. The account is in a different Azure region, while its firewall and permissions are correctly configured. What is the likely cause?
Azure Storage account
Hard
A.A regional resource generally requires the diagnostic storage destination to be in the same region
B.The storage account must contain a manually created container before the setting is deployed
C.Diagnostic settings cannot send logs to storage accounts protected by Azure Resource Manager
D.Diagnostic settings require the storage account to use locally redundant storage exclusively
Correct Answer: A regional resource generally requires the diagnostic storage destination to be in the same region
Explanation:
For many regional Azure resources, the storage account selected by a diagnostic setting must be in the same region. Global resources are treated differently.
Incorrect! Try again.
47Security logs are stored in an immutable container with a locked 365-day time-based retention policy. A lifecycle rule attempts to delete the blobs after 90 days. What will happen?
Azure Storage account
Hard
A.The blobs are deleted after 90 days but remain recoverable through container soft delete for 275 days
B.The lifecycle rule shortens the immutable retention period because it was created after the policy
C.The lifecycle rule deletes the blobs because lifecycle management takes precedence over immutability
D.Deletion is blocked until the immutable retention period expires, even though the lifecycle rule matches
Correct Answer: Deletion is blocked until the immutable retention period expires, even though the lifecycle rule matches
Explanation:
A locked immutability policy enforces WORM retention. Lifecycle management cannot delete a protected blob before its retention period expires.
Incorrect! Try again.
48An archive must remain available after a zonal failure and must provide read access from a secondary Azure region if the primary region becomes unavailable. Which redundancy option best satisfies both requirements?
RA-GZRS combines zone-level resilience in the primary region, geo-replication to a secondary region, and direct read access to the secondary endpoint.
Incorrect! Try again.
49A lifecycle rule moves diagnostic log blobs to the Cool tier 30 days after creation. Some blobs are unexpectedly moved later because a metadata operation changed their last-modified time. Which lifecycle behavior explains this?
Azure Storage account
Hard
A.Lifecycle age conditions begin when the diagnostic setting creates its destination container
B.Lifecycle age conditions are evaluated using the blob's last-modified time rather than an embedded event timestamp
C.Lifecycle age conditions begin only after the blob has remained unchanged for one complete billing cycle
D.Lifecycle age conditions are evaluated using the newest log record stored inside each blob
Correct Answer: Lifecycle age conditions are evaluated using the blob's last-modified time rather than an embedded event timestamp
Explanation:
Azure Blob lifecycle rules evaluate properties such as days since last modification. They do not parse diagnostic records to determine event age.
Incorrect! Try again.
50An ADLS Gen2 storage account is reachable only through private endpoints. Blob API operations succeed, but analytics clients using hierarchical namespace operations fail DNS resolution for the Data Lake endpoint. What should be added?
Azure Storage account
Hard
A.A second blob private endpoint in the same virtual network
B.A dfs private endpoint and corresponding private DNS configuration
C.A queue private endpoint and corresponding private DNS configuration
D.A file private endpoint and corresponding private DNS configuration
Correct Answer: A dfs private endpoint and corresponding private DNS configuration
Explanation:
ADLS Gen2 clients use the DFS endpoint for hierarchical namespace operations. Private connectivity commonly requires both blob and dfs endpoints with correct DNS resolution.
Incorrect! Try again.
51A security team needs attack-path analysis, cloud security explorer capabilities, and risk-prioritized recommendations across Azure resources. Enabling only the foundational Defender for Cloud posture features does not provide them. Which plan is required?
Correct Answer: Microsoft Defender Cloud Security Posture Management
Explanation:
Defender CSPM provides advanced posture-management capabilities such as attack-path analysis, cloud security explorer, and risk-based prioritization.
Incorrect! Try again.
52Defender for Servers Plan 2 is enabled on one subscription. Virtual machines in another subscription under the same management group remain uncovered. What is the most scalable correction?
Configure Microsoft Defender for Cloud
Hard
A.Enable Microsoft Sentinel on the management group so Defender plans are inherited automatically
B.Associate all virtual machines with the Log Analytics workspace used by the protected subscription
C.Move the uncovered virtual machines into a resource group belonging to the protected subscription
D.Use an Azure Policy initiative or management-group governance process to enable the plan on every required subscription
Correct Answer: Use an Azure Policy initiative or management-group governance process to enable the plan on every required subscription
Explanation:
Defender plans are enabled at subscription or connector scope rather than inherited automatically from another subscription. Policy can enforce consistent configuration at scale.
Incorrect! Try again.
53A legacy system temporarily cannot satisfy a Defender for Cloud recommendation. The security team must document the accepted risk, identify an owner, and automatically revisit the decision after 60 days. What should it configure?
Configure Microsoft Defender for Cloud
Hard
A.A Sentinel analytics rule that closes incidents generated by the recommendation
B.A permanent dismissal of the recommendation at the management-group scope
C.A DCR transformation that removes the associated assessment records before ingestion
D.A recommendation exemption with justification, scope, and an expiration date
Correct Answer: A recommendation exemption with justification, scope, and an expiration date
Explanation:
A time-limited exemption documents accepted risk while preventing a temporary exception from becoming permanent. Disabling or filtering the assessment removes useful governance context.
Incorrect! Try again.
54Administrators must access management ports on Azure virtual machines only after an approved request, and the ports should remain closed outside the approved interval. Which Defender capability directly addresses this requirement?
Configure Microsoft Defender for Cloud
Hard
A.Agentless machine scanning in Defender Cloud Security Posture Management
B.Sensitive data discovery in Microsoft Defender for Storage
C.Adaptive application controls in Defender for Servers Plan 1
D.Just-in-time virtual machine access in Defender for Servers Plan 2
Correct Answer: Just-in-time virtual machine access in Defender for Servers Plan 2
Explanation:
Just-in-time access keeps selected management ports closed and opens them only for approved source addresses, ports, and time windows.
Incorrect! Try again.
55Defender for Cloud reports vulnerabilities discovered through agentless scanning, but no corresponding raw vulnerability records appear in a custom Log Analytics table populated by an Azure Monitor Agent DCR. What is the best interpretation?
Configure Microsoft Defender for Cloud
Hard
A.The workspace must use the legacy Log Analytics agent because agentless scanning is incompatible with Azure Monitor Agent
B.The DCR must collect the SecurityEvent stream before Defender can expose any agentless vulnerability findings
C.Agentless scanning analyzes snapshots independently of the Azure Monitor Agent and does not require records to pass through that DCR
D.Agentless scanning writes findings to every DCR-associated workspace only after workspace retention reaches 90 days
Correct Answer: Agentless scanning analyzes snapshots independently of the Azure Monitor Agent and does not require records to pass through that DCR
Explanation:
Agentless scanning obtains security findings without depending on AMA collection. The absence of matching raw rows in a custom DCR table does not imply that scanning failed.
Incorrect! Try again.
56A SOC needs an analytics rule that evaluates events approximately once per minute and minimizes detection delay without using a custom continuous polling service. Which Sentinel rule type is most appropriate?
Microsoft Sentinel
Hard
A.A near-real-time analytics rule
B.A hunting query stored as a favorite
C.A Microsoft security incident creation rule
D.A scheduled analytics rule running hourly
Correct Answer: A near-real-time analytics rule
Explanation:
Near-real-time rules are designed for very frequent evaluation and lower detection latency than conventional scheduled analytics rules.
Incorrect! Try again.
57A large Sentinel watchlist contains malicious IP addresses. A scheduled rule must efficiently compare SigninLogs.IPAddress with the watchlist. Which design is most appropriate?
Microsoft Sentinel
Hard
A.Convert every sign-in record to JSON and compare the complete record with the watchlist
B.Run one _GetWatchlist call for each sign-in event and filter the results in a loop
C.Configure the IP field as the watchlist SearchKey and join it with SigninLogs.IPAddress
D.Store all IP fields in one watchlist column and use contains against the serialized row
Correct Answer: Configure the IP field as the watchlist SearchKey and join it with SigninLogs.IPAddress
Explanation:
Using the watchlist SearchKey for the comparison field supports more efficient matching than scanning serialized rows or repeatedly retrieving the watchlist.
Incorrect! Try again.
58A DCR transformation discards all successful sign-in events before they reach the Sentinel workspace. Investigators later need those events to establish a user's normal sign-in locations. Which statement is correct?
Microsoft Sentinel
Hard
A.Microsoft Defender for Cloud automatically recreates the events when an investigation graph is opened
B.The discarded events cannot be recovered from Sentinel, so the ingestion design must retain or separately route required events
C.Sentinel can reconstruct the discarded events from failed sign-ins by enabling user and entity behavior analytics
D.The events remain hidden in the workspace archive and become searchable after an archive restoration operation
Correct Answer: The discarded events cannot be recovered from Sentinel, so the ingestion design must retain or separately route required events
Explanation:
Ingestion-time filtering is irreversible for the destination workspace. Security and investigation requirements must be considered before a DCR drops records.
Incorrect! Try again.
59A detection must work across authentication data from several vendors whose native tables use different column names and schemas. Which Sentinel approach minimizes vendor-specific query logic?
Microsoft Sentinel
Hard
A.Rename every source table to SigninLogs through a workspace transformation
B.Export each source to storage and run one separate analytics rule per container
C.Convert every table to SecurityEvent by changing its DCR stream declaration
D.Query an Authentication ASIM parser that normalizes the vendor-specific schemas
Correct Answer: Query an Authentication ASIM parser that normalizes the vendor-specific schemas
Explanation:
Advanced Security Information Model parsers normalize fields across supported products, allowing detections and hunting queries to operate on a common schema.
Incorrect! Try again.
60A central SOC must investigate Sentinel data in several customer tenants while each customer retains its own workspace and billing boundary. Which architecture best supports delegated cross-tenant operations?
Microsoft Sentinel
Hard
A.Share each workspace ID and primary key with SOC analysts for interactive portal access
B.Use Azure Lighthouse delegation with appropriate Sentinel and Log Analytics roles in each tenant
C.Create one DCR in the SOC tenant and associate it directly with all cross-tenant workspaces
D.Move every customer workspace into the SOC tenant while leaving customer subscriptions unchanged
Correct Answer: Use Azure Lighthouse delegation with appropriate Sentinel and Log Analytics roles in each tenant
Explanation:
Azure Lighthouse provides governed cross-tenant delegation while customers retain ownership, workspace isolation, and billing responsibility.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →