You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually. You deploy Azure Sentinel. You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?

multi s3

Quiz
•
Geography
•
Professional Development
•
Easy
John Doe
Used 2+ times
FREE Resource
35 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
And a new scheduled query rule.
Add a data connector to Azure Sentinel
Configure a custom Threat Intelligence connector in Azure Sentinel.
Modify the trigger in the logic app.
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Your company uses Azure Sentinel to manage alerts from more than 10,000 IoT devices. A security manager at the company reports that tracking security threats is increasingly difficult due to the large number of incidents. You need to recommend a solution to provide a custom visualization to simplify the investigation of threats and to infer threats by using machine learning. What should you include in the recommendation?
built-in queries
livestream
notebooks
bookmarks
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
You have a playbook in Azure Sentinel. When you trigger the playbook, it sends an email to a distribution group. You need to modify the playbook to send the email to the owner of the resource instead of the distribution group. What should you do?
Add a parameter and modify the trigger.
Add a custom data connector and modify the trigger
Add a condition and modify the action.
Add an alert and modify the action.
4.
MULTIPLE SELECT QUESTION
45 sec • 1 pt
You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector. While creating a new rule from a template in the connector, you decide to generate a new alert for every event. You create the following rule query.
By which two components can you group alerts into incidents? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point
user
resource group
IP address
computer
5.
MULTIPLE SELECT QUESTION
45 sec • 1 pt
Your company stores the data of every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant. Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription. You deploy Azure Sentinel to a new Azure subscription. You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions. Which two actions should you perform?
Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Add the Security Events connector to the Azure Sentinel workspace.
Create a query that uses the workspace expression and the union operator.
Use the alias statement.
Create a query that uses the resource expression and the alias operator.
Add the Azure Sentinel solution to each workspace.
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
You have an Azure Sentinel workspace. You need to test a playbook manually in the Azure portal. From where can you run the test in Azure Sentinel?
Playbooks
Analytics
Threat intelligence
Incidents
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
You have a custom analytics rule to detect threats in Azure Sentinel. You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED. What is a possible cause of the issue?
There are connectivity issues between the data sources and Log Analytics.
The number of alerts exceeded 10,000 within two minutes.
The rule query takes too long to run and times out
Permissions to one of the data sources of the rule query were modified
Create a free account and access millions of resources
Similar Resources on Quizizz
30 questions
Gk Quiz-II

Quiz
•
KG - Professional Dev...
32 questions
JavaScript and GEE Quizz

Quiz
•
Professional Development
30 questions
Retail Consult Quiz - I Edition

Quiz
•
Professional Development
30 questions
География АТТЕСАЦИЯ-2023 -8

Quiz
•
Professional Development
30 questions
Monday Trivia 18/5

Quiz
•
Professional Development
34 questions
US National Parks

Quiz
•
Professional Development
32 questions
DES RÉSEAUX DE PRODUCTION ET D’ÉCHANGES MONDIALISÉS

Quiz
•
Professional Development
30 questions
MGNF 20

Quiz
•
Professional Development
Popular Resources on Quizizz
15 questions
Multiplication Facts

Quiz
•
4th Grade
20 questions
Math Review - Grade 6

Quiz
•
6th Grade
20 questions
math review

Quiz
•
4th Grade
5 questions
capitalization in sentences

Quiz
•
5th - 8th Grade
10 questions
Juneteenth History and Significance

Interactive video
•
5th - 8th Grade
15 questions
Adding and Subtracting Fractions

Quiz
•
5th Grade
10 questions
R2H Day One Internship Expectation Review Guidelines

Quiz
•
Professional Development
12 questions
Dividing Fractions

Quiz
•
6th Grade