Courseiva

CCNA Defender Cloud Sentinel Questions

75 of 119 questions · Page 1/2 · Defender Cloud Sentinel topic · Answers revealed

1
MCQhard

Your organization is using Microsoft Defender for Cloud to protect Azure SQL databases. You need to enable Advanced Threat Protection (ATP) for all existing and future Azure SQL databases in a subscription. The solution must minimize administrative effort. What should you do?

A.Configure Microsoft Sentinel to monitor Azure SQL databases.
B.Enable the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level.
C.Create an Azure Policy to deploy Advanced Threat Protection on Azure SQL databases.
D.Enable Advanced Threat Protection on each Azure SQL database individually.
AnswerB

Enabling the Azure SQL databases plan at subscription level activates Defender for Cloud's threat detection across every existing and future Azure SQL database automatically, with no per-database configuration. This directly satisfies the stem's requirement to minimise administrative effort, since new databases inherit protection without any further action.

Why this answer

Enabling the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level automatically enables Advanced Threat Protection (ATP) for all existing and future Azure SQL databases within that subscription. This approach requires minimal administrative effort because it applies the protection globally without needing to configure each database individually or create custom policies. Microsoft Defender for Cloud manages the ATP settings centrally, ensuring consistent security coverage across the entire subscription.

Exam trap

The trap here is that candidates often confuse enabling a Defender for Cloud plan (which is a simple toggle at the subscription level) with creating an Azure Policy (which is a more complex, policy-as-code approach), leading them to choose Option C even though it requires more administrative effort than the direct plan enablement.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) tool used for threat detection and response across multiple sources, not a mechanism to enable ATP on Azure SQL databases; it can ingest alerts from Defender for Cloud but does not enable the ATP feature itself. Option C is wrong because while an Azure Policy can enforce the deployment of ATP on Azure SQL databases, it requires creating and assigning a custom policy definition, which introduces additional administrative overhead compared to simply enabling the plan at the subscription level; the question specifically asks to minimize administrative effort. Option D is wrong because enabling ATP on each Azure SQL database individually is the most labor-intensive approach and contradicts the requirement to minimize administrative effort, as it does not automatically cover future databases.

2
MCQhard

Your organization has a complex Azure environment with multiple subscriptions, each containing hundreds of VMs and PaaS services. You are responsible for ensuring that all resources are monitored for security threats using Microsoft Defender for Cloud. The environment includes: - Subscription A: Production workloads, requires the highest security posture. - Subscription B: Development environment, has a lower security budget. - Subscription C: Shared services (e.g., DNS, Active Directory). You need to implement the most cost-effective security monitoring solution that meets the following requirements: - All subscriptions must be covered by Defender for Cloud. - Production subscription must have vulnerability assessment for VMs. - Development subscription does not need vulnerability assessment but must have basic CSPM. - Shared services subscription must have advanced threat protection for Azure SQL databases. - You must minimize administrative overhead and ensure that security policies are centrally managed. What should you do?

A.Enable all Defender plans on the management group to cover all subscriptions, then disable vulnerability assessment on Subscription B via policy.
B.Enable the 'Defender Cloud Security Posture Management' (CSPM) plan on the management group that contains all subscriptions. Then, on Subscription A, enable the 'Defender for Servers' plan with vulnerability assessment. On Subscription C, enable the 'Defender for Azure SQL' plan. Leave Subscription B with only the CSPM plan.
C.Enable the 'Defender for Servers' plan on Subscription A, 'Defender for Azure SQL' on Subscription C, and disable Defender for Cloud on Subscription B.
D.Enable only the free tier of Defender for Cloud on all subscriptions, then manually configure vulnerability assessment for VMs in Subscription A and advanced threat protection for SQL in Subscription C.
AnswerB

This option correctly treats Microsoft Defender for Cloud's plans as modular components: the CSPM plan at the management group gives every subscription a baseline of continuous security posture assessment, attack-path analysis, and regulatory compliance scoring. Then, workload-specific plans are scoped precisely—Defender for Servers on Subscription A delivers built-in vulnerability assessment (via Microsoft Defender for Endpoint or Qualys) and host-level endpoint detection, while Defender for Azure SQL on Subscription C provides SQL injection protection and anomalous access detection. Leaving Subscription B on CSPM alone is cost-effective and appropriate for a non-production environment that requires monitoring but not those advanced workload-specific defenses.

Why this answer

Option B is correct because enabling the Defender Cloud Security Posture Management (CSPM) plan at the management group scope centrally covers all subscriptions with basic CSPM at no/low cost, while selectively enabling Defender for Servers with vulnerability assessment only on Subscription A and Defender for Azure SQL only on Subscription C matches each subscription's specific requirement and minimizes cost and administrative overhead. This scoped approach avoids paying for unnecessary plans on Subscription B, which only needs basic CSPM. Option A is wrong because enabling all Defender plans on the management group would incur costs for plans not required (e.g., vulnerability assessment on Subscription B) and then require extra policy work to disable them.

Option C is wrong because disabling Defender for Cloud on Subscription B violates the requirement that all subscriptions be covered and that B have basic CSPM. Option D is wrong because the free tier does not provide the required vulnerability assessment for VMs or advanced threat protection for Azure SQL, and manual configuration increases administrative overhead.

3
Multi-Selectmedium

Which TWO actions can be performed using Microsoft Defender for Cloud's 'Regulatory Compliance' dashboard?

Select 2 answers
A.Upload evidence documents for manual controls.
B.Automatically remediate non-compliant resources.
C.View compliance score against a specific regulatory standard.
D.Configure continuous export of compliance data.
E.Integrate with third-party GRC tools directly from the dashboard.
AnswersA, C

The Regulatory Compliance dashboard supports manual attestation: for controls Defender for Cloud cannot assess automatically, you upload evidence files and mark them as compliant, which feeds the assessment. This satisfies the scenario's requirement to document manual control evidence within the dashboard.

Why this answer

Option A is correct because the Regulatory Compliance dashboard in Microsoft Defender for Cloud lets you attach evidence files to manual controls that cannot be assessed automatically, so auditors can verify attestation-based requirements. Option C is correct because the dashboard displays a compliance score for each selected regulatory standard (for example, PCI DSS, ISO 27001, or NIST SP 800-53), showing the percentage of passed controls and the breakdown by control domain. Options B, D, and E are not actions available from this dashboard: automatic remediation is driven by workflow automation or remediation logic in recommendations, continuous export is configured separately under Environment settings, and third-party GRC integration is not performed directly from the Regulatory Compliance dashboard.

Exam trap

AZ-500 often tests the distinction between viewing/attesting compliance versus remediating or exporting it, so candidates mistakenly select remediation or export options that belong to other Defender for Cloud blades.

4
MCQeasy

You are configuring Microsoft Sentinel data connectors. Which data connector should you use to ingest logs from Microsoft Entra ID (Azure AD) audit logs and sign-in logs?

A.Office 365 connector
B.Microsoft Defender XDR connector
C.Azure Activity connector
D.Microsoft Entra ID connector
AnswerD

The Microsoft Entra ID connector uses the Microsoft Graph API to stream both sign-in reports and directory audit logs into Microsoft Sentinel. Ingested data populates tables such as SigninLogs and AuditLogs, enabling detection rules for suspicious logons, MFA failures, and tenant configuration changes. This is the directly appropriate data source for monitoring identity behavior in Microsoft Entra ID.

Why this answer

The Microsoft Entra ID connector (formerly Azure AD connector) is specifically designed to ingest both audit logs and sign-in logs from Microsoft Entra ID into Microsoft Sentinel. This connector uses the Microsoft Graph API to pull the data, enabling security monitoring of identity-related activities such as user sign-ins, directory changes, and risky sign-in events. The other connectors either focus on different data sources or do not capture the full set of Entra ID logs.

Exam trap

The trap here is that candidates often confuse the Azure Activity connector (which logs Azure resource management actions) with the Entra ID connector (which logs identity and authentication events), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector ingests logs from Exchange Online, SharePoint Online, Teams, and other Office 365 workloads, not Microsoft Entra ID audit or sign-in logs. Option B is wrong because the Microsoft Defender XDR connector ingests alerts and incidents from Microsoft 365 Defender (including Defender for Endpoint, Defender for Office 365, etc.), not raw Entra ID audit or sign-in logs. Option C is wrong because the Azure Activity connector ingests subscription-level operational logs from Azure Resource Manager (e.g., create/delete resources), not identity-related logs from Entra ID.

5
Multi-Selecteasy

Which TWO features are available in Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) capabilities? (Choose two.)

Select 2 answers
A.Attack path analysis
B.Security governance and compliance scoring
C.Just-in-time VM access
D.User and Entity Behavior Analytics (UEBA)
E.Vulnerability assessment for VMs
AnswersA, B

Attack path analysis is a cloud security posture management (CSPM) capability in Microsoft Defender for Cloud that builds a graph of your cloud resources and identifies chains of misconfigurations, exposed credentials, and weak network controls that could allow an attacker to reach a critical asset. Each path is scored and visualized so security teams can prioritize a small number of fixes that break multiple high-risk attack routes. This feature belongs to the posture-management pillar, not to workload protection.

Why this answer

Attack path analysis is a CSPM capability in Microsoft Defender for Cloud that identifies the most likely sequences of actions an attacker could take to breach critical resources. It uses a graph-based model of your cloud environment to map dependencies and misconfigurations, enabling proactive risk mitigation. This is a core part of the Cloud Security Posture Management (CSPM) pillar, not a workload protection feature.

Exam trap

The trap here is that candidates confuse workload protection features (like JIT VM access and vulnerability assessment) with CSPM capabilities, which are specifically about cloud configuration posture and risk analysis, not runtime or endpoint security.

6
MCQmedium

You are using Microsoft Defender for Cloud to protect Azure Kubernetes Service (AKS) clusters. You need to receive alerts about suspicious activities within the cluster, such as privilege escalations. What should you enable?

A.Microsoft Defender for Containers
B.Microsoft Sentinel with AKS data connector
C.Azure Policy for AKS
D.Azure Security Center (classic)
AnswerA

Microsoft Defender for Containers provides Kubernetes-aware threat detection, monitoring control plane audit logs and node-level runtime activity to surface suspicious events such as privilege escalation inside AKS clusters. Enabling it satisfies the stem's requirement for cluster activity alerts, which generic Defender for Cloud plans or standalone Microsoft Entra ID controls cannot deliver.

Why this answer

Microsoft Defender for Containers is the correct solution because it provides threat detection for AKS clusters, including alerts for privilege escalations, suspicious process execution, and other runtime threats. It integrates directly with Defender for Cloud to monitor the Kubernetes audit logs and container workloads without requiring additional data connectors or agents.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender for Cloud (a cloud security posture management and threat detection tool), assuming that ingesting AKS logs into Sentinel provides the same built-in threat detection alerts as Defender for Containers, but Sentinel requires custom analytics rules to generate alerts, whereas Defender for Containers provides out-of-the-box detection for privilege escalations.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel with the AKS data connector ingests logs for security information and event management (SIEM) purposes, but it does not natively generate the specific threat detection alerts for privilege escalations within the cluster; that requires Defender for Containers. Option C is wrong because Azure Policy for AKS enforces compliance and governance rules (e.g., restricting privileged containers) but does not produce real-time security alerts for suspicious activities like privilege escalations. Option D is wrong because Azure Security Center (classic) is the predecessor to Microsoft Defender for Cloud and lacks the container-specific threat detection capabilities that Defender for Containers provides; it has been superseded and does not support the same level of AKS runtime monitoring.

7
MCQeasy

You need to ensure that security alerts from Microsoft Defender for Cloud are sent to a central SIEM system. What should you configure?

A.Create a playbook that forwards alerts to the SIEM
B.Configure diagnostic settings for the subscription
C.Assign an Azure Policy to export alerts
D.Enable continuous export to Event Hubs
AnswerD

Continuous export is a native Microsoft Defender for Cloud feature that streams security alerts and recommendations to an Event Hubs namespace or a Log Analytics workspace in near real time. This is the officially supported integration path for sending security alerts to an external SIEM, because Event Hubs serves as a high-throughput, durable ingestion endpoint that downstream tools like Splunk or QRadar can consume. You enable it per subscription or configure it centrally with Azure Policy, and it guarantees ongoing delivery without per-alert manual action. This satisfies the requirement of ensuring security alerts reach the SIEM continuously.

Why this answer

Microsoft Defender for Cloud can stream security alerts and recommendations to an Event Hubs namespace via the 'Continuous export' settings. This enables external SIEM systems, such as Splunk or Azure Sentinel, to ingest the data by connecting to the Event Hubs endpoint. Diagnostic settings export activity logs and metrics, not security alerts, and playbooks are for automated response, not data forwarding.

Exam trap

The trap here is that candidates often confuse 'diagnostic settings' (which export logs and metrics) with 'continuous export' (which specifically exports security alerts and recommendations), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because a playbook in Microsoft Sentinel or Defender for Cloud is designed for automated incident response actions (e.g., triggering a ticket or blocking an IP), not for forwarding alerts to an external SIEM. Option B is wrong because diagnostic settings export platform logs and metrics (e.g., Azure Activity log, resource metrics) to destinations like Log Analytics or Storage, but they do not include security alerts from Defender for Cloud. Option C is wrong because Azure Policy is used to enforce compliance rules and configurations across resources, not to export security alerts; it cannot directly stream alert data to a SIEM.

8
MCQeasy

You run the PowerShell command shown in the exhibit. After execution, you check the Log Analytics workspace in the Azure portal. The workspace is created successfully. However, when you try to onboard the workspace to Microsoft Sentinel, you receive an error that Sentinel cannot be enabled on this workspace. What is the most likely cause?

A.The SKU is set to PerGB2018, which is not compatible with Sentinel.
B.The resource group location is different from the workspace location.
C.The workspace is in a region that does not support Microsoft Sentinel.
D.The retention period is set to 365 days, which exceeds the maximum for Sentinel.
AnswerC

Microsoft Sentinel is not available in every Azure region. The Log Analytics workspace must reside in a region where the Sentinel solution (Microsoft.SecurityInsights) is supported. If the workspace is in an unsupported region, enabling Sentinel will fail with a region-specific error. This is the only listed condition that directly and necessarily blocks Sentinel deployment, making it the correct answer.

Why this answer

Microsoft Sentinel is not available in all Azure regions. The error 'Sentinel cannot be enabled on this workspace' most commonly occurs when the Log Analytics workspace is deployed in a region that does not support Sentinel. Even though the workspace is created successfully, Sentinel requires specific regional availability, and if the workspace region is not in the supported list, onboarding will fail.

Exam trap

The trap here is that candidates assume any Log Analytics workspace can be onboarded to Sentinel as long as it is created successfully, overlooking the critical regional restriction that Sentinel is not globally available in all Azure regions.

How to eliminate wrong answers

Option A is wrong because PerGB2018 is a valid and supported pricing tier for Log Analytics workspaces used with Microsoft Sentinel; Sentinel does not require a specific SKU. Option B is wrong because the resource group location and workspace location can be different without affecting Sentinel enablement; Sentinel only cares about the workspace's own region. Option D is wrong because a retention period of 365 days is within the allowed range for Sentinel workspaces (up to 2 years by default, extendable to 7 years with add-on); it does not block Sentinel enablement.

9
MCQhard

Refer to the exhibit. You are reviewing a scheduled analytics rule in Microsoft Sentinel that uses the KQL query shown. The rule is configured to run every hour. A security analyst reports that the rule is generating too many incidents. What is the most likely cause?

A.The rule is configured to run too frequently.
B.The query does not filter out known safe IP addresses sufficiently.
C.The query uses 'ago(1h)' which includes data from the previous hour, causing duplicate incidents.
D.The query has a syntax error that causes all sign-ins to match.
AnswerB

The query excludes only two specific IP addresses, which leaves all other internal or trusted IPs subject to creating an incident when a disabled account signs in. Because disabled-account sign-in events are often generated by old service accounts, scheduled tasks, or users who have not been offboarded, the rule should apply an allowlist of corporate egress ranges or a blocklist/allowlist combination. Without a sufficiently broad safe-IP filter, the rule will repeatedly alert on legitimate activity and drown out genuinely suspicious disabled-account access.

Why this answer

The query likely uses a broad filter for sign-in events without excluding known safe IP addresses (e.g., corporate VPNs, trusted services). This causes every sign-in from those IPs to generate an incident, overwhelming the rule with false positives. The rule's frequency (every hour) is not the issue; the query logic is insufficiently scoped.

Exam trap

The trap here is that candidates often blame the rule frequency (Option A) or the time range (Option C) without realizing that the core issue is the query's lack of IP filtering, which is a common misconfiguration in Sentinel analytics rules.

How to eliminate wrong answers

Option A is wrong because running the rule every hour is a standard frequency for sign-in monitoring; the problem is not the schedule but the query's failure to exclude benign events. Option C is wrong because 'ago(1h)' correctly limits the query to the last hour's data, preventing overlap with previous runs; it does not cause duplicate incidents. Option D is wrong because a syntax error would cause the rule to fail or return no results, not generate too many incidents.

10
MCQeasy

You are a security analyst using Microsoft Defender for Cloud. You need to ensure that any new Azure subscription added to your management group automatically receives the default security policy assignments and that security recommendations are continuously assessed. What should you enable?

A.Azure Policy initiative assignment at the management group scope.
B.Azure Arc enrollment for all servers in the subscriptions.
C.Microsoft Sentinel workspace onboarding for each subscription.
D.Microsoft Defender for Cloud auto-provisioning of the Log Analytics agent.
AnswerA

Assigning the Azure Security Benchmark or default Microsoft Defender for Cloud policy initiative at the management group scope ensures that all subscriptions within that management group inherit the policy assignments. This enables continuous assessment and automatic application of security policies to new subscriptions. It is the recommended approach for centralized governance and meets the requirement for automatic policy application.

Why this answer

To ensure that new subscriptions automatically receive security policy assignments and continuous assessment, you should assign the appropriate Azure Policy initiative (such as the Microsoft cloud security benchmark) at the management group level. Subscriptions within that management group inherit the policy, and Defender for Cloud continuously evaluates resources against the policy, providing recommendations. This centralized approach simplifies governance and ensures compliance across all subscriptions without manual intervention.

Exam trap

The trap here is assuming that enabling auto-provisioning or onboarding to Sentinel will automatically apply security policies; those features handle data collection and threat detection, not policy assignment.

11
MCQmedium

Refer to the exhibit. A Microsoft Sentinel analytics rule uses this KQL query. What is the primary purpose of this rule?

A.Detect users who have never signed in from the US before.
B.Detect users with multiple risky sign-ins from non-US countries.
C.Detect impossible travel patterns between the US and other countries.
D.Detect users whose sign-in count is higher than the average for their region.
AnswerB

The rule's KQL query aggregates sign-in logs where the risk level is marked as risky and the location is outside the United States, grouping results by user principal name. When the count of such events exceeds a threshold (for example, more than 3) within the 7-day evaluation period, an alert is triggered. This directly matches the stated detection intent, making it the correct description of the query's behavior.

Why this answer

The KQL query filters sign-ins with risk level 'medium' or 'high' from countries other than the US, then counts them per user and filters for users with more than one such sign-in. This directly detects users who have multiple risky sign-ins from non-US countries, making option B correct. The rule does not consider historical sign-in patterns or averages, only the count of risky sign-ins outside the US.

Exam trap

The trap here is that candidates may confuse 'risky sign-ins from non-US countries' with 'impossible travel' (option C), but impossible travel requires analyzing the time gap between geographically distant sign-ins, which this query does not do.

How to eliminate wrong answers

Option A is wrong because the query does not check whether a user has never signed in from the US; it only counts risky sign-ins from non-US countries, so a user could have signed in from the US safely and still trigger the rule if they have multiple risky sign-ins elsewhere. Option C is wrong because impossible travel requires analyzing time and location differences between consecutive sign-ins, but this query only counts risky sign-ins per user without any temporal or sequential analysis. Option D is wrong because the query does not compute an average for the user's region; it simply counts risky sign-ins from non-US countries and compares the count to 1, not to any regional average.

12
MCQmedium

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the purpose of this query?

A.To list all alerts with severity 'High' in the last 7 days.
B.To list the top 10 most frequent alert names along with their severity over the last 7 days.
C.To list all alerts generated in the last 7 days.
D.To list the count of alerts per severity for the last 7 days.
AnswerB

The query groups alert records by AlertName and Severity using summarize, counts the occurrences in each combination, and applies top to rank those combinations descending by count. This returns the ten most frequent alert-name/severity pairs over the rolling 7-day window, which precisely matches the stated purpose. The inclusion of both fields in the grouping key is essential to the output.

Why this answer

The KQL query uses the `summarize` operator to group alerts by `AlertName` and `Severity`, then sorts by `count_` in descending order and takes the top 10 results. This produces a list of the 10 most frequent alert names along with their severity over the last 7 days, matching option B.

Exam trap

The trap here is that candidates often confuse aggregation (`summarize`) with filtering or listing, leading them to choose options that describe simple filtering (A, C) or a different aggregation (D) instead of recognizing the top-N grouping by alert name and severity.

How to eliminate wrong answers

Option A is wrong because the query does not filter by severity 'High'; it includes all severities and summarizes counts. Option C is wrong because the query does not list all alerts individually; it aggregates them using `summarize` and limits output to the top 10. Option D is wrong because the query groups by `AlertName` and `Severity`, not by severity alone, and it returns the top 10 alert names, not a count per severity.

13
MCQmedium

Your company uses Microsoft Sentinel to monitor Azure resources. A new analytics rule is created to detect anomalous access to storage accounts. The rule runs every 5 minutes and looks at the last 15 minutes of data. After deploying, the rule generates no alerts even though you suspect there are anomalies. What is the most likely issue?

A.The rule is not enabled.
B.The rule query logic is incorrect or the entities are not properly mapped.
C.The rule severity is set too low.
D.The rule query frequency is longer than the data lookback period.
AnswerB

For a scheduled analytics rule, an alert is only created when the KQL query returns at least one row. The most common reason for silence is that the query contains incorrect logic—such as referencing a non-existent table, filtering on misspelled columns, or using a where clause that never evaluates to true—which results in zero matching records. Improper entity mapping does not directly prevent alert generation, but it can cause alerts to lack the required entity fields, which may interfere with incident creation and automation, making it appear as though the rule is failing.

Why this answer

The most likely issue is that the rule query logic is incorrect or the entities are not properly mapped. In Microsoft Sentinel, an analytics rule uses a KQL query to detect anomalies; if the query syntax is wrong, the logic fails to match the expected data patterns, or the entity mappings (e.g., Account, IP, Host) are misconfigured, the rule will not generate alerts even when anomalous activity exists. Without correct entity mapping, the rule cannot correlate events or trigger incidents, resulting in zero alerts despite underlying anomalies.

Exam trap

The trap here is that candidates often assume a rule's frequency or lookback period is the root cause, but Microsoft Sentinel allows the frequency to be shorter than the lookback period (e.g., 5 min frequency with 15 min lookback) to enable sliding window analysis; the real issue is almost always incorrect query logic or missing entity mappings.

How to eliminate wrong answers

Option A is wrong because if the rule were not enabled, it would not run at all, but the question states the rule is deployed and runs every 5 minutes, implying it is enabled. Option C is wrong because rule severity (e.g., Low, Medium, High) only affects the classification of alerts once generated, not whether alerts are generated in the first place; a low severity rule still produces alerts. Option D is wrong because the rule query frequency (5 minutes) being shorter than the data lookback period (15 minutes) is actually a valid and common configuration—it allows the rule to re-evaluate overlapping windows of data; this does not prevent alert generation.

14
MCQmedium

Your organization has multiple Azure subscriptions managed by Microsoft Defender for Cloud. You need to ensure that all subscriptions have the same security policies applied, and that any new subscription automatically inherits these policies. What should you do?

A.Create an Azure Blueprint and assign it to each subscription
B.Assign a policy initiative to a resource group and then move subscriptions into that group
C.Assign a policy initiative to each subscription individually
D.Assign a policy initiative at the management group level
AnswerD

Assigning a policy initiative at the management group scope is the correct centralized approach because all subscriptions and resource groups under that management group inherit the policy assignment automatically. This includes future subscriptions added later, which become compliant without any additional assignment effort. Management group assignments also provide a single point to manage exclusions, remediation, and compliance reporting across the entire organizational hierarchy.

Why this answer

Assigning a policy initiative at the management group level ensures that all subscriptions within that management group inherit the same security policies. When a new subscription is added to the management group, it automatically receives the assigned initiative, meeting the requirement for consistent and automatic inheritance. This is the most efficient and scalable approach for managing multiple subscriptions in Microsoft Defender for Cloud.

Exam trap

The trap here is that candidates often confuse Azure Blueprints with management group policy assignments, thinking Blueprints provide automatic inheritance, when in fact Blueprints require explicit assignment per scope and do not dynamically apply to new subscriptions.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used to deploy a repeatable set of Azure resources and policies, but they require manual assignment to each subscription and do not automatically apply to new subscriptions unless explicitly assigned again. Option B is wrong because policy initiatives cannot be assigned to resource groups and then have subscriptions moved into them; subscriptions are not moved into resource groups, and resource groups are containers for resources, not for subscriptions. Option C is wrong because assigning a policy initiative to each subscription individually would require manual effort for every existing and new subscription, failing to meet the requirement for automatic inheritance.

15
MCQmedium

Your security team is investigating a potential data exfiltration incident. They have identified that a user has been downloading large amounts of data from Azure Blob Storage to an external IP address. You need to create a Microsoft Sentinel analytics rule that triggers when more than 1 GB of data is downloaded from a storage account in a single hour. Which KQL query should be the basis of the rule?

A.StorageBlobLogs | where OperationName == 'GetBlob' | summarize TotalGB = sum(ResponseBodySize) / 1073741824 by bin(TimeGenerated, 1h) | where TotalGB > 1
B.StorageBlobLogs | where OperationName == 'GetBlob' | summarize avg(ResponseBodySize) by bin(TimeGenerated, 1h) | where avg_ResponseBodySize > 1073741824
C.StorageBlobLogs | where OperationName == 'GetBlob' and ResponseBodySize > 1073741824
D.StorageBlobLogs | where OperationName == 'GetBlob' | summarize count() by bin(TimeGenerated, 1h) | where count_ > 1000
AnswerA

This is correct because it sums the ResponseBodySize of all GetBlob operations in each one-hour bin, converting bytes to gigabytes by dividing by 1,073,741,824 (2^30). This captures the total volume of data downloaded per hour, which is the true signal for a bulk exfiltration scenario. The `where TotalGB > 1` then isolates hours where more than 1 GB left the storage account, aligning with the security team's threshold.

Why this answer

Option A is correct because it filters StorageBlobLogs to GetBlob operations, sums ResponseBodySize (which is in bytes) over a one-hour bin, converts the total to gigabytes by dividing by 1073741824, and then filters for totals greater than 1 GB — exactly matching the requirement to detect more than 1 GB downloaded per hour. Option B uses avg(ResponseBodySize), which measures the average size of individual downloads rather than the total volume, so it would not detect aggregate exfiltration. Option C checks each individual GetBlob event against 1 GB, missing the scenario where many smaller downloads sum to over 1 GB in an hour.

Option D counts the number of GetBlob operations rather than bytes transferred, so it does not measure data volume at all.

16
Multi-Selecthard

Which THREE of the following are capabilities of Microsoft Defender for Cloud's workload protection plans?

Select 3 answers
A.Adaptive application controls
B.DDoS protection
C.Data Loss Prevention (DLP)
D.File Integrity Monitoring (FIM)
E.Just-in-time (JIT) VM access
AnswersA, D, E

Adaptive application controls are a workload-protection capability in Microsoft Defender for Cloud that uses machine learning to establish a baseline of applications permitted to run on a specific set of Azure or non-Azure VMs. In audit mode, it learns typical running processes; in enforce mode, it blocks untrusted executables and generates security alerts. This feature directly protects the workload plane, distinguishing it from network-layer services like DDoS protection.

Why this answer

Adaptive application controls (A) are a capability of Microsoft Defender for Cloud's workload protection plans. They use machine learning to analyze processes running on Azure and non-Azure machines, allowing you to define allowlists for known safe applications and generate security alerts when unauthorized applications execute, thus reducing the attack surface.

Exam trap

The trap here is that candidates may confuse Azure DDoS Protection (a separate network-layer service) or Microsoft Purview DLP (a data security solution) as being part of Defender for Cloud's workload protection plans, when in fact they are distinct services with different scopes and integration points.

17
MCQeasy

You are responsible for securing an Azure environment using Microsoft Defender for Cloud. You need to reduce the number of false positive security alerts for a specific Azure SQL Database. The database is regularly scanned by a legitimate security tool that generates alerts. What should you do?

A.Disable the security alert rule for SQL databases in Defender for Cloud.
B.Exclude the database from the vulnerability assessment solution.
C.Create a suppression rule for the specific alert type and source IP address.
D.Modify the Azure SQL Database firewall rules to allow the scanning tool's IP.
AnswerC

Creating a suppression rule for the specific alert type and source IP address is the targeted, recommended solution. Defender for Cloud lets you define a rule on an alert that automatically dismisses future matches based on properties like entity, IP address, or attack evidence, so benign scanning activity from that IP is ignored while all other alerts continue to fire. This reduces alert fatigue without disabling any detection capability.

Why this answer

Microsoft Defender for Cloud allows you to create suppression rules to automatically filter out specific security alerts that are known to be benign. By configuring a suppression rule for the specific alert type and the source IP address of the legitimate security scanning tool, you can prevent those alerts from appearing in the security alerts queue without disabling broader detection for SQL databases. This approach reduces false positives while maintaining visibility into other potential threats.

Exam trap

The trap here is that candidates often confuse suppression rules (which filter alerts) with disabling detection rules or modifying firewall settings, thinking that blocking the source IP or disabling the rule entirely is the correct way to handle false positives.

How to eliminate wrong answers

Option A is wrong because disabling the entire security alert rule for SQL databases would stop all alerts for that resource, including legitimate threat detections, leaving the database unprotected. Option B is wrong because excluding the database from the vulnerability assessment solution would prevent the assessment from scanning for vulnerabilities, but the false positive alerts are generated by security alerts (e.g., SQL injection detection), not by the vulnerability assessment itself. Option D is wrong because modifying the Azure SQL Database firewall rules to allow the scanning tool's IP addresses does not affect how Defender for Cloud generates alerts; firewall rules control network access, not alert suppression.

18
MCQmedium

Your security operations center (SOC) uses Microsoft Sentinel. You need to ensure that an incident is automatically created when a specific type of alert fires from Microsoft Defender for Cloud. What is the most efficient way to configure this?

A.Create a playbook that triggers on alert and generates an incident via API.
B.Configure the Microsoft Defender for Cloud data connector in Sentinel and enable incident creation.
C.Design a workbook to monitor alerts and manually create incidents.
D.Write a scheduled analytics rule that queries Defender for Cloud logs.
AnswerB

The Microsoft Defender for Cloud data connector in Microsoft Sentinel is the native integration that ingests security alerts from Defender for Cloud plans into your workspace, and enabling incident creation on that connector activates the built-in analytics rule that automatically generates a Sentinel incident for each incoming alert. This is the intended, supportable path because it requires no custom code or manual effort, and it ensures that Defender for Cloud detection signals flow directly into your SOC incident queue for triage and investigation.

Why this answer

Option B is correct because the Microsoft Defender for Cloud data connector in Microsoft Sentinel includes an option to automatically create incidents from Defender for Cloud alerts, which is the native and most efficient integration for this scenario. Once the connector is configured and incident creation is enabled, alerts from Defender for Cloud flow into Sentinel and generate incidents without custom automation. Option A is unnecessary because a playbook and API calls add complexity when the connector already supports automatic incident creation.

Option C is incorrect because workbooks are only for visualization and do not create incidents, and manual creation is not automatic. Option D is also incorrect because scheduled analytics rules query log data on a schedule and are not the intended mechanism for ingesting Defender for Cloud alerts as incidents.

19
MCQhard

Your organization is migrating to Azure and needs to protect against advanced threats like fileless malware. You must use a solution that provides real-time protection and integrates with Microsoft Defender for Cloud. What should you deploy on Azure VMs?

A.Microsoft Antimalware for Azure
B.Microsoft Defender for Endpoint (Microsoft Defender XDR)
C.Azure Monitor Agent (AMA)
D.Azure Security Center (free tier)
AnswerB

Microsoft Defender for Endpoint, integrated into Microsoft Defender XDR, provides true endpoint detection and response with continuous memory scanning, kernel-level behavioral monitoring, and cloud-driven machine learning. It identifies fileless malware by correlating anomalous process activity, script execution, and in-memory indicators, then automatically contains the host. This capability is precisely why it, not any agent-based scanner, defeats fileless attacks.

Why this answer

Microsoft Defender for Endpoint (part of Microsoft Defender XDR) provides next-generation protection, including behavior-based, real-time detection of fileless malware and other advanced threats. It integrates natively with Microsoft Defender for Cloud to deliver unified security management and automated response for Azure VMs, meeting the requirement for real-time protection against sophisticated attacks.

Exam trap

The trap here is that candidates often confuse Microsoft Antimalware for Azure (a legacy, signature-based solution) with modern endpoint detection and response (EDR) capabilities, mistakenly believing it can handle fileless malware when it cannot.

How to eliminate wrong answers

Option A is wrong because Microsoft Antimalware for Azure is a signature-based antimalware solution that lacks the behavioral analysis and machine learning capabilities needed to detect fileless malware; it also does not integrate with Defender for Cloud for advanced threat protection. Option C is wrong because Azure Monitor Agent (AMA) is a data collection agent for monitoring and diagnostics, not a security solution for real-time malware protection. Option D is wrong because Azure Security Center (free tier) provides basic security assessment and recommendations but does not include real-time endpoint protection or advanced threat detection capabilities.

20
MCQhard

Your company, Contoso Ltd., has a hybrid environment with 500 on-premises Windows servers and 200 Azure VMs. The Azure VMs are spread across multiple subscriptions. You need to implement a centralized security monitoring solution using Microsoft Sentinel. The requirements are: - Collect security events from all on-premises servers. - Collect Azure activity logs and VM logs from all Azure subscriptions. - Detect and respond to threats using built-in and custom analytics. - Automatically remediate common threats such as disabling compromised user accounts. - Ensure compliance with regulatory standards (e.g., NIST 800-53). - Minimize administrative overhead and cost. What should you do?

A.Install Microsoft Monitoring Agent on on-premises servers and connect to a Log Analytics workspace. Enable Sentinel. Use Azure Automation runbooks for remediation.
B.Enable Microsoft Defender for Cloud on all subscriptions and install Defender for Endpoint on all servers. Forward logs to a third-party SIEM.
C.Create a Log Analytics workspace and enable Sentinel on the Free tier. Use KQL queries for detection and manual remediation.
D.Deploy Azure Arc on all on-premises servers. Use Azure Monitor Agent with Data Collection Rules to collect security events. Enable Microsoft Sentinel on a Log Analytics workspace. Configure analytics rules and automation rules with playbooks for remediation.
AnswerD

Deploying Azure Arc gives on-premises servers an Azure Resource Manager identity, allowing them to be governed with Azure Policy, Defender for Cloud, and Data Collection Rules just like Azure VMs. Azure Monitor Agent, configured via Data Collection Rules, efficiently collects Windows and Linux security events and forwards them to a Log Analytics workspace where Microsoft Sentinel ingests and analyzes them. Sentinel analytics rules detect threats and generate incidents, while automation rules trigger Azure Logic Apps playbooks for consistent, automated remediation. This is the current, fully supported hybrid SIEM/SOAR design that unifies on-premises and cloud security operations.

Why this answer

Option D is correct because it uses Azure Arc to onboard the 500 on-premises Windows servers into Azure, then Azure Monitor Agent (AMA) with Data Collection Rules (DCRs) to collect Windows security events into a Log Analytics workspace where Microsoft Sentinel is enabled; Sentinel's analytics rules provide built-in and custom threat detection, and automation rules with playbooks (Logic Apps) deliver automated remediation such as disabling compromised accounts, while Sentinel's compliance workbook and built-in NIST 800-53 content address regulatory requirements. This approach centralizes monitoring across all subscriptions and on-premises servers with minimal administrative overhead. Option A is outdated because the Microsoft Monitoring Agent (MMA) is deprecated in favor of AMA, and it lacks the Arc-based onboarding and DCR-based collection needed for modern hybrid coverage.

Option B does not meet the requirement for Microsoft Sentinel, since it forwards logs to a third-party SIEM instead. Option C relies on manual remediation and the Sentinel Free tier, which has limited data ingestion and retention, so it does not satisfy automated remediation or compliance needs.

21
MCQmedium

You are a security engineer for a large enterprise using Microsoft Sentinel. You have multiple workspaces deployed across different Azure regions to meet data residency requirements. You need to query data across all workspaces from a single query. You have set up a workspace as the 'central' workspace for cross-workspace queries. The central workspace has the necessary permissions to access the other workspaces. Which KQL operator should you use to include data from other workspaces in your query?

A.where
B.union
C.join
D.project
AnswerB

Correct. In Kusto Query Language (KQL), the union operator merges rows from two or more table expressions, and its workspace('workspace-id') function lets each branch point to another Log Analytics/Microsoft Sentinel workspace. This makes union the fundamental operator for cross-workspace queries: each table reference can be rewritten as workspace('<workspace>').<Table>, and the results are concatenated into a single result set.

Why this answer

The correct option is B, the union operator, because in Microsoft Sentinel and Azure Monitor Log Analytics, cross-workspace queries are performed by using union with workspace identifiers, such as union workspace("WorkspaceName").TableName, which combines rows from tables in the central workspace and the referenced workspaces into a single result set. This matches the scenario where the central workspace has permissions to query the other workspaces for data residency-compliant cross-region reporting. The where operator only filters rows within a single table and cannot reference another workspace, join correlates columns across tables but does not by itself aggregate multiple workspaces, and project only selects or renames columns from an existing result set.

Therefore, union is the only operator that satisfies the requirement to include data from other workspaces in one query.

22
MCQeasy

You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory. Which two data connectors are necessary to collect sign-in logs and audit logs?

A.Azure Activity and Azure Active Directory Audit logs
B.Office 365 and Azure Active Directory Sign-in logs
C.Azure Active Directory Sign-in logs and Azure Active Directory Audit logs
D.Security Events and Azure Active Directory Sign-in logs
AnswerC

Azure Active Directory Sign-in Logs ingest authentication and authorization events, such as successful and failed user sign-ins, conditional access results, and MFA challenges. Azure Active Directory Audit Logs capture all directory-management activities, including user creation, group membership changes, password resets, and application role assignments. These two complementary connectors provide the full AAD security telemetry needed to monitor both user access and administrative changes in Microsoft Sentinel.

Why this answer

To collect sign-in logs and audit logs in Microsoft Sentinel, you need the Azure Active Directory Sign-in logs connector for sign-in activity and the Azure Active Directory Audit logs connector for directory changes and user management events. These two connectors directly correspond to the two log categories required by the question.

Exam trap

The trap here is that candidates confuse Azure Activity logs (subscription-level) with Azure AD Audit logs (tenant-level), or assume Office 365 logs include Azure AD sign-in events, when in fact each log type requires its own dedicated connector.

How to eliminate wrong answers

Option A is wrong because Azure Activity logs capture subscription-level control plane events (e.g., resource creation), not Azure AD sign-in or audit logs. Option B is wrong because Office 365 connector collects Exchange, SharePoint, and Teams logs, not Azure AD sign-in logs; the Azure AD Sign-in logs connector is required separately. Option D is wrong because Security Events are Windows security logs from virtual machines, not Azure AD sign-in or audit logs.

23
MCQmedium

A company has enabled Microsoft Defender for Cloud on all subscriptions. The security team wants to ensure that all virtual machines have vulnerability assessment solutions installed. What should they configure?

A.Enable Azure Update Management for all VMs
B.Enable the Vulnerability Assessment solution in Defender for Cloud and set it to 'On'
C.Create an Azure Policy to audit VMs without vulnerability assessment
D.Use Azure Automation to run a script that installs a vulnerability scanner
AnswerB

The Vulnerability Assessment solution in Microsoft Defender for Cloud, when set to 'On', auto-provisions a built-in scanner (Qualys or Microsoft Defender Vulnerability Management) to supported machines. This continuously scans for known CVEs, misconfigurations, and security weaknesses, and surfaces findings in the Defender for Cloud recommendations and Secure Score. It is the native, integrated way to meet the requirement of vulnerability assessment across all VMs.

Why this answer

Microsoft Defender for Cloud provides a built-in Vulnerability Assessment solution that can be enabled at the subscription level. When set to 'On', it automatically deploys the Qualys or Microsoft threat and vulnerability management agent to all supported Azure VMs, ensuring continuous vulnerability scanning without manual intervention.

Exam trap

The trap here is that candidates often confuse 'auditing' (Option C) with 'remediation' — an Azure Policy audit only checks compliance, but the question asks to ensure the solution is installed, which requires enabling the built-in Defender for Cloud vulnerability assessment solution.

How to eliminate wrong answers

Option A is wrong because Azure Update Management focuses on OS patch compliance, not vulnerability assessment; it does not scan for software vulnerabilities or misconfigurations. Option C is wrong because an Azure Policy to audit VMs without vulnerability assessment only reports non-compliance but does not install or enable the solution; it requires a separate remediation task or initiative to deploy the agent. Option D is wrong because using Azure Automation to run a custom script is a manual, non-native approach that lacks integration with Defender for Cloud's centralized vulnerability reporting and auto-provisioning capabilities.

24
MCQhard

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). You need to investigate a possible insider threat where a user is accessing sensitive data from unusual locations. Which Sentinel feature should you use to visualize the user's activities and related entities?

A.Hunting queries
B.UEBA investigation insights and entity pages
C.Analytics rules
D.Workbooks
AnswerB

Microsoft Sentinel's UEBA builds entity pages that consolidate a user, device, or other entity's activity into a single pane, including a timeline, related entities, and behavioral analytics. These pages surface investigation insights like anomalous logon patterns, impossible travel, and peer-group deviations, which are automatically generated via machine learning baselines. This gives analysts an entity-centric, visual starting point for investigation, making it the exact feature that matches the question's requirement for timeline and related-entity visualization.

Why this answer

UEBA in Microsoft Sentinel provides investigation insights and entity pages that aggregate user activities, related entities, and behavioral anomalies into a visual timeline. This allows you to see a user's access patterns from unusual locations and correlate them with other entities like devices or IP addresses, making it the correct feature for investigating insider threats.

Exam trap

The trap here is that candidates confuse the proactive, query-based nature of Hunting queries with the reactive, visual investigation capabilities of UEBA entity pages, leading them to select Option A when they need to investigate a specific user's behavior.

How to eliminate wrong answers

Option A is wrong because Hunting queries are proactive searches for threats using KQL, not a visual investigation tool for a specific user's activities and related entities. Option C is wrong because Analytics rules are used to generate alerts based on predefined conditions, not to visualize or investigate a user's historical behavior and entity relationships. Option D is wrong because Workbooks are customizable dashboards for reporting and monitoring, not designed for interactive, entity-centric investigation of a single user's activities.

25
MCQeasy

A security analyst receives a high-severity alert in Microsoft Sentinel indicating a potential brute-force attack against an Azure VM. The analyst wants to automatically block the attacker IP for 24 hours. What is the most efficient way to achieve this?

A.Create an automation rule in Sentinel that runs a playbook to add a deny NSG rule.
B.Enable Just-in-Time VM access to restrict all RDP traffic.
C.Create an Azure Policy to deny all traffic from the attacker IP.
D.Manually add a deny rule to the NSG attached to the VM's subnet.
AnswerA

An automation rule in Microsoft Sentinel triggers a playbook—a Logic Apps workflow—that can programmatically add a deny rule to the network security group (NSG) attached to the VM's subnet, blocking the attacker's source IP. This provides immediate and consistent containment without manual intervention, making it the correct response for a high-severity alert requiring rapid network-level blocking.

Why this answer

It leverages Microsoft Sentinel's automation rules to trigger a playbook that programmatically adds a deny Network Security Group (NSG) rule, blocking the attacker's IP for a specified duration. This is the most efficient approach as it automates the response without manual intervention, directly modifying the NSG attached to the VM's subnet to drop inbound traffic from the malicious IP.

Exam trap

The trap here is that candidates may confuse Azure Policy (which is for compliance and governance) with NSG rules (which are for network traffic control), or mistakenly think Just-in-Time VM access can block a specific IP, when it only manages port access timing.

How to eliminate wrong answers

Option B is wrong because Just-in-Time (JIT) VM access controls inbound RDP/SSH access via Azure Security Center, but it does not block a specific attacker IP; it reduces the attack surface by opening ports only when needed, not by adding a deny rule for a particular address. Option C is wrong because Azure Policy is used for enforcing organizational compliance and governance rules (e.g., requiring specific tags or SKUs), not for real-time, dynamic network access control like blocking an IP address. Option D is wrong because manually adding a deny rule to the NSG is inefficient and not automated; it requires human intervention, which delays response time and is not suitable for a high-severity alert requiring immediate action.

26
Multi-Selectmedium

Which TWO are benefits of using Microsoft Sentinel's automation rules? (Choose two.)

Select 2 answers
A.Aggregate multiple incidents into a single incident.
B.Create new analytics rules based on incident patterns.
C.Automatically query external threat intelligence feeds.
D.Trigger a playbook when an incident is created or updated.
E.Automatically assign incidents to a specific analyst or team.
AnswersD, E

A primary benefit of automation rules is the 'Run playbook' action, which can be triggered automatically when an incident is created or updated. This enables incident response teams to execute Logic Apps that perform enrichment, containment, or remediation steps without manual intervention. Playbooks can be invoked with the incident as context, making it easy to gather data, block indicators, or send notifications.

Why this answer

Option D is correct because Microsoft Sentinel automation rules can define conditions (such as incident creation or update) and then invoke a playbook (Logic App) as the action, enabling automated response workflows. Option E is correct because automation rules support an 'Assign owner' action, letting you automatically route incidents to a specific analyst or team based on rule conditions. Options A, B, and C are not benefits of automation rules: incident aggregation/merging is handled by the incident merging feature rather than automation rules, analytics rules are created manually or via templates/API rather than generated from incident patterns by automation rules, and querying external threat intelligence feeds is performed through threat intelligence connectors, watchlists, or analytics rule queries, not automation rules.

Exam trap

The trap here is that candidates confuse automation rules with analytics rules or playbooks, mistakenly thinking automation rules can create rules or query external feeds, when in fact automation rules only respond to incidents with predefined actions.

27
MCQhard

You are a security analyst using Microsoft Sentinel. You need to create an analytics rule that triggers an incident when more than 10 failed sign-ins occur from the same IP address within 5 minutes. The rule should use a KQL query. Which query should you use?

A.SigninLogs | where ResultType !in ("0","50125") // failed attempts | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10
B.SigninLogs | where ResultType != "0" | make-series Count=count() default=0 on TimeGenerated from ago(5m) to now() step 5m by IPAddress
C.SigninLogs | where ResultType == "0" | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10
D.SigninLogs | where ResultType == "0" | summarize Count = count() by IPAddress, bin(time-generated, 5m) | where Count > 10
AnswerA

This query correctly groups failed sign-ins by IP and 5-minute bin, and filters for >10.

Why this answer

It filters for failed sign-ins by excluding successful results (ResultType '0' and '50125', where '50125' is a non-failure code), then uses `summarize` with `bin(TimeGenerated, 5m)` to count failed attempts per IP address within 5-minute windows, and finally filters for counts exceeding 10. This directly meets the requirement to trigger an incident when more than 10 failed sign-ins occur from the same IP within 5 minutes.

Exam trap

The trap here is that candidates often confuse the ResultType values, mistakenly filtering for successful sign-ins (ResultType == '0') instead of failed sign-ins, or they use `make-series` which is designed for time-series analysis rather than event counting with threshold filtering.

How to eliminate wrong answers

Option B is wrong because `make-series` creates a time series with default values, which is not appropriate for counting discrete events and does not filter for failed sign-ins (it includes all ResultType values except '0'). Option C is wrong because it filters for successful sign-ins (`ResultType == '0'`), which is the opposite of what is needed. Option D is wrong because it filters for successful sign-ins (`ResultType == '0'`) and uses an incorrect field name `time-generated` (should be `TimeGenerated`), which would cause the query to fail or return no results.

28
MCQhard

You are configuring Microsoft Defender for Cloud's 'Workload protections' for a Kubernetes cluster that is already using Azure Kubernetes Service (AKS). The cluster has 'Azure Policy' enabled. You need to enable the 'Microsoft Defender for Containers' plan to protect the cluster. You have already enabled the plan at the subscription level. However, the cluster is not showing as protected in the 'Inventory' blade. You have confirmed that the 'Azure Policy for Kubernetes' add-on is installed. What should you do to ensure the cluster is protected?

A.Install the 'Defender profile' on the AKS cluster.
B.Enable the 'Azure Policy for Kubernetes' add-on on the cluster.
C.Wait for 24 hours for the protection to automatically apply.
D.Install the Log Analytics agent on the cluster nodes.
AnswerA

Installing the Defender profile is the correct action because Microsoft Defender for Cloud’s Defender for Containers plan uses a dedicated DaemonSet on each AKS node to collect security signals such as Kubernetes audit logs, node events, and container runtime telemetry. The profile must be explicitly enabled on the cluster; enabling the plan at the subscription level alone does not protect existing clusters. Without this profile, the cluster remains visible in Defender for Cloud but lacks workload-level threat detection.

Why this answer

Even with the subscription-level plan enabled, you need to install the 'Defender profile' on the AKS cluster to enable protection. The Defender profile deploys the necessary agents for threat detection. Option A is correct.

Option B is incorrect because Azure Policy for Kubernetes is already enabled; it is a separate feature. Option C is incorrect because protection does not automatically apply; you must install the profile. Option D is incorrect because the Log Analytics agent is not required for Defender for Containers; the Defender profile handles agent deployment.

29
MCQmedium

Your company has a hybrid environment with on-premises servers and Azure VMs. All resources are onboarded to Microsoft Defender for Cloud. You need to receive alerts when a critical vulnerability is detected on any server. The security team wants to minimize false positives. What should you configure?

A.Enable vulnerability assessment for servers via the integrated VA solution.
B.Configure just-in-time VM access to reduce attack surface.
C.Enable adaptive application controls to detect unapproved software.
D.Enable file integrity monitoring on critical files.
AnswerA

The integrated vulnerability assessment (VA) solution in Microsoft Defender for Cloud, powered by Qualys, performs agent-based scans of the OS and installed software to identify missing patches, insecure configurations, and known Common Vulnerabilities and Exposures (CVEs). It surfaces these findings as security recommendations and can generate alerts when discovered vulnerabilities align with known attack vectors. For on-premises and hybrid servers, you must first onboard them to Azure Arc and enable the Defender for Servers plan so the VA scanner can report to the cloud workload-protection dashboard.

Why this answer

Microsoft Defender for Cloud's integrated vulnerability assessment (VA) solution, powered by Qualys or Microsoft Defender Vulnerability Management, continuously scans servers for known CVEs and generates security alerts when critical vulnerabilities are found. This directly meets the requirement to receive alerts on critical vulnerabilities while minimizing false positives, as the VA solution uses curated, verified vulnerability data rather than heuristic or behavioral detections that might produce noise.

Exam trap

The trap here is that candidates confuse vulnerability detection (finding CVEs) with other security controls like access restriction (JIT), application whitelisting (AAC), or change monitoring (FIM), all of which address different threat vectors and do not directly alert on critical vulnerabilities.

How to eliminate wrong answers

Option B is wrong because just-in-time (JIT) VM access reduces the attack surface by controlling network access to management ports, but it does not detect or alert on critical vulnerabilities; it is a preventive control, not a detection mechanism. Option C is wrong because adaptive application controls (AAC) create allowlists for approved software and generate alerts only when unapproved software runs, which addresses application control, not vulnerability detection; it would miss critical OS-level or service-level CVEs. Option D is wrong because file integrity monitoring (FIM) tracks changes to critical files and registry keys, alerting on modifications, not on vulnerabilities; it would not detect a critical CVE unless the vulnerability itself caused a file change, which is unreliable and indirect.

30
MCQhard

You are designing a Microsoft Sentinel deployment for a multinational company. The company requires that data from different geographic regions be stored separately to comply with data residency laws. What is the recommended approach?

A.Deploy a single Sentinel workspace and use Azure Purview to tag data for residency.
B.Deploy a single Sentinel workspace and configure diagnostic settings to send data to separate Log Analytics workspaces.
C.Deploy a single Sentinel workspace and use data collection rules to route data to different storage accounts.
D.Deploy a separate Microsoft Sentinel workspace in each required region.
AnswerD

Each Microsoft Sentinel workspace is functionally a Log Analytics workspace with Sentinel enabled, and the workspace's location determines where all underlying data is stored at rest. Deploying Sentinel in each required region creates separate, region-pinned data stores that fully contain that region's logs, satisfying residency requirements. This also allows rules and workbooks to be scoped to local data, though cross-workspace queries or Azure Lighthouse can still provide a pane-of-glass view for centralized monitoring.

Why this answer

Microsoft Sentinel is built on top of Log Analytics workspaces, and each workspace is a distinct data container with its own retention, encryption, and geographic location. To comply with data residency laws that require data from different regions to be stored separately, you must deploy a separate Sentinel workspace in each required region. This ensures that data ingested from a specific region remains within that region's boundaries and is not mixed with data from other regions.

Exam trap

The trap here is that candidates may think data collection rules or diagnostic settings can route data to different storage accounts or workspaces within a single Sentinel instance, but Sentinel's architecture requires each workspace to be a separate Log Analytics workspace with its own regional binding.

How to eliminate wrong answers

Option A is wrong because Azure Purview is a data governance and catalog service, not a data routing or residency enforcement tool; it cannot separate stored data by region within a single Sentinel workspace. Option B is wrong because diagnostic settings send data to a Log Analytics workspace, but a single Sentinel workspace is tied to a single Log Analytics workspace; you cannot use diagnostic settings to split data into separate Log Analytics workspaces from within one Sentinel deployment. Option C is wrong because data collection rules (DCRs) in Azure Monitor can route data to different destinations like storage accounts, but Sentinel requires data to be in a Log Analytics workspace to be analyzed; routing to separate storage accounts does not satisfy the requirement for separate Sentinel workspaces for regional data residency.

31
MCQmedium

You are a security engineer managing a Microsoft Sentinel workspace. The security operations team wants to automatically create a ServiceNow incident whenever a new high-severity incident is generated in Microsoft Sentinel. You need to configure the automation rule to trigger only for incidents with severity High and to include the incident's entities in the ServiceNow ticket. What should you do first?

A.Enable the Microsoft Sentinel data connector for ServiceNow and configure the connector to automatically create incidents for all high-severity alerts.
B.Create an analytics rule that generates an incident and configure its incident settings to run a playbook automatically.
C.Create a playbook that uses the ServiceNow connector, then create an automation rule with the condition Severity equals High and add an action to run the playbook.
D.Create a workbook that monitors incidents and use Azure Logic Apps to send an email to the security team when a high-severity incident occurs.
AnswerC

Automation rules in Microsoft Sentinel can trigger playbooks based on incident conditions. The playbook must be created first, then referenced in the automation rule. The condition Severity equals High ensures only high-severity incidents trigger the playbook, and the playbook can access incident entities to populate ServiceNow fields. This is the correct sequence to achieve the requirement.

Why this answer

Automation rules in Microsoft Sentinel allow you to define conditions and actions that run when incidents are created or updated. To integrate with ServiceNow, you must first create a playbook that contains the logic to create a ServiceNow incident, using the ServiceNow connector. Then, you create an automation rule that triggers on High severity incidents and runs that playbook.

This ensures that only high-severity incidents result in ServiceNow tickets, and the playbook can access incident entities to populate the ticket details.

Exam trap

The trap here is confusing the direction of the ServiceNow connector: it ingests ServiceNow data into Sentinel, not the reverse; outbound automation requires playbooks triggered by automation rules.

32
MCQhard

A security team uses Microsoft Defender for Cloud's regulatory compliance dashboard to track compliance with PCI DSS. They notice that some controls are marked as 'N/A' even though they have relevant resources. What is the most likely reason?

A.The resources do not have the required custom assessment.
B.The compliance dashboard requires a Microsoft Purview Compliance Manager license.
C.The resources are in a subscription that is not included in the scope of the compliance standard.
D.The resources have not been manually claimed as compliant.
AnswerC

In Defender for Cloud, each regulatory compliance standard is assigned to a specific scope, such as a subscription or management group, when you enable it. Only resources within that assigned scope are evaluated and reported in the compliance dashboard, and resources in unassigned subscriptions are completely ignored. If the subscription containing the resources is not part of the standard's assignment, those resources will not appear in the compliance view.

Why this answer

The correct answer is C: resources in a subscription that is not included in the scope of the compliance standard. In Microsoft Defender for Cloud's regulatory compliance dashboard, a control is shown as 'N/A' when the standard's assessment scope does not cover the subscription containing those resources, so the control is not evaluated against them. This scoping is configured when assigning the regulatory compliance standard, and only in-scope subscriptions are assessed.

Option A is incorrect because a missing custom assessment would leave a control unassessed or healthy/unhealthy, not scoped out as N/A. Option B is incorrect because the regulatory compliance dashboard is a Defender for Cloud capability and does not require a Microsoft Purview Compliance Manager license. Option D is incorrect because manual attestation affects a control's compliance state, not whether it is marked N/A due to scope.

33
Multi-Selectmedium

Your company uses Microsoft Defender for Cloud to protect Azure resources. You want to enable the 'Defender for Containers' plan to secure AKS clusters. Which two configurations are necessary? (Choose two.)

Select 2 answers
A.Assign the 'Kubernetes cluster should be accessible only through private endpoint' Azure Policy.
B.Connect the AKS cluster to Azure Arc.
C.Enable the 'Defender for Containers' plan in Microsoft Defender for Cloud.
D.Install the Log Analytics agent on each AKS node.
E.Ensure the AKS cluster's audit logs are enabled and streamed to a Log Analytics workspace.
AnswersC, E

Enabling the 'Defender for Containers' plan in Microsoft Defender for Cloud is the fundamental step that activates threat detection, vulnerability assessment, and security recommendations for AKS clusters. This plan must be turned on for the subscription that contains the cluster; once enabled, Defender automatically deploys the necessary components to collect and analyze security signals. Without this plan, no amount of audit logging or agent installation will produce Defender's container-specific protection.

Why this answer

Enabling the 'Defender for Containers' plan in Microsoft Defender for Cloud is the primary configuration required to activate threat detection and security monitoring for AKS clusters. Option E is correct because audit logs must be enabled and streamed to a Log Analytics workspace to provide the necessary data for Defender for Containers to analyze Kubernetes audit events and detect suspicious activities.

Exam trap

The trap here is that candidates often confuse the Log Analytics agent requirement with the actual data collection mechanism, mistakenly thinking it must be installed on each node, whereas Defender for Containers uses its own dedicated Defender profile and relies on audit log streaming instead.

34
MCQmedium

Your organization uses Microsoft Defender for Cloud's workload protection for Azure SQL databases. You notice that Defender for Cloud is not generating alerts for anomalous activities on a specific SQL database. The database is in a VNet with a service endpoint enabled for SQL. What should you verify first?

A.Ensure the service endpoint is configured correctly.
B.Enable Advanced Threat Protection on the Azure SQL Server.
C.Enable auditing on the SQL database.
D.Configure a firewall rule to allow Defender for Cloud IP addresses.
AnswerB

Advanced Threat Protection (ATP) for Azure SQL Server (also known as Defender for SQL) must be enabled at the server level; it activates vulnerability assessment, anomaly detection, and the alerting engine that surface suspicious activities like SQL injection, brute-force attempts, or unusual access patterns. When ATP is on, Microsoft Defender for Cloud automatically collects and displays these SQL-specific security alerts in its alerts pane. Without ATP enabled, no anomaly-based SQL alert will ever appear in Defender for Cloud, regardless of auditing, firewalls, or service endpoints.

Why this answer

Defender for Cloud's workload protection for Azure SQL databases relies on Advanced Threat Protection (ATP) being enabled at the Azure SQL Server level. Without ATP enabled, Defender for Cloud cannot generate alerts for anomalous activities, regardless of network configurations like VNet service endpoints. Enabling ATP activates the threat detection engine that monitors SQL audit logs for suspicious patterns.

Exam trap

The trap here is that candidates often assume network-level controls (like service endpoints or firewall rules) are the root cause for missing alerts, when the actual requirement is enabling the threat detection feature (ATP) at the server level.

How to eliminate wrong answers

Option A is wrong because the service endpoint is correctly configured for SQL, as stated in the scenario, and service endpoints are for network connectivity, not for enabling threat detection alerts. Option C is wrong because auditing is a prerequisite for ATP to analyze logs, but enabling auditing alone does not activate the threat detection engine; ATP must be explicitly enabled. Option D is wrong because Defender for Cloud does not require specific IP addresses to be allowed; it analyzes audit logs stored in Azure, not direct network traffic to the database.

35
MCQeasy

Your company has multiple Azure subscriptions and wants to use Microsoft Sentinel as a SIEM. You need to collect security events from all Azure VMs, including existing and future ones. What should you use?

A.Use the Azure portal to enable 'Security Center' on each VM.
B.Use Azure Automation Desired State Configuration (DSC) to push the agent.
C.Manually install the Log Analytics agent on each VM.
D.Create an Azure Policy assignment to deploy the Log Analytics agent.
AnswerD

Creating an Azure Policy assignment using a built-in definition such as 'Deploy Log Analytics agent to Windows VMs' automatically installs the agent on both existing and future VMs in the assigned scope via a deployIfNotExists effect. This approach centralizes governance at the subscription or management group level, requires only a Log Analytics workspace ID as a parameter, and continuously enforces compliance without human intervention.

Why this answer

Azure Policy can automatically deploy the Log Analytics agent to all existing and future Azure VMs via the 'Deploy Log Analytics agent for Windows/Linux VMs' built-in policy. This ensures consistent security event collection for Microsoft Sentinel without manual intervention, scaling across multiple subscriptions and VM lifecycles.

Exam trap

The trap here is that candidates often confuse manual or automation-based agent installation (options A, B, C) with the policy-driven, at-scale deployment that Azure Policy provides, which is the only method that automatically covers both existing and future resources without ongoing manual effort.

How to eliminate wrong answers

Option A is wrong because enabling 'Security Center' on each VM via the portal is a manual, per-VM action that does not scale to future VMs and does not directly deploy the Log Analytics agent required for Sentinel data ingestion. Option B is wrong because Azure Automation DSC is a configuration management tool for applying desired state configurations, not a scalable, policy-driven mechanism to deploy agents across all VMs in a subscription; it requires targeting individual VMs or VM sets and does not automatically cover new VMs. Option C is wrong because manually installing the Log Analytics agent on each VM is impractical for large environments, does not enforce compliance, and fails to cover future VMs without repeated manual effort.

36
MCQmedium

A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically respond to phishing emails detected by Microsoft Defender XDR. They want to create a playbook that, when triggered, will delete the email from all recipients' mailboxes. Which integration should the playbook use?

A.Microsoft Graph API
B.Microsoft Power Automate
C.Exchange Online PowerShell
D.Microsoft 365 Defender API
AnswerA

The Microsoft Graph API provides a unified REST endpoint for Microsoft 365 services, including Outlook mail, enabling Sentinel playbooks to execute remediation actions such as soft-deleting or purging malicious emails from a user's mailbox. Since Sentinel's Logic Apps connector supports HTTP requests to Graph API with proper OAuth authentication, it is the appropriate mechanism for mailbox-level threat remediation within an automated incident response workflow. Unlike PowerShell or other APIs, Graph API is directly consumable from a playbook and is designed for cross-service automation.

Why this answer

The Microsoft Graph API provides the necessary endpoints to programmatically access and manipulate Exchange Online mail items, including deleting emails from user mailboxes. A Sentinel playbook can use an HTTP trigger with the Graph API to perform the deletion action on behalf of the security team, enabling automated remediation of phishing emails across all recipients.

Exam trap

The trap here is that candidates confuse the Microsoft 365 Defender API (which handles detection data) with the Microsoft Graph API (which handles mailbox actions), leading them to select D instead of A.

How to eliminate wrong answers

Option B is wrong because Microsoft Power Automate is a workflow automation platform that can be used to build playbooks, but it is not the integration itself; the playbook would still need to call an API (like Graph API) to delete emails. Option C is wrong because Exchange Online PowerShell requires a persistent connection and is not designed for serverless, event-driven automation within a Sentinel playbook; it also lacks native HTTP trigger support. Option D is wrong because the Microsoft 365 Defender API focuses on threat detection and investigation data (e.g., alerts, incidents), not on direct mailbox manipulation like deleting emails.

37
MCQhard

You have configured Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). You notice that sign-in logs for external guest users are not appearing in Sentinel. What is the most likely cause?

A.The diagnostic settings in Microsoft Entra ID are not configured to stream sign-in logs to the Log Analytics workspace used by Sentinel.
B.Microsoft Sentinel does not support ingestion of external guest user sign-in logs.
C.The Microsoft Sentinel Entra ID connector requires a separate connector for guest users.
D.Guest user sign-ins are not logged in Microsoft Entra ID.
AnswerA

The Microsoft Entra ID connector for Microsoft Sentinel relies on diagnostic settings that must be explicitly enabled in Microsoft Entra ID to route sign-in logs to a Log Analytics workspace. If these settings are absent or misconfigured, sign-in log ingestion fails even though the Sentinel connector itself appears connected, which precisely matches the reported symptom. You must verify that the diagnostic setting streams AuditLogs and SignInLogs to the same workspace that Sentinel uses, and that the workspace ID matches the one selected in the connector.

Why this answer

Microsoft Sentinel ingests Azure AD (Entra ID) logs via diagnostic settings configured on the Entra ID tenant. These settings must explicitly stream sign-in logs (including guest user sign-ins) to a Log Analytics workspace. If the diagnostic settings are missing or misconfigured, no sign-in logs—including those for external guest users—will appear in Sentinel.

Exam trap

The trap here is that candidates may assume guest user logs require a special connector or are not logged at all, when in reality the issue is simply a missing or incomplete diagnostic settings configuration in Entra ID.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel fully supports ingestion of external guest user sign-in logs as long as the diagnostic settings stream them to the workspace. Option C is wrong because there is no separate connector for guest users; the single Entra ID connector handles all sign-in logs, including guest sign-ins, based on the diagnostic settings. Option D is wrong because Azure AD (Entra ID) does log guest user sign-ins in the Sign-in logs, provided the guest user has signed in at least once.

38
MCQmedium

You are a security engineer at a company that uses Microsoft Sentinel. You need to create an automation rule that assigns a specific owner to incidents generated from a particular analytics rule and adds a comment. The automation rule must run when an incident is created. What should you use to define the condition?

A.A playbook that uses the incident creation trigger and a condition action.
B.A workbook that monitors incident metrics and triggers an alert.
C.A Microsoft Sentinel automation rule with a condition based on the analytics rule name.
D.A Microsoft Sentinel analytics rule with incident grouping enabled.
AnswerC

Automation rules in Microsoft Sentinel can trigger on incident creation and evaluate conditions such as the analytics rule name, severity, or tags. They can then assign an owner and add a comment. This directly meets the requirement to assign a specific owner and add a comment when an incident is created from a particular analytics rule.

Why this answer

Microsoft Sentinel automation rules are designed to automate incident handling. They can trigger on incident creation and evaluate conditions such as the analytics rule name. When the condition matches, the rule can assign an owner and add a comment.

Playbooks are for more complex orchestration and are invoked by automation rules, but the condition and simple actions are defined in the automation rule itself.

Exam trap

The trap here is confusing automation rules with playbooks; automation rules define conditions and basic actions, while playbooks are for complex workflows triggered by automation rules.

39
Multi-Selectmedium

Your organization uses Microsoft Sentinel to monitor security events. You need to configure automated response actions for incidents. Which TWO of the following can be used to trigger automated responses in Microsoft Sentinel?

Select 2 answers
A.Workbooks
B.Watchlists
C.Hunting queries
D.Automation rules
E.Playbooks (Azure Logic Apps)
AnswersD, E

Automation rules run independently of playbooks and can trigger responses directly when an incident is created, satisfying the requirement for automated response actions. They support conditions on analytics rules, severity, and entity mappings, and can execute playbooks, assign owners, or change status without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created or updated, based on conditions like severity or specific analytics rules. They can run playbooks (Azure Logic Apps) to execute complex workflows, such as sending notifications or creating tickets, without manual intervention.

Exam trap

The trap here is that candidates often confuse Workbooks or Hunting queries as automation triggers because they are interactive tools, but they lack the event-driven trigger capability that Automation rules and Playbooks provide.

40
MCQeasy

A security analyst needs to query Microsoft Sentinel logs to find all sign-in events from a specific IP address in the last 24 hours. Which query language should the analyst use?

A.GraphQL
B.Transact-SQL (T-SQL)
C.PowerShell
D.Kusto Query Language (KQL)
AnswerD

Microsoft Sentinel uses Kusto Query Language (KQL) for log queries and analytics. KQL is designed for querying large datasets in Azure Monitor and Log Analytics, and it supports filtering, aggregation, and time-based queries. The analyst can use KQL to search sign-in logs, such as SigninLogs, and filter by IP address and time range.

Why this answer

Microsoft Sentinel is built on Azure Monitor Log Analytics, which uses Kusto Query Language (KQL) for all log queries. KQL is optimized for fast filtering, sorting, and aggregation of large datasets. The analyst can write a KQL query against the SigninLogs table to find events from a specific IP within the last 24 hours, making it the correct choice.

Exam trap

The trap here is confusing query languages used in other Microsoft services, such as T-SQL for databases or GraphQL for APIs, with the native language for Sentinel.

41
MCQhard

Refer to the exhibit. You assign this policy to a subscription that already has a security contact configured with email 'admin@contoso.com'. What will be the outcome?

A.The policy will not modify the existing security contact because it already exists.
B.The policy will fail because the security contact already exists.
C.The subscription will become non-compliant because the email does not match.
D.The policy will overwrite the existing security contact with the one in the policy.
AnswerA

The deployIfNotExists effect first evaluates the existence condition—here, checking whether a security contact with a non-empty email already exists. Because that condition is true, the policy skips the deployment template entirely, leaving the existing security contact unchanged. As a result, the policy is compliant and no modification occurs to the already-provisioned contact.

Why this answer

The Azure Policy definition shown uses the 'DeployIfNotExists' effect, which only deploys a resource (in this case, a security contact) if it does not already exist. Since the subscription already has a security contact configured with email 'admin@contoso.com', the policy will detect its presence and skip the deployment, leaving the existing contact unchanged. This behavior is by design to avoid overwriting existing configurations that may have been set manually or by other processes.

Exam trap

The trap here is that candidates often assume Azure Policy will enforce a specific configuration value (like the email address) and overwrite any existing setting, but 'DeployIfNotExists' only cares about the existence of the resource, not its properties, unless the policy rule explicitly includes a property match condition.

How to eliminate wrong answers

Option B is wrong because 'DeployIfNotExists' does not fail when the resource already exists; it simply evaluates to 'compliant' and takes no action. Option C is wrong because the policy does not enforce compliance based on email matching; it only checks for the existence of the security contact resource, and if it exists, the subscription is considered compliant regardless of the email value. Option D is wrong because 'DeployIfNotExists' is specifically designed to deploy only when the resource is absent; it will never overwrite an existing resource, as that would require a 'Modify' or 'Deploy' effect with a different evaluation logic.

42
MCQeasy

You are configuring Microsoft Defender for Cloud for an Azure subscription. You want to receive email notifications when a high-severity alert is generated. What should you configure?

A.Azure Monitor action groups with an email action.
B.The Email notifications settings in Microsoft Defender for Cloud.
C.A Microsoft Sentinel analytics rule with an email playbook.
D.A Log Analytics workspace with a scheduled query alert.
AnswerB

Microsoft Defender for Cloud provides a dedicated email notifications configuration where you can specify email addresses and choose which severity levels trigger notifications. This is the direct and intended way to receive email alerts for high-severity findings. It also allows notifying subscription owners and security contacts. This meets the requirement without additional services.

Why this answer

Microsoft Defender for Cloud includes a built-in email notification feature that allows you to specify recipients and severity levels for alerts. This is the simplest and most direct method to receive email notifications for high-severity alerts. It does not require additional services like Azure Monitor, Microsoft Sentinel, or Log Analytics, and it is designed specifically for this purpose.

Exam trap

The trap here is overcomplicating the solution by involving other services when Defender for Cloud has a native email notification setting.

43
Multi-Selecthard

Which THREE are prerequisites for integrating Microsoft Sentinel with Microsoft Defender XDR? (Choose three.)

Select 3 answers
A.Appropriate permissions (Security Administrator or Global Administrator)
B.The Microsoft 365 Defender data connector must be enabled in Sentinel
C.The Microsoft Monitoring Agent installed on all endpoints
D.A valid license for Microsoft 365 Defender (or individual workloads)
E.An Azure Sentinel workspace in the same region as the Microsoft 365 tenant
AnswersA, B, D

Correct: Required to enable the connector.

Why this answer

Integrating Microsoft Sentinel with Microsoft Defender XDR requires the user to have either Security Administrator or Global Administrator roles in Azure Active Directory. These permissions are necessary to grant consent for the data connector and to configure cross-tenant or cross-service access policies that enable Defender XDR to send incident and alert data to Sentinel.

Exam trap

The trap here is that candidates often assume the Microsoft Monitoring Agent is required for all Microsoft security integrations, but the Sentinel–Defender XDR connector is API-based and does not use MMA, and they also mistakenly think the workspace must be in the same region as the tenant, which is not enforced by the integration.

44
MCQeasy

You need to prioritize security recommendations in Microsoft Defender for Cloud. Your compliance team requires a framework that maps to regulatory standards. What should you use?

A.Regulatory compliance standards
B.Azure Policy compliance dashboard
C.Inventory feature
D.Secure score
AnswerA

Regulatory compliance standards in Microsoft Defender for Cloud are the correct choice because they directly map security recommendations to specific compliance frameworks, such as SOC 2, PCI DSS, and ISO 27001. This feature provides a dashboard where you can track your organization's compliance posture against each standard, with controls and corresponding recommendations that need remediation. It allows you to prioritize recommendations based on regulatory audit deadlines and requirements, which aligns with the compliance team's need to map recommendations to regulations.

Why this answer

Regulatory compliance standards in Microsoft Defender for Cloud map security recommendations to specific regulatory frameworks (e.g., SOC 2, PCI DSS, ISO 27001), enabling the compliance team to prioritize based on regulatory requirements. The secure score (Option D) provides an overall posture but does not map to specific standards. Azure Policy compliance dashboard (Option B) is used for policy enforcement, not recommendation prioritization.

Inventory (Option C) lists resources without compliance mapping.

45
MCQhard

You are configuring Microsoft Sentinel to use a playbook for automated response to incidents. The playbook needs to block the source IP address of a malicious sign-in on the Azure Firewall. Which Microsoft Sentinel feature should the playbook use?

A.Azure Automation runbooks
B.Azure Functions
C.Azure Logic Apps
D.KQL queries
AnswerC

Azure Logic Apps are the correct platform for Sentinel playbooks because they provide a low-code workflow engine with native connectors to Microsoft Defender, Teams, ServiceNow, and hundreds of other services. Logic Apps are triggered by Sentinel incidents and alerts through dedicated connectors, allowing automated investigation and response actions. They support both consumption and standard hosting plans and are the only compute service that integrates natively with Sentinel automation rules.

Why this answer

Microsoft Sentinel playbooks are built on Azure Logic Apps, which provide the workflow automation and connectors needed to orchestrate response actions like blocking an IP on Azure Firewall. Logic Apps can integrate with Azure Firewall via its REST API or the Azure Resource Manager connector to update firewall rules, making it the correct feature for this automated incident response task.

Exam trap

The trap here is that candidates often confuse Azure Automation runbooks (Option A) with Logic Apps because both can automate tasks, but Sentinel playbooks are explicitly built on Logic Apps, not Automation runbooks, and the exam tests this specific architectural distinction.

How to eliminate wrong answers

Option A is wrong because Azure Automation runbooks are designed for script-based automation (e.g., PowerShell, Python) and lack the native connectors and workflow designer for direct integration with Sentinel incidents and Azure Firewall rule updates; they require custom code and are less suited for event-driven playbooks. Option B is wrong because Azure Functions are serverless compute units for running code in response to events, but they do not provide the built-in connectors, workflow state management, or visual designer that Sentinel playbooks require; using Functions would necessitate manual implementation of the entire orchestration and connector logic. Option D is wrong because KQL queries are used for querying and analyzing log data in Sentinel, not for executing automated response actions like blocking an IP address on a firewall.

46
MCQmedium

You are a security engineer for a company that uses Microsoft Defender for Cloud. The security team wants to automatically trigger a Logic App playbook when a high-severity alert is generated for an Azure Storage account. The playbook must run without manual intervention. What should you configure?

A.Create an automation rule in Microsoft Defender for Cloud that triggers the playbook on alerts with severity High and resource type Storage accounts.
B.Configure a diagnostic setting to stream alerts to an event hub and use Azure Functions to invoke the playbook.
C.Enable just-in-time (JIT) VM access on the storage account and attach the playbook to the JIT policy.
D.Create an Azure Monitor action group that triggers the playbook when an alert is fired, and assign the action group to the storage account.
AnswerA

Automation rules in Microsoft Defender for Cloud can trigger Logic Apps based on alert severity, resource type, and other conditions. This directly satisfies the requirement for automatic, no-touch execution. The rule evaluates new alerts and invokes the playbook, which can then perform remediation steps such as isolating the storage account or notifying the SOC.

Why this answer

Automation rules in Microsoft Defender for Cloud are the native way to automatically respond to security alerts. They can filter by alert severity, resource type, and other properties, and then trigger a Logic App playbook. This provides a no-code, scalable solution that meets the requirement for automatic execution without manual intervention.

Other options either require custom code or apply to the wrong resource type.

Exam trap

The trap here is assuming that Azure Monitor action groups can directly trigger playbooks for Defender for Cloud alerts, when automation rules are the correct feature.

47
MCQeasy

A company is deploying Microsoft Sentinel in a new Azure subscription. The security team wants to ingest Windows security events from on-premises servers. Which data connector should they use?

A.Windows Security Events via AMA (Azure Monitor Agent)
B.Office 365 connector
C.Azure Active Directory connector
D.Common Event Format (CEF) connector
AnswerA

The Windows Security Events via AMA connector is the correct choice because Azure Monitor Agent (AMA) is the modern agent that collects Windows Event Logs, including the Security channel, using a Data Collection Rule (DCR). This connector streams events such as successful/failed logons, process creation, and privilege use directly into Sentinel's WindowsEvent table, making it the current standard for this source. Unlike the legacy Log Analytics agent, AMA provides a single agent for both Log Analytics and extension-based workloads, with more granular filtering and network-friendly control.

Why this answer

The Windows Security Events via AMA connector is the current recommended method for streaming Windows security events to Azure Sentinel using the Azure Monitor Agent. Option B is wrong because the Azure Active Directory connector is for Microsoft Entra ID logs, not Windows events. Option C is wrong because the Office 365 connector is for Office logs.

Option D is wrong because the Common Event Format (CEF) connector is for syslog from security appliances, not Windows security events.

48
MCQeasy

Your company is using Microsoft Sentinel to monitor security events. You need to ensure that all incidents generated in Sentinel are automatically sent to a third-party ticketing system via a webhook. Which Sentinel feature should you configure?

A.Create an automation rule that runs a playbook when an incident is created.
B.Use a watchlist to map incidents to ticketing system IDs.
C.Create a workbook that exports incidents to the ticketing system.
D.Configure a data connector to the ticketing system.
AnswerA

Automation rules in Microsoft Sentinel are condition-based triggers that fire on incident creation, and they can invoke a playbook (an Azure Logic Apps workflow). The playbook can use an HTTP or webhook action to create a ticket in your external ticketing system, making this the correct outbound integration path. Unlike the other options, this is an active, automated mechanism that sends data out of Sentinel.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when an incident is created. The playbook can then use an HTTP action to call a webhook endpoint on the third-party ticketing system, sending the incident data automatically. This is the native, built-in mechanism for outbound event-driven integration with external systems.

Exam trap

The trap here is confusing inbound data ingestion (data connectors) with outbound event-driven automation (automation rules + playbooks), leading candidates to incorrectly select a data connector for exporting incidents.

How to eliminate wrong answers

Option B is wrong because watchlists are used for storing reference data (e.g., IP addresses, usernames) to correlate with events during analytics rule processing, not for triggering outbound webhook calls to ticketing systems. Option C is wrong because workbooks are visualization and reporting tools that display data from Log Analytics workspaces; they cannot execute automated actions like sending HTTP requests to external systems. Option D is wrong because data connectors are designed to ingest data into Sentinel from external sources (e.g., security appliances, cloud platforms), not to export incidents outbound to a ticketing system.

49
MCQeasy

Your security team wants to use Microsoft Defender for Cloud's 'Just-In-Time (JIT) VM access' to reduce the attack surface. Which Azure policy must be enabled on the subscription to use JIT?

A.Microsoft Defender for Databases
B.Microsoft Defender for Servers
C.Microsoft Defender for Storage
D.Microsoft Defender for Key Vault
AnswerB

Microsoft Defender for Servers is the only plan that includes Just-in-Time VM access, which locks down inbound management ports by default and lets defenders request temporary, time-bound access through Defender for Cloud. The feature works by automatically configuring and updating NSG rules to allow a specific source IP and port pair for a defined window, then reverting to close the port. This makes Defender for Servers the correct choice for a security team seeking JIT capabilities for their virtual machines.

Why this answer

Just-In-Time (JIT) VM access is a feature of Microsoft Defender for Cloud that requires the Microsoft Defender for Servers plan to be enabled on the subscription. This plan provides the advanced threat protection and access control capabilities, including JIT, which dynamically locks down inbound traffic to VMs and opens ports only when authorized users request access via Azure Policy or the portal.

Exam trap

The trap here is that candidates often confuse the 'Microsoft Defender for Servers' plan with other Defender plans (like Databases or Storage) because they assume any 'Defender' plan can enable JIT, but only the Servers plan provides the necessary VM-level access control and network security group management.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Databases is designed to protect database services (e.g., Azure SQL, Azure Database for PostgreSQL) and does not include JIT VM access functionality. Option C is wrong because Microsoft Defender for Storage protects Azure Blob Storage, Azure Files, and Data Lake Storage from threats, but it has no role in managing VM network access. Option D is wrong because Microsoft Defender for Key Vault provides advanced threat protection for Azure Key Vault, focusing on secrets and key management, not VM network-level just-in-time access.

50
MCQeasy

You are evaluating Microsoft Defender for Cloud's cloud security posture management (CSPM) capabilities. You need to identify misconfigurations across your Azure, AWS, and GCP environments. What should you enable?

A.Ingest logs from AWS and GCP into Microsoft Sentinel.
B.Create Azure Policy assignments for AWS and GCP resources.
C.Deploy Azure Arc on VMs in AWS and GCP.
D.Enable the 'Defender for Cloud' multicloud connector for AWS and GCP.
AnswerD

Microsoft Defender for Cloud provides multicloud CSPM via its connector feature: in the Azure Portal, you enable the AWS connector (using a CloudFormation template and cross-account role) or GCP connector (using a service account) to on-board your entire cloud environments. Once connected, Defender for Cloud continuously pulls resource configuration and workload telemetry using AWS Config/AWS Security Hub and GCP Cloud Asset Inventory, then applies built-in security standards (e.g., CIS, NIST, Azure Security Benchmark) to generate recommendations and compliance scores across AWS, GCP, and Azure. This native multicloud connector also enables advanced threat protection features such as attack path analysis and cloud security explorer, making it the only listed option that fulfills multicloud CSPM.

Why this answer

The Defender for Cloud multicloud connector is specifically designed to ingest security findings and configuration data from AWS and GCP into Microsoft Defender for Cloud's CSPM dashboard. This enables unified visibility and assessment of misconfigurations across Azure, AWS, and GCP environments without requiring agents or log ingestion into Sentinel.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel's log ingestion with Defender for Cloud's CSPM capabilities, assuming that any multicloud security requires a SIEM, when in fact Defender for Cloud's native connector provides the required posture management without Sentinel.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM/SOAR solution for threat detection and incident response, not a CSPM tool for identifying cloud misconfigurations; ingesting logs into Sentinel does not provide the built-in compliance and posture assessments that Defender for Cloud offers. Option B is wrong because Azure Policy can only enforce rules on Azure resources; it cannot directly manage or evaluate AWS or GCP resources, as those environments do not support Azure Policy assignments. Option C is wrong because Azure Arc extends Azure management to on-premises and multicloud servers, but it does not provide CSPM scanning for cloud-native services like AWS S3 or GCP Cloud Storage; Arc focuses on VM-level management, not cloud-wide posture assessment.

51
MCQhard

A company uses Microsoft Defender for Cloud to manage the security posture of multiple Azure subscriptions. The security team wants to ensure that all subscriptions are covered by the same Microsoft Defender for Cloud policy initiative, but one subscription is not showing compliance data. The subscription is in the same Azure AD tenant and has the same tags. What is the most likely cause?

A.The user does not have Security Admin permissions on the subscription.
B.The subscription does not have any tags applied.
C.The subscription does not have the default policy initiative assigned.
D.The subscription is not registered with the Microsoft.Security resource provider.
AnswerD

For Defender for Cloud to assess a subscription, the Microsoft.Security resource provider must be registered at the subscription level, as this registration is what allows the service to query Azure Resource Manager for resource metadata and configuration. When the provider is unregistered, Defender for Cloud cannot perform any resource discovery, so no security recommendations, regulatory compliance controls, or secure score data are generated for that subscription. Registration is typically performed automatically when a user first opens Defender for Cloud in the portal, but it can also be done programmatically via Azure CLI (`az provider register --namespace Microsoft.Security`) or PowerShell. An unregistered provider explains both the absence of data and why the user perceives that security posture is completely missing.

Why this answer

Microsoft Defender for Cloud relies on the Microsoft.Security resource provider to collect security configurations, apply policy initiatives, and report compliance data. If a subscription is not registered with the Microsoft.Security resource provider, Defender for Cloud cannot evaluate policies or generate compliance results, even if the subscription is in the same tenant and has identical tags. Registering the resource provider is a prerequisite for any Defender for Cloud functionality, including policy assignment and compliance reporting.

Exam trap

The trap here is that candidates often assume missing compliance data is due to permissions (Security Admin) or missing policy assignments, but the root cause is frequently the unregistered Microsoft.Security resource provider, which is a prerequisite that many overlook.

How to eliminate wrong answers

Option A is wrong because Security Admin permissions control who can manage security policies and view alerts, but they do not affect whether the subscription itself can report compliance data; a subscription without the required resource provider will show no compliance data regardless of user permissions. Option B is wrong because tags are metadata used for organizing resources and do not influence policy compliance or the underlying resource provider registration; a subscription without tags will still show compliance data if the policy initiative is assigned and the resource provider is registered. Option C is wrong because while a missing default policy initiative would result in no compliance data for that specific initiative, the question states that all subscriptions should be covered by the same policy initiative, implying it is assigned; the core issue is that the subscription cannot process the policy at all due to the missing resource provider.

52
MCQmedium

Your company uses Microsoft Defender for Cloud's Security Posture Management (CSPM) features. You need to identify resources that are not compliant with the organization's security baseline. What should you do?

A.View the secure score
B.Review the security recommendations
C.Use the regulatory compliance dashboard
D.Use the inventory blade
AnswerC

The regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it provides a continuous, standards-based assessment by mapping Azure Policy initiatives to controls from frameworks such as Azure CIS, PCI DSS, ISO 27001, SOC 2, and even custom standards. It shows a compliance percentage per standard, lets you drill down to non-compliant resources and controls, and tracks compliance history over time. You can select which standards to assess in the compliance policies settings, giving you exactly the detailed compliance status needed.

Why this answer

The regulatory compliance dashboard in Microsoft Defender for Cloud provides a view of how your resources comply with specific security standards and baselines, such as the Microsoft Cloud Security Benchmark (MCSB) or custom regulatory frameworks. By selecting the appropriate compliance standard that matches your organization's security baseline, you can identify resources that are non-compliant with specific controls. This dashboard directly maps security assessments to compliance controls, making it the correct tool for identifying resources not meeting your baseline.

Exam trap

The trap here is that candidates often confuse the secure score or security recommendations with compliance tracking, not realizing that the regulatory compliance dashboard is the dedicated tool for mapping resources to specific baseline controls and standards.

How to eliminate wrong answers

Option A is wrong because the secure score is a numerical summary of your overall security posture based on implemented recommendations, not a detailed view of compliance with a specific baseline. Option B is wrong because security recommendations are actionable steps to improve security, but they do not map directly to a regulatory or custom baseline compliance status. Option D is wrong because the inventory blade lists all resources and their basic security configurations, but it does not provide compliance status against a defined baseline or regulatory standard.

53
MCQeasy

You need to configure a continuous export of Microsoft Defender for Cloud alerts to a third-party SIEM. Which feature should you use?

A.Create an Azure Logic App to periodically query and send alerts.
B.Use the Defender for Cloud REST API to pull alerts.
C.Configure Azure Monitor agent on all VMs.
D.Use the continuous export feature in Defender for Cloud to stream alerts to an Event Hubs namespace.
AnswerD

The continuous export feature in Microsoft Defender for Cloud natively streams security alerts and recommendations to an Azure Event Hubs namespace, allowing near real-time integration with an external SIEM or log management tool. You configure it under Environment settings for a subscription or a management group, and it supports filtering for specific alert severities or recommendations. Because this is built in, it handles batching, schema, and transport without custom code, making it the correct method for continuous alert export.

Why this answer

The continuous export feature in Microsoft Defender for Cloud is specifically designed to stream security alerts and recommendations to an Event Hubs namespace, which can then be consumed by a third-party SIEM. This native integration eliminates the need for custom polling or scripting, ensuring near real-time data flow with minimal latency.

Exam trap

The trap here is that candidates often confuse the Azure Monitor agent (which collects VM logs) with the continuous export feature (which streams Defender for Cloud alerts), leading them to select Option C despite it being unrelated to alert export.

How to eliminate wrong answers

Option A is wrong because creating a Logic App to periodically query and send alerts introduces unnecessary polling overhead and latency, whereas continuous export provides a push-based streaming model. Option B is wrong because using the Defender for Cloud REST API to pull alerts requires custom code and manual scheduling, lacking the automated, event-driven streaming capability of continuous export. Option C is wrong because the Azure Monitor agent collects OS-level performance and event logs, not Defender for Cloud alerts; it is unrelated to exporting security alerts to a SIEM.

54
MCQmedium

You manage security for a company using Microsoft Sentinel. The security team wants to automatically assign incidents to the on-call analyst based on the incident severity and the entity involved. They also want to ensure that when an incident is updated, the assignment is re-evaluated. You need to configure this with minimal administrative effort. What should you use?

A.Configure the analytics rule to include the owner in the incident details, and use a scheduled query to update the owner periodically.
B.Create a playbook that uses the Microsoft Sentinel connector to assign the incident, and configure the analytics rule to run the playbook on incident creation.
C.Create an automation rule that triggers on incident creation and update, with conditions based on severity and entity, and an action to assign the incident to the on-call analyst.
D.Use Microsoft Defender for Cloud's workflow automation to assign the incident to the on-call analyst based on severity.
AnswerC

Automation rules in Microsoft Sentinel are designed to handle incident management tasks such as assignment, tagging, and status changes. They can trigger on incident creation and update, and support conditions based on analytics rule name, severity, and entities. This meets the requirement with minimal effort, as no custom logic or playbooks are needed.

Why this answer

Automation rules in Microsoft Sentinel are the native mechanism for incident management, allowing automatic assignment based on conditions such as severity and entities. They can trigger on both incident creation and update, ensuring re-evaluation when incidents change. This approach requires minimal effort because it is built into the platform and does not require custom playbook development.

Exam trap

The trap here is assuming that playbooks are required for any automation in Microsoft Sentinel, when automation rules are specifically designed for incident management tasks like assignment and can trigger on updates.

55
MCQmedium

You administer an Azure environment with Microsoft Defender for Cloud enabled. A security analyst reports that a suspicious process was executed on a virtual machine, but no alert was found in the portal. You need to ensure that Defender for Cloud can detect and alert on suspicious activities on the VM. What should you do?

A.Configure a custom alert rule in Azure Monitor to trigger on specific process creation events.
B.Enable the Log Analytics agent and configure a data collection rule to forward Security events.
C.Ensure the Microsoft Defender for Servers plan is enabled and that the Azure Monitor Agent is installed on the VM.
D.Enable just-in-time (JIT) VM access to restrict inbound traffic and log connection attempts.
AnswerC

Defender for Servers provides advanced threat detection for VMs, including process-level monitoring and behavioral analytics. The Azure Monitor Agent, when deployed via the plan, installs the required extensions (such as the Defender for Endpoint sensor) to collect and analyze security events. Without this plan and agent, process execution events may not be captured, and alerts will not be generated.

Why this answer

To detect suspicious process execution on a VM, Defender for Cloud must have the Defender for Servers plan enabled, which deploys the Azure Monitor Agent and integrates with Microsoft Defender for Endpoint. This combination provides deep endpoint detection and response capabilities, including process-level monitoring. Other options either use outdated agents or focus on network controls, which do not fulfill the requirement.

Exam trap

The trap here is assuming that any logging agent or custom alert rule will provide the same depth of threat detection as the built-in Defender for Servers plan.

56
MCQhard

Your company has Microsoft Sentinel deployed in multiple workspaces across several Azure regions. The security operations team wants to query data from all workspaces centrally using a single KQL query. What feature should you implement?

A.Configure Log Analytics workspaces as linked to a central workspace.
B.Use cross-workspace queries with the workspace() expression in KQL.
C.Export all data to Azure Data Explorer and query there.
D.Use the Microsoft Sentinel SIEM connector to aggregate data.
AnswerB

The workspace() expression in KQL—e.g., union workspace('Contoso-Sentinel').SecurityEvent, workspace('Fabrikam-Sentinel').SecurityEvent—lets you query tables across multiple Log Analytics workspaces in a single query. This is the Azure-native mechanism designed for Microsoft Sentinel multi-workspace scenarios and works without duplicating data or adding an extra ETL layer. It also supports resource-id based references, so you can query Sentinel workspaces that data is retained in while preserving the full context of the original table schema.

Why this answer

The workspace() expression in KQL allows you to include tables from multiple Log Analytics workspaces in a single query, enabling centralized querying across all Microsoft Sentinel workspaces without moving or aggregating data. This is the native and recommended approach for cross-workspace queries in Azure Sentinel.

Exam trap

The trap here is that candidates confuse the workspace() expression with the legacy linked workspace feature (Option A) or assume that a central aggregation mechanism (like a SIEM connector or data export) is required, when in fact KQL's native cross-workspace querying is the simplest and most cost-effective solution.

How to eliminate wrong answers

Option A is wrong because linked workspaces (via the legacy 'linked server' feature) are used for cross-region querying in Log Analytics but do not support the workspace() expression and are not designed for Microsoft Sentinel's multi-workspace architecture; they also require manual configuration and have limitations on the number of linked workspaces. Option C is wrong because exporting all data to Azure Data Explorer is unnecessary overhead—it introduces additional cost, latency, and complexity, and is not the standard method for querying Sentinel data across workspaces; the workspace() expression is simpler and more efficient. Option D is wrong because the Microsoft Sentinel SIEM connector is used to ingest data from external SIEMs (e.g., Splunk, ArcSight) into Sentinel, not to aggregate queries across multiple Sentinel workspaces.

57
MCQhard

You are the security engineer for a multinational company that uses Azure to host critical workloads. The company has deployed Microsoft Defender for Cloud with the enhanced security features enabled on all subscriptions. Recently, a security audit revealed that several virtual machines (VMs) in the production environment are missing critical security updates. The audit report indicates that the VMs are not being assessed for missing updates by Defender for Cloud. You need to ensure that all VMs are automatically assessed for missing OS updates using Defender for Cloud's vulnerability assessment capabilities. The solution must minimize administrative overhead and should not require manual installation of agents on existing VMs. What should you do?

A.Enable the 'SQL servers on machines' plan in Defender for Cloud.
B.Enable the 'Servers' plan in Defender for Cloud and ensure that the 'Vulnerability assessment for machines' setting is turned on.
C.Configure a vulnerability assessment solution from the Azure Marketplace and assign it to the VMs.
D.Deploy the Log Analytics agent to all VMs using Azure Policy.
AnswerB

Enabling the 'Servers' plan (Microsoft Defender for Servers) and turning on the 'Vulnerability assessment for machines' setting activates the built-in Microsoft Defender Vulnerability Management (MDVM) scanning capability. This integration automatically discovers installed software, missing OS patches, and configuration vulnerabilities across Azure and hybrid VMs without requiring you to manually deploy a separate VA scanner on each machine. The resulting recommendations are surfaced in Defender for Cloud, directly satisfying the requirement to assess VMs for missing updates with minimal administrative overhead.

58
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You are using Microsoft Defender for Cloud to monitor security posture. You notice that the recommendation 'MFA should be enabled on accounts with owner permissions on your subscription' shows a status of 'Unhealthy' for some accounts, but those accounts already have Microsoft Entra Conditional Access policies requiring MFA. What is the most likely reason for the discrepancy?

A.The Conditional Access policies are not applied to all users; some users bypass MFA.
B.The accounts are guest users from another tenant; MFA cannot be enforced.
C.Defender for Cloud evaluates the 'per-user' MFA state, which is separate from Conditional Access.
D.The recommendation requires MFA to be configured in the subscription's access control (IAM) blade.
AnswerC

Defender for Cloud's identity recommendations rely on the per-user MFA state in Microsoft Entra ID, which is a distinct flag set at the user level independent of any Conditional Access policies. Even when an organization has robust Conditional Access requiring MFA for all users, the per-user MFA property may still be 'Disabled', causing the recommendation to flag accounts as non-compliant. This is why the recommendation persists even when there is no actual MFA bypass, making this the correct explanation.

Why this answer

The correct answer is C: Defender for Cloud evaluates the 'per-user' MFA state, which is separate from Conditional Access. Microsoft Defender for Cloud's MFA recommendation checks whether each account has MFA enabled at the per-user level in Microsoft Entra ID (the legacy per-user MFA setting), not whether Conditional Access policies enforce MFA at sign-in. Therefore, accounts protected only by Conditional Access can still appear 'Unhealthy' because their per-user MFA status remains disabled.

Option A is wrong because the scenario states the Conditional Access policies require MFA, so the discrepancy is not caused by policy scope. Option B is wrong because guest users can be protected by MFA through Conditional Access. Option D is wrong because Azure subscription IAM does not configure MFA; MFA is an identity-level control in Microsoft Entra ID.

59
MCQmedium

Refer to the exhibit. You are reviewing the Microsoft Defender for Cloud settings for a subscription. The JSON shows that 'autoProvision' is set to true. What does this mean?

A.All Microsoft Defender plans are automatically enabled for new resources
B.The Log Analytics agent is automatically installed on new Azure VMs
C.Security policies are automatically assigned to new resource groups
D.Continuous export of security alerts is enabled
AnswerB

When auto-provisioning is enabled in Microsoft Defender for Cloud, the Log Analytics agent is automatically installed on existing and newly created Azure VMs. For new VMs, the agent extension is deployed as part of the VM provisioning process, ensuring that security data like event logs, performance counters, and audit records are collected without manual intervention. This agent installation is the core behavior of auto-provisioning and is the correct interpretation of the setting in the exhibit. The agent forwards data to the configured Log Analytics workspace for analysis by Defender for Cloud.

Why this answer

When 'autoProvision' is set to true in Microsoft Defender for Cloud, it means the Log Analytics agent (formerly Microsoft Monitoring Agent) is automatically installed on all existing and new Azure VMs in the subscription. This agent collects security-related telemetry and sends it to the Log Analytics workspace associated with Defender for Cloud, enabling threat detection and security monitoring. The setting does not enable any Defender plans or policies—it only controls agent deployment.

Exam trap

The trap here is that candidates confuse 'autoProvision' (agent installation) with 'auto enablement of Defender plans' (pricing tier), leading them to incorrectly select Option A, even though enabling plans requires explicit configuration under 'Environment settings' > 'Defender plans'.

How to eliminate wrong answers

Option A is wrong because 'autoProvision' controls agent installation, not the enabling of Defender plans; Defender plans (e.g., Defender for Servers, Defender for SQL) are enabled separately via the 'pricing' tier settings. Option C is wrong because security policies are assigned at the management group or subscription level, not automatically to new resource groups, and 'autoProvision' has no effect on policy assignment. Option D is wrong because continuous export of security alerts is a separate feature configured under 'Continuous export' settings in Defender for Cloud, unrelated to the 'autoProvision' property.

60
MCQmedium

Your security team receives a high-priority alert from Microsoft Sentinel indicating a potential brute-force attack against an Azure SQL Database. The alert was generated by an analytics rule using the following KQL query: 'SigninLogs | where ResultType == "50057" | summarize Count = count() by UserPrincipalName, IPAddress | where Count > 10'. What is the most likely cause of the alert?

A.Multiple failed MFA attempts by a user.
B.A user successfully signed in after many attempts.
C.Multiple sign-in attempts using a disabled account from the same IP address.
D.Multiple sign-in attempts from a non-existent user account.
AnswerC

Sign-in attempts against a disabled account return error code 50057 (user account disabled), which means the directory explicitly prohibits authentication. When multiple such attempts come from the same IP address, it signals a coordinated credential-stuffing or brute-force effort targeting a specific disabled account. Because a disabled account has no legitimate use, every attempt is unequivocally anomalous and represents a high-priority threat, especially if the IP shows other malicious activity.

Why this answer

The KQL query filters for ResultType == '50057', which specifically indicates 'User Account is Disabled'. The query then counts sign-in attempts by UserPrincipalName and IPAddress, triggering the alert when the count exceeds 10. This means the alert fires when there are more than 10 sign-in attempts from the same user and IP address against a disabled account, which matches the description of a brute-force attack targeting a disabled account.

Exam trap

The trap here is that candidates may confuse ResultType '50057' with generic sign-in failures or MFA errors, but Microsoft specifically uses unique error codes for each failure type, and this question tests your ability to map the code to the exact condition.

How to eliminate wrong answers

Option A is wrong because ResultType '50057' does not correspond to failed MFA attempts; failed MFA attempts return ResultType '50074' or '50076'. Option B is wrong because the query filters on ResultType '50057', which is a failure code, not a success code; successful sign-ins return ResultType '0'. Option D is wrong because non-existent user accounts generate ResultType '50034' (user does not exist), not '50057'.

61
Multi-Selectmedium

Which TWO are capabilities of Microsoft Sentinel UEBA? (Choose two.)

Select 2 answers
A.Integration with external threat intelligence feeds
B.Entity pages with timelines and related events
C.Automatic incident creation for all detected anomalies
D.Peer group analysis to detect anomalies
E.Automated response actions like blocking IPs
AnswersB, D

Entity pages in Microsoft Sentinel are a UEBA feature that aggregates an entity's activity into a timeline, showing behavior over time, related alerts, and anomalies. This allows analysts to quickly assess an entity's risk and contextualize investigations. UEBA specifically contributes anomaly-prone behavior insights and peer-group comparisons to these pages.

Why this answer

Option B is correct because Microsoft Sentinel UEBA provides entity pages that show a timeline of activities and related events for entities such as users, hosts, and IP addresses, helping analysts investigate anomalous behavior in context. Option D is correct because UEBA includes peer group analysis, which baselines an entity's behavior against similar peers to surface deviations that may indicate compromise or insider threat. Option A is not a UEBA capability per se; threat intelligence integration is a separate Sentinel feature (threat intelligence connectors and analytics rules), not part of UEBA's behavioral analytics.

Option C is incorrect because UEBA does not automatically create incidents for every detected anomaly; anomalies are surfaced as insights/entities and can be used by analytics rules to generate incidents selectively. Option E is incorrect because automated response actions such as blocking IPs are handled by Sentinel automation rules and playbooks (Logic Apps), not by the UEBA feature itself.

Exam trap

The trap here is that candidates confuse UEBA's behavioral alerting with automated incident creation or response, assuming that any anomaly detection must automatically trigger an incident or action, when in fact UEBA focuses on providing investigative context and anomaly scoring.

62
MCQmedium

You are investigating a security incident in Microsoft Sentinel. The incident involves multiple alerts from different data sources. You need to correlate the alerts to determine the full attack chain. Which Microsoft Sentinel feature should you use?

A.Incident investigation
B.Analytics rules
C.Playbooks
D.Workbooks
AnswerA

The Incident investigation view in Microsoft Sentinel opens an interactive graphical map that presents the incident's related alerts, entities, and activities as linked nodes. This tool enables you to trace relationships between hosts, IP addresses, accounts, and security events, revealing the attack path through entity timeline and expansion queries. It is precisely the correlation capability that helps analysts explore how individual alerts combine into an attacker's sequence of actions.

Why this answer

Incident investigation in Microsoft Sentinel is designed specifically for visualizing and correlating alerts within an incident to reconstruct the full attack chain. It provides a graphical map that links entities (e.g., IP addresses, user accounts, hosts) across alerts from different data sources, enabling you to trace the attacker's path step by step.

Exam trap

The trap here is that candidates confuse 'incident investigation' with 'analytics rules' or 'workbooks,' thinking that correlation happens at the rule or dashboard level, rather than understanding that investigation is a dedicated post-detection feature for exploring relationships within an incident.

How to eliminate wrong answers

Option B is wrong because analytics rules are used to generate alerts from raw data based on predefined queries, not to correlate already-generated alerts within an incident. Option C is wrong because playbooks automate response actions (e.g., blocking an IP) but do not provide visual correlation or mapping of alerts. Option D is wrong because workbooks are interactive dashboards for reporting and monitoring, not a tool for investigating a specific incident's alert correlation.

63
MCQhard

A financial services company uses Microsoft Sentinel to detect ransomware activity. They want to correlate alerts from multiple sources to reduce false positives. They have enabled Microsoft Defender for Cloud, Microsoft Defender XDR, and Azure Firewall logs. Which Sentinel feature should they use to create a single alert from multiple signals?

A.Near-real-time (NRT) rules
B.Fusion (machine learning) rules
C.Anomaly detection rules
D.Scheduled query rules
AnswerB

Fusion (machine learning) rules are specifically built for detecting multi-stage attacks by correlating alerts from multiple products, such as Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud. The engine uses scalable machine learning algorithms to analyze incoming alerts, identify patterns that match known kill-chain sequences, and automatically fuse them into a single actionable incident with a story of the attack. This goes beyond simple alert aggregation: Fusion evaluates the timing, context, and relationships between alerts to produce high-fidelity incidents with low false-positive rates. Because the scenario requires detecting a multi-stage attack that spans various alert sources, Fusion is the correct choice.

Why this answer

Fusion (machine learning) rules in Microsoft Sentinel are specifically designed to correlate alerts from multiple sources—such as Microsoft Defender for Cloud, Microsoft Defender XDR, and Azure Firewall logs—by using machine learning models to identify multi-stage attack patterns and reduce false positives. This makes Fusion the correct choice for creating a single alert from multiple signals, as it automatically combines related alerts into a single, high-fidelity incident.

Exam trap

The trap here is that candidates often confuse Fusion rules with Scheduled query rules, thinking they can manually write KQL to correlate alerts, but Fusion's machine learning correlation is automatic and purpose-built for multi-source alert fusion, which is exactly what the scenario requires.

How to eliminate wrong answers

Option A is wrong because Near-real-time (NRT) rules are used for querying data with low latency (up to 5 minutes) but do not correlate alerts from multiple sources; they simply run a query on a single table. Option C is wrong because Anomaly detection rules identify deviations from baseline behavior using machine learning on a single data source, not correlation across multiple sources. Option D is wrong because Scheduled query rules run periodic queries on log data but require manual correlation logic and do not automatically fuse alerts from different sources like Fusion does.

64
MCQmedium

Your company deploys a new Azure application gateway with WAF policy in prevention mode. After deployment, users report that legitimate traffic is being blocked. You need to identify which WAF rules are causing the blocks without affecting the security posture. What should you do?

A.Disable the WAF policy temporarily.
B.Create a custom rule to allow all traffic.
C.Set the WAF policy to custom rules only.
D.Change the WAF policy mode to detection.
AnswerD

Changing the WAF policy mode to detection makes the gateway evaluate every managed and custom rule and log all matches to the WAF diagnostic logs, but it stops enforcing blocking actions. You can then correlate the rejected requests with the exact rule ID and request details in Log Analytics, confirming whether this is a false positive. Once you've identified the offending rule, you can add exclusions or tune rule actions and switch the policy back to prevention mode.

Why this answer

Switching the WAF policy mode from prevention to detection allows the application gateway to log WAF rule matches without blocking legitimate traffic. This enables you to review the logs and identify which specific rules are causing false positives, while still maintaining visibility into threats. Once identified, you can fine-tune the rules or create exceptions without disrupting the security posture.

Exam trap

The trap here is that candidates may think disabling the WAF or creating an allow-all rule is a quick fix, but the correct approach is to use detection mode to diagnose false positives without compromising security.

How to eliminate wrong answers

Option A is wrong because disabling the WAF policy entirely removes all protection, leaving the application vulnerable to attacks during troubleshooting. Option B is wrong because creating a custom rule to allow all traffic effectively bypasses the WAF, negating its security benefits and defeating the purpose of having a WAF in place. Option C is wrong because setting the WAF policy to custom rules only disables the managed rule sets, which are the primary source of false positives in this scenario, and still does not provide a diagnostic view of which rules are blocking traffic.

65
MCQeasy

Your company has a hybrid environment with Azure resources and on-premises servers. You have deployed Microsoft Sentinel and connected it to Azure AD, Azure Activity Logs, and Windows Security Events from on-premises servers via the Log Analytics gateway. You need to create a workbook that shows the number of sign-ins from each country over the last 24 hours. The data source is the SigninLogs table. However, the workbook does not display any data. You verify that the Log Analytics workspace is receiving sign-in logs from Azure AD. Which of the following is the most likely reason the workbook shows no data?

A.The workbook uses a different visualization type that requires KQL.
B.The Log Analytics gateway is blocking the sign-in logs.
C.The workbook's time range filter is set to 'Last 7 days' but the query uses a 24-hour filter incorrectly.
D.The Log Analytics workspace is not receiving sign-in logs from Azure AD.
AnswerC

This is correct. The workbook's time range filter might be set to a broader range (e.g., last 7 days) while the query uses a 24-hour filter. If the query does not correctly use the time parameter, it may return no results when the dashboard filter is applied.

Why this answer

The workbook likely has a time range filter set to 'Last 7 days', but the underlying KQL query uses a hardcoded 24-hour filter. This mismatch causes the query to return data only for the last 24 hours, but the dashboard filter may interfere or the query may be incorrectly referencing the time parameter. As a result, no data is displayed.

Option A is incorrect because workbooks rely on KQL queries regardless of visualization type. Option B is incorrect because the Log Analytics gateway is used for on-premises data, not for Azure AD sign-in logs which stream directly to the workspace. Option D is incorrect because the problem statement confirms sign-in logs are being received.

Exam trap

The most common trap is assuming that if logs are flowing into the Log Analytics workspace, the workbook will automatically show data. However, workbook queries often have their own time filters that must align with the dashboard's time range. Misconfigured time parameters are a frequent hidden issue.

66
MCQmedium

Your organization uses Microsoft Defender for Cloud to monitor Azure SQL databases. You receive an alert indicating a potential SQL injection attack. What is the most effective immediate action to validate and respond?

A.Enable Transparent Data Encryption (TDE) on the database
B.Run a vulnerability assessment on the database
C.Review the SQL database auditing logs to identify the source queries
D.Immediately block all IP addresses from the alert in the SQL firewall
AnswerC

SQL database auditing tracks database events and writes them to an audit log in Azure Storage, Log Analytics, or Event Hub. Reviewing these logs lets you see the exact queries, the principal/user, the source IP address, and the timestamp of the suspicious activity, confirming whether the Defender alert is a genuine attack and revealing its origin. This is the direct and immediate way to validate an alert from Microsoft Defender for Cloud.

Why this answer

SQL database auditing logs capture detailed information about database events, including the exact SQL queries executed against the database. Reviewing these logs allows you to identify the source queries, the originating IP addresses, and the user accounts involved in the suspected SQL injection attack, enabling you to validate the alert and take targeted remediation actions. This is the most effective immediate step to confirm the attack and understand its scope before implementing broader security controls.

Exam trap

The trap here is that candidates often confuse reactive forensic actions (like reviewing audit logs) with proactive security controls (like TDE or vulnerability assessments), or they assume that blocking IPs is the immediate best practice without first validating the attack through logs, which is a common mistake in incident response scenarios.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts data at rest, which protects against physical theft of storage media but does not prevent or detect SQL injection attacks, which exploit application-layer vulnerabilities. Option B is wrong because running a vulnerability assessment identifies misconfigurations and missing patches but does not provide real-time forensic data about an ongoing or recent attack; it is a proactive security measure, not a reactive validation step. Option D is wrong because immediately blocking all IP addresses from the alert in the SQL firewall could disrupt legitimate traffic and may not address the root cause if the attack originated from a compromised application or a spoofed IP; it is a reactive measure that should be taken only after confirming the malicious queries through auditing logs.

67
MCQhard

You are designing a Microsoft Sentinel solution for a multinational company. The company requires that security incidents be correlated across regions, but data residency mandates require logs to remain in their original region. What should you implement?

A.Deploy one Microsoft Sentinel workspace per region and use cross-workspace querying for correlation
B.Deploy a separate Log Analytics workspace per region, but only one Sentinel workspace
C.Deploy a single Microsoft Sentinel workspace in a central region and use Azure Lighthouse
D.Deploy a single Microsoft Sentinel workspace and use data collection rules to filter logs
AnswerA

Deploying one Microsoft Sentinel workspace per region satisfies data residency because each workspace is a Log Analytics workspace that ingests and stores logs within its own geographic boundary. Cross-workspace querying with the 'workspace()' expression or Azure Resource Graph lets security analysts run a single KQL query that references multiple workspaces, correlating threats without moving data out of its resident region. Sentinel's built-in UEBA and analytics rules work on each workspace, while cross-workspace views preserve centralized hunting.

Why this answer

Deploying one Microsoft Sentinel workspace per region satisfies data residency mandates by keeping logs in their original region, while cross-workspace querying allows security incidents to be correlated across regions using KQL queries that span multiple workspaces. This approach ensures compliance with regional data sovereignty laws without sacrificing the ability to perform centralized threat detection and investigation.

Exam trap

The trap here is that candidates often assume a single Sentinel workspace is required for centralized correlation, overlooking that cross-workspace querying can achieve the same goal while respecting data residency mandates.

How to eliminate wrong answers

Option B is wrong because deploying a separate Log Analytics workspace per region but only one Sentinel workspace violates data residency mandates, as Sentinel ingests and stores logs in the workspace's region, forcing all logs into a single region. Option C is wrong because a single Sentinel workspace in a central region would store all logs in that region, directly conflicting with data residency requirements. Option D is wrong because data collection rules (DCRs) control ingestion and transformation of logs but do not alter the storage location; logs still reside in the single workspace's region, failing the residency mandate.

68
Multi-Selectmedium

Which THREE of the following are features of Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM)?

Select 3 answers
A.Vulnerability scanning of containers
B.Security recommendations for resources
C.Secure Score
D.Threat detection for VMs
E.Regulatory compliance assessments
AnswersB, C, E

CSPM generates recommendations to improve security.

Why this answer

CSPM in Microsoft Defender for Cloud continuously assesses Azure resources against built-in security policies and industry best practices, generating actionable security recommendations to harden the environment. These recommendations are derived from the Azure Security Benchmark and are displayed in the Recommendations blade, directly influencing the Secure Score.

Exam trap

The trap here is that candidates confuse CSPM's configuration-based recommendations and Secure Score with the threat detection and vulnerability scanning features that belong to separate Defender for Cloud workload protection plans, leading them to select options A or D as CSPM features.

69
Multi-Selecthard

Which THREE are valid ways to trigger a playbook in Microsoft Sentinel? (Choose three.)

Select 3 answers
A.Manually from an incident by selecting 'Run playbook'.
B.From an automation rule when an incident is created.
C.From a watchlist item update.
D.From an entity page by clicking 'Investigate'.
E.From an automation rule when an alert is created.
AnswersA, B, E

From an incident, clicking 'Run playbook' opens a side panel where you can select an enabled playbook, which then executes with the Incident trigger. This manual trigger is essential for ad-hoc response, testing, or remediation tasks that require human judgment, and it passes the full incident context—including alerts, entities, and metadata—to the playbook. It is a valid, documented way to launch a playbook on demand.

Why this answer

Option A is correct because Microsoft Sentinel allows analysts to manually trigger a playbook directly from an incident's page by selecting 'Run playbook', which executes the associated Logic App workflow on demand. Option B is correct because automation rules in Microsoft Sentinel can be configured with a trigger of 'When incident is created' and an action of 'Run playbook', automatically invoking the playbook as soon as the incident is generated. Option E is correct because automation rules also support the trigger 'When alert is created', allowing a playbook to be run automatically at alert creation time, before or independently of incident creation.

Option C is not a valid trigger because watchlists are reference data sources and do not have automation-rule triggers for playbook execution. Option D is not a valid trigger because the 'Investigate' action on an entity page opens the investigation experience and does not itself run a playbook.

Exam trap

A common mistake is confusing automation rule triggers: remember that automation rules can trigger on both alert creation and incident creation, but not on watchlist updates or entity page actions.

70
MCQmedium

You are investigating a security incident in Microsoft Sentinel. A KQL query returns results indicating that a user logged in from an IP address that is not in the organization's approved list. The user's account has been compromised. You need to automatically disable the user account in Microsoft Entra ID when such an alert is triggered. What should you configure?

A.Configure an Azure Policy that disables the user account.
B.Use Microsoft Defender for Cloud to automatically disable the account.
C.Create a Power Automate flow triggered by the Sentinel alert.
D.Create a playbook in Microsoft Sentinel with a Logic Apps connector to Microsoft Entra ID.
AnswerD

A Sentinel playbook is an Azure Logic Apps workflow that is designed explicitly to run automated responses in conjunction with Sentinel incidents and alerts. When you create a playbook, you can add a Microsoft Entra ID connector that uses the Microsoft Graph API to perform actions such as disabling a user or updating the accountEnabled property of the target identity. The playbook can be attached to an automation rule that fires on an incident, making it the correct, supported way to automatically disable a compromised account.

Why this answer

Microsoft Sentinel can use playbooks, which are automated workflows built on Azure Logic Apps, to respond to security alerts. By creating a playbook triggered by a Sentinel alert, you can use the Microsoft Entra ID connector to automatically disable a compromised user account, providing a direct and integrated remediation action.

Exam trap

The trap here is that candidates might confuse Microsoft Defender for Cloud's workload protection capabilities with identity-based remediation, or think that Azure Policy can manage Entra ID objects, when in fact only a Logic Apps-based playbook provides the necessary automation and API access to disable a user account.

How to eliminate wrong answers

Option A is wrong because Azure Policy is used to enforce compliance rules on Azure resources (e.g., VMs, storage accounts) and cannot directly disable user accounts in Microsoft Entra ID. Option B is wrong because Microsoft Defender for Cloud focuses on securing cloud workloads and infrastructure, not on managing user identities or automating account disablement in response to Sentinel alerts. Option C is wrong because while Power Automate can be triggered by Sentinel alerts, it lacks the native, deep integration with Microsoft Entra ID that a Logic Apps playbook provides; playbooks are the recommended and more robust method for automated remediation in Sentinel.

71
MCQmedium

A company uses Microsoft Defender for Cloud to protect its hybrid workloads. Security administrators report that critical alerts for SQL servers are not appearing in the Defender for Cloud dashboard. The SQL servers are on-premises and have Azure Arc enabled. Which configuration step should be verified first?

A.Deploy the Log Analytics agent to the SQL servers
B.Configure Azure Firewall logs for SQL traffic
C.Assign the 'Configure Azure Defender for SQL agents on virtual machines' policy
D.Enable the 'SQL servers on machines' plan in Microsoft Defender for Cloud
AnswerD

Enabling the 'SQL servers on machines' plan in Microsoft Defender for Cloud is the prerequisite that activates threat detection for Azure Arc-enabled SQL Server instances. This plan, part of Defender for Cloud's enhanced security features, turns on SQL-specific alerts, vulnerability assessments, and advanced threat protection for on-premises and multi-cloud SQL servers. Without this plan enabled, no SQL server security alerts will be generated regardless of other configurations, so this is the required first step.

Why this answer

For on-premises SQL servers with Azure Arc, the 'SQL servers on machines' plan must be enabled in Microsoft Defender for Cloud to surface alerts. Without enabling this plan, alerts for SQL servers will not appear. Options A and C are related to agent deployment and policy assignment, but the first step is to ensure the plan is enabled.

Option B is unrelated as Azure Firewall logs are not required for SQL-specific alerts.

72
MCQeasy

You are configuring Microsoft Defender for Cloud to protect your Azure virtual machines. You need to enable just-in-time (JIT) VM access to reduce the attack surface. What prerequisite must be met?

A.Configure Microsoft Defender for Cloud Apps with the VMs as connected.
B.Enable the Defender for Cloud 'JIT' plan.
C.Deploy Azure Bastion in the same virtual network.
D.Enable Microsoft Defender for Servers Plan 2.
AnswerD

This is the correct action because JIT VM access is a feature specifically included in Microsoft Defender for Servers Plan 2. When you enable Defender for Servers Plan 2, Defender for Cloud automatically activates JIT and allows you to create just-in-time policies on supported VMs. The JIT feature locks down VM management ports (e.g., SSH 22 and RDP 3389) via NSG rules and opens them temporarily only after approval, with a configurable maximum access duration. Without this plan—or with only Defender for Servers Plan 1—JIT is not available, so enabling Plan 2 is the required step.

Why this answer

Just-in-time (JIT) VM access in Microsoft Defender for Cloud requires Microsoft Defender for Servers Plan 2 to be enabled. This plan provides the advanced security capabilities, including JIT, vulnerability assessment, and file integrity monitoring. Without Plan 2, the JIT blade and policy options are not available, as Plan 1 only covers basic log collection and threat detection.

Exam trap

The trap here is that candidates often confuse the 'JIT' feature as a standalone plan or assume it works with any Defender for Cloud tier, but it specifically requires Defender for Servers Plan 2 (the full server protection plan) to be enabled.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a separate SaaS security broker (CASB) that does not control VM network access or JIT functionality; it focuses on cloud application usage and shadow IT. Option B is wrong because there is no standalone 'JIT plan' in Defender for Cloud; JIT is a feature bundled within Defender for Servers Plan 2, not a separate purchasable plan. Option C is wrong because Azure Bastion provides secure RDP/SSH connectivity via a browser without exposing public IPs, but it is not a prerequisite for JIT; JIT works independently of Bastion and can be used with or without it.

73
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) feature? (Choose two.)

Select 2 answers
A.Block sign-ins from anonymous IP addresses
B.Run KQL queries to find threats across multiple data sources
C.Automatically disable compromised user accounts
D.Detect anomalous behavior based on historical user activity
E.Identify users whose activities are anomalous compared to their peers
AnswersD, E

Microsoft Sentinel UEBA builds a baseline of each user's historical behavior, including sign-in patterns, resource access, and geographic locations, using machine learning. When a user's activity deviates significantly from their own established baseline, UEBA flags it as an anomaly with a risk score. This historical individual baseline is a core mechanism of UEBA, distinguishing it from simple rule-based alerting.

Why this answer

Option D is correct because Microsoft Sentinel UEBA builds behavioral baselines from historical log data (sign-in, Azure Activity, Office 365, etc.) and uses machine learning to surface deviations from a user's own normal activity, such as unusual logon times or data volumes. Option E is correct because UEBA also performs peer-group analysis, comparing each user's actions against similar users in the organization to flag anomalous behavior that would not stand out against the user's own baseline. Options A, B, and C are not UEBA capabilities: blocking anonymous-IP sign-ins is done via Conditional Access or named-location policies, running KQL queries across multiple data sources is core Log Analytics/Sentinel hunting (not UEBA-specific), and automatically disabling compromised accounts requires automated response playbooks (Logic Apps) or identity protection tooling, not UEBA itself.

Exam trap

The trap here is that candidates confuse UEBA's detection-only role with automated response actions (like blocking or disabling accounts), which are separate capabilities in Microsoft Sentinel's automation and playbook features.

74
MCQhard

Your organization has multiple Azure subscriptions and uses Microsoft Defender for Cloud. You need to ensure that all subscriptions have a consistent security policy applied. You create a management group containing all subscriptions. What should you do next to assign a Defender for Cloud initiative to all subscriptions?

A.Use Azure Blueprints to define the initiative and assign it to the management group.
B.Assign the initiative as an Azure Policy at the management group scope.
C.Create a custom RBAC role that includes the initiative and assign it to the management group.
D.Assign the initiative to each subscription individually using the Defender for Cloud interface.
AnswerB

Correct: Policy assignment at management group scope applies to all subscriptions under it.

Why this answer

Assigning the initiative as an Azure Policy at the management group scope is the correct approach because Azure Policy can be applied at the management group, subscription, or resource group level, and it will be inherited by all child subscriptions. This ensures a consistent security policy across all subscriptions without manual per-subscription configuration. Microsoft Defender for Cloud uses Azure Policy initiatives (such as the Microsoft Cloud Security Benchmark) to enforce security controls, and assigning at the management group scope is the most efficient method for bulk compliance.

Exam trap

The trap here is that candidates often confuse Azure Blueprints with Azure Policy inheritance, thinking Blueprints can apply policies across a management group hierarchy, when in fact Blueprints require per-subscription assignment and do not support automatic inheritance like Azure Policy does.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used for deploying repeatable sets of Azure resources and policies, but they require explicit assignment to each subscription and do not automatically inherit down the management group hierarchy like Azure Policy does. Option C is wrong because RBAC roles control permissions to Azure resources, not the assignment of policy initiatives; a custom RBAC role cannot assign or enforce a Defender for Cloud initiative. Option D is wrong because assigning the initiative to each subscription individually is inefficient and error-prone, and it does not leverage the management group inheritance that Azure Policy provides for consistent application.

75
MCQmedium

Your company uses Microsoft Sentinel to monitor security events. You need to detect brute-force attacks against Azure VMs that are not yet onboarded to Sentinel. What should you do?

A.Use the Office 365 connector to collect sign-in logs.
B.Use the Windows Security Events connector via Azure Monitor Agent.
C.Use the Common Event Format connector to forward syslog.
D.Use the Azure Activity connector to collect sign-in logs.
AnswerB

The Windows Security Events connector using the Azure Monitor Agent (AMA) is the correct choice because it collects Windows Event Log entries, including security events such as successful and failed logon attempts (Event IDs 4624, 4625) from Azure VMs. AMA is configured with a data collection rule (DCR) that specifies which event IDs to send to the Log Analytics workspace where Microsoft Sentinel can analyze them. This is exactly the native, supported path for OS-level sign-in monitoring on Windows virtual machines.

Why this answer

The Windows Security Events connector via Azure Monitor Agent can collect security event logs from Azure VMs, including failed logon attempts that indicate brute-force attacks. Since the VMs are not yet onboarded to Sentinel, this connector allows you to ingest their existing Windows Event Logs (specifically Event ID 4625 for failed logons) directly into Sentinel for detection and alerting.

Exam trap

The trap here is that candidates often confuse the Azure Activity connector (which logs control-plane operations) with VM-level sign-in logs, mistakenly thinking it captures authentication events, when it only records resource management activities like VM start/stop.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector collects sign-in logs from Microsoft 365 services, not from Azure VMs, and cannot capture local authentication attempts on the VMs. Option C is wrong because the Common Event Format connector is designed to ingest syslog data from on-premises or third-party appliances, not from Azure VMs that generate Windows Security Events. Option D is wrong because the Azure Activity connector collects subscription-level operational logs (e.g., resource creation, policy changes), not VM-level sign-in or authentication events.

Page 1 of 2 · 119 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Defender Cloud Sentinel questions.