Courseiva

CCNA Defender Cloud Sentinel Questions

44 of 119 questions · Page 2/2 · Defender Cloud Sentinel topic · Answers revealed

76
MCQhard

Your company uses Microsoft Defender for Cloud to protect Azure resources. You notice that some Azure VMs are not showing any security recommendations. You verify that the VMs are running and have network connectivity. What is the most likely cause?

A.The Log Analytics agent is not installed on the VMs
B.The VMs are in a resource group that lacks the required Azure RBAC role
C.The VMs have a resource lock preventing policy evaluation
D.The VMs are in the Free tier of Defender for Cloud
AnswerA

Defender for Cloud relies on the Log Analytics agent (Microsoft Monitoring Agent) on each VM to collect telemetry such as installed patches, endpoint protection status, and audit logs; without it, the VM cannot be assessed and often appears as 'Not monitored' or missing data. The agent sends data to a Log Analytics workspace where the security engine evaluates the configuration and generates recommendations. Therefore, the absence of the agent directly explains why Defender for Cloud shows no or incomplete recommendations for these VMs.

Why this answer

Microsoft Defender for Cloud relies on the Log Analytics agent (or Azure Monitor Agent) to collect security-relevant data from Azure VMs, such as configuration settings, event logs, and vulnerability signals. Without this agent installed, Defender for Cloud cannot assess the VM's security posture, and therefore no security recommendations will be generated for that VM, even if the VM is running and has network connectivity.

Exam trap

The trap here is that candidates often assume network connectivity or VM running status is sufficient for Defender for Cloud to generate recommendations, but they overlook the critical dependency on the Log Analytics agent for data collection and policy evaluation.

How to eliminate wrong answers

Option B is wrong because Azure RBAC roles control who can manage resources, not whether Defender for Cloud can collect data from a VM; the agent installation is what enables data collection. Option C is wrong because resource locks prevent accidental deletion or modification of resources but do not block Defender for Cloud's policy evaluation or data collection from the VM. Option D is wrong because the Free tier of Defender for Cloud still provides security recommendations for Azure VMs; the absence of recommendations is not caused by the pricing tier but by missing data collection via the agent.

77
MCQmedium

You are using Microsoft Sentinel to monitor security events. You need to create a custom analytics rule that detects when a user account is added to a privileged group. The rule should run every 5 minutes and generate an incident. Which query language and data source should you use?

A.KQL against the AzureActivity table.
B.KQL against the AuditLogs table.
C.KQL against the SigninLogs table.
D.KQL against the SecurityEvent table.
AnswerB

The AuditLogs table in Microsoft Sentinel contains Azure Active Directory (Microsoft Entra ID) audit logs, which include events for adding members to groups, especially privileged groups. This is the correct data source for detecting user account additions to privileged groups. KQL is the query language used in Sentinel analytics rules, and this table provides the necessary events.

Why this answer

To detect user account additions to privileged groups, you need Azure Active Directory audit logs, which are stored in the AuditLogs table in Microsoft Sentinel. KQL is the query language for analytics rules. The AuditLogs table captures group management activities, including additions to privileged roles.

The rule can be scheduled to run every 5 minutes and generate incidents when the condition is met.

Exam trap

The trap here is assuming that SecurityEvent or AzureActivity tables contain Azure AD group changes, but those are in AuditLogs.

78
Multi-Selecthard

Which THREE are valid methods to ingest data into Microsoft Sentinel? (Select three.)

Select 3 answers
A.Microsoft Sentinel Data Collector API
B.Azure CLI
C.Common Event Format (CEF) over Syslog
D.Azure Data Factory
E.Azure Monitor Agent
AnswersA, C, E

The Microsoft Sentinel Data Collector API is a valid ingestion method because it provides a direct REST endpoint for sending custom and third-party log sources into a Log Analytics workspace, which Sentinel monitors. It accepts structured data formats such as JSON, and supports the creation of custom log tables, making it essential for integrating proprietary systems or hardening existing connectors. The API uses Azure AD authentication and can be invoked from automation scripts or security tools, enabling near real-time log upload without requiring an agent.

Why this answer

The Microsoft Sentinel Data Collector API is a valid ingestion method because it allows custom logs and data sources to be sent directly to Sentinel via a RESTful API endpoint. This is commonly used for non-standard data sources that do not have built-in connectors, enabling organizations to ingest data from custom applications or legacy systems.

Exam trap

The trap here is that candidates may confuse Azure CLI or Azure Data Factory as valid ingestion methods because they are common Azure tools, but neither directly sends log data to Sentinel's ingestion pipeline.

79
MCQeasy

Refer to the exhibit. This is an excerpt from an Azure Policy assignment. What is the effect of the 'notScopes' property?

A.The policy will apply only to the VM-Sensitive virtual machine.
B.The policy will apply to all resources in RG-Prod except the entire resource group.
C.The policy will apply to all resources in RG-Prod except the VM-Sensitive virtual machine.
D.The policy will apply to the subscription but not to RG-Prod.
AnswerC

The assignment's scope is RG-Prod, making every contained resource subject to policy evaluation. The notScopes array specifies the VM-Sensitive virtual machine resource ID, so that VM alone is excluded from compliance evaluation. All other resources, regardless of type, remain within the assignment's scope and are evaluated.

Why this answer

'notScopes' excludes specific sub-scopes from the policy assignment. In this case, the policy applies to all resources in 'RG-Prod' except the VM named 'VM-Sensitive'. Option A is wrong because 'notScopes' do not add resources.

Option B is wrong because it does not remove the entire resource group. Option D is wrong because it does not affect subscription-level exclusions.

80
Multi-Selecteasy

Which TWO of the following data connectors are available by default in Microsoft Sentinel?

Select 2 answers
A.Palo Alto Networks
B.ServiceNow
C.Microsoft Entra ID
D.Azure Activity
E.Amazon Web Services (AWS)
AnswersC, D

The Microsoft Entra ID connector, like the Azure Activity connector, is available by default in Microsoft Sentinel because it ingests sign-in logs, audit logs, and provisioning logs directly from the Microsoft cloud platform. You still need to enable it and possess the appropriate Microsoft Entra ID P1/P2 or relevant role permissions, but there is no extra licensing for the connector itself; it is considered a built-in, non-premium connector.

Why this answer

Microsoft Entra ID (Option C) is a default data connector in Microsoft Sentinel because it provides native integration for streaming Azure AD audit logs and sign-in logs directly into Sentinel without requiring additional licensing or configuration beyond enabling the connector. This is a core Microsoft source that is automatically available in the Sentinel data connector gallery.

Exam trap

The trap here is that candidates often assume any popular third-party service (like Palo Alto Networks or AWS) is a default connector because of its common use in security monitoring, but Microsoft Sentinel only includes first-party Microsoft services as default connectors, while all third-party integrations require manual setup.

81
MCQeasy

You need to enable Microsoft Defender for Cloud's workload protection for Azure Kubernetes Service (AKS) clusters. Which Defender plan should you enable?

A.Enable the foundational Cloud Security Posture Management (CSPM) plan.
B.Enable Defender for SQL.
C.Enable Defender for Containers.
D.Enable Defender for Servers.
AnswerC

Enabling Defender for Containers is the appropriate plan because it is specifically architected for Kubernetes and AKS, integrating Kubernetes audit logs, control-plane insight, runtime threat detection for workloads, and image vulnerability assessment. At the cluster level it monitors the Kubelet, etcd, and API server while also analyzing behaviors in running containers via the Defender agent (or Azure Arc for hybrid clusters). This single plan provides the runtime protection for container workloads that the scenario requires.

Why this answer

To enable workload protection for Azure Kubernetes Service (AKS) clusters in Microsoft Defender for Cloud, you must enable the Defender for Containers plan. This plan provides runtime threat detection, vulnerability assessment, and compliance monitoring specifically for containerized environments, including AKS, Azure Container Registry (ACR), and Azure Container Instances (ACI). It covers Kubernetes audit logs, host-level security, and container image scanning, which are essential for securing AKS workloads.

Exam trap

The trap here is that candidates often confuse the foundational CSPM plan (which provides basic security recommendations) with the workload-specific Defender plans, mistakenly thinking CSPM alone can protect AKS workloads when it only offers posture visibility without runtime threat detection.

How to eliminate wrong answers

Option A is wrong because the foundational Cloud Security Posture Management (CSPM) plan provides only posture management and basic security recommendations without workload-level threat detection for AKS. Option B is wrong because Defender for SQL is designed to protect Azure SQL Database, SQL Managed Instance, and SQL Server on Azure VMs, not container orchestration platforms like AKS. Option D is wrong because Defender for Servers protects Azure VMs and on-premises servers with endpoint detection and response (EDR) and vulnerability management, but it does not cover Kubernetes-specific threats such as pod-level attacks, container escape, or cluster misconfigurations.

82
Multi-Selecteasy

Which TWO security controls are automatically provided by enabling Microsoft Defender for Cloud's foundational CSPM (Cloud Security Posture Management) capabilities? (Choose two.)

Select 2 answers
A.Azure Firewall Manager integration.
B.Just-in-time (JIT) VM access.
C.Continuous assessment of Azure resources against the Microsoft cloud security benchmark.
D.Security recommendations for Azure resources.
E.Vulnerability assessment for VMs.
AnswersC, D

The foundational cloud security posture management (CSPM) tier in Microsoft Defender for Cloud provides continuous assessment of all supported Azure resources against the Microsoft cloud security benchmark (MCSB), a comprehensive set of security best-practice controls aligned with industry standards. This assessment runs automatically for every onboarded Azure subscription and drives the secure score and compliance dashboards without any additional configuration or licensing. As a built-in, always-on capability, this is a correct answer.

Why this answer

Option C is correct because the foundational CSPM plan in Microsoft Defender for Cloud continuously assesses Azure resources against the Microsoft cloud security benchmark (MCSB), producing a secure score and compliance view without any additional agent or paid plan. Option D is correct because the same foundational CSPM capabilities generate security recommendations for Azure resources based on those assessments, guiding remediation of misconfigurations. Options A, B, and E are not part of the free foundational CSPM offering: Azure Firewall Manager integration is a separate networking service, just-in-time VM access requires the paid Defender for Servers plan (Plan 2), and vulnerability assessment for VMs is also provided by Defender for Servers rather than by foundational CSPM.

83
MCQmedium

You are configuring Microsoft Defender for Cloud for a subscription that contains Azure Kubernetes Service (AKS) clusters. You need to ensure that Defender for Containers provides vulnerability assessment for container images stored in Azure Container Registry (ACR). What should you enable?

A.Enable the Defender for App Service plan and configure the ACR integration from the App Service environment.
B.Enable the Defender for Containers plan and ensure that the ACR integration is turned on, then grant the Defender for Cloud service principal the AcrPull role on the registry.
C.Enable the Defender for Storage plan and configure a private endpoint to ACR.
D.Enable the Defender for Servers plan and deploy the Log Analytics agent to all AKS nodes.
AnswerB

Defender for Containers includes vulnerability assessment for container images in ACR when the ACR integration is enabled. The integration requires the Defender for Cloud service principal to have AcrPull permissions to scan images. This allows Defender for Cloud to pull and analyze images for vulnerabilities, providing continuous assessment as new images are pushed.

Why this answer

Defender for Containers is the correct plan for protecting AKS clusters and container images in ACR. Enabling the plan and the ACR integration, along with granting the service principal AcrPull permissions, allows Defender for Cloud to scan images for vulnerabilities. The other plans target different resource types and do not include container image assessment.

Exam trap

The trap here is selecting Defender for Servers because AKS nodes are VMs, but container image scanning requires Defender for Containers.

84
MCQmedium

Refer to the exhibit. You are creating a Microsoft Sentinel scheduled analytics rule using the KQL query shown. The rule is set to run every hour. What will this rule detect?

A.Successful logins from a single IP address
B.Accounts that have more than 10 failed logins from a specific IP address in the last hour
C.Total failed logins in the last 24 hours
D.Accounts with more than 10 failed logins from any IP address
AnswerB

This is the correct answer because the query applies a 1-hour time filter via `TimeGenerated > ago(1h)`, selects only EventID 4625 (failed logons), and then runs `summarize Count = count() by Account, IpAddress`. The final `Count > 10` condition in the `having` clause ensures only account/IP pairs that exceeded 10 failures within that hour are returned, matching the described behavior.

Why this answer

The KQL query uses `summarize` with `bin(TimeGenerated, 1h)` to count failed logins per account and IP address within 1-hour bins. The `where` clause filters for `ResultType == 50057` (failed logins) and `where count_ > 10` ensures only accounts with more than 10 failed logins from a specific IP in that hour are returned. Since the rule runs every hour, it detects accounts exceeding 10 failed logins from a single IP in the last hour.

Exam trap

The trap here is that candidates overlook the `summarize` grouping by both `Account` and `IPAddress`, mistakenly thinking the count applies to all IPs combined, or they misinterpret `bin(TimeGenerated, 1h)` as a 24-hour window instead of a 1-hour aggregation.

How to eliminate wrong answers

Option A is wrong because the query specifically filters for `ResultType == 50057` (failed logins), not successful logins. Option C is wrong because the query uses `bin(TimeGenerated, 1h)` to aggregate data in 1-hour windows, not 24 hours. Option D is wrong because the `summarize` clause groups by `IPAddress` as well as `Account`, meaning it counts failed logins per specific IP address, not from any IP address.

85
Multi-Selectmedium

Which TWO are features of Microsoft Defender for Cloud's workload protection for Azure SQL databases? (Select two.)

Select 2 answers
A.File integrity monitoring (FIM)
B.Adaptive network hardening
C.Just-in-time VM access
D.Advanced threat protection (ATP)
E.Vulnerability assessment
AnswersD, E

Advanced threat protection (ATP) for Azure SQL is a built-in feature of Microsoft Defender for SQL that continuously monitors database activity for unusual access patterns, suspicious location changes, and potential SQL injection attempts. It generates security alerts for anomalies such as a user accessing the database from an unfamiliar IP address or an attempt to enumerate credentials. This makes ATP a correct choice because it directly protects SQL database workload.

Why this answer

Option D (Advanced threat protection/ATP) is correct because Microsoft Defender for Cloud's workload protection for Azure SQL databases includes Defender for SQL's advanced threat protection, which detects anomalous activities such as potential SQL injection, brute-force attempts, and unusual access patterns, and raises security alerts. Option E (Vulnerability assessment) is correct because Defender for SQL provides a built-in vulnerability assessment that scans Azure SQL databases for misconfigurations, missing security updates, and other weaknesses, with findings surfaced in Defender for Cloud. Option A (File integrity monitoring) is not correct here because FIM applies to files and registry keys on servers/VMs (via Defender for Servers/Log Analytics), not to Azure SQL database workload protection.

Option B (Adaptive network hardening) is not correct because it is a Defender for Cloud feature for virtual machines that analyzes network security group rules and traffic patterns, not a SQL database protection feature. Option C (Just-in-time VM access) is not correct because JIT VM access is a Defender for Servers capability that locks down management ports on VMs, not an Azure SQL database workload protection feature.

Exam trap

The trap here is that candidates often confuse workload protection features that apply broadly to VMs (like FIM, Adaptive Network Hardening, and JIT VM Access) with those specifically designed for PaaS services like Azure SQL, leading them to select options that are not applicable to databases.

86
MCQeasy

Refer to the exhibit. You are assigning a built-in Azure Policy definition to a subscription using Azure CLI. The policy is 'Audit VMs that do not use managed disks'. After assignment, you check in Microsoft Defender for Cloud and see that the policy is not generating any recommendations. What is the most likely reason?

A.The policy effect is set to 'Audit', but it should be 'Deny' to generate recommendations.
B.The policy requires a managed identity to run.
C.The policy is not part of a Defender for Cloud security initiative.
D.The policy is assigned to the wrong subscription.
AnswerC

Defender for Cloud does not display recommendations for every individual policy assigned in the environment; it only generates recommendations from policies that belong to a security initiative, such as the Azure Security Benchmark, that is assigned to the subscription or management group. A standalone policy assigned directly to the subscription will produce compliance results in Azure Policy but will not appear as a security recommendation in Defender for Cloud. Therefore, the missing initiative membership explains why this policy's recommendations are not visible.

Why this answer

Microsoft Defender for Cloud only generates security recommendations from policies that are part of a built-in or custom security initiative (such as the 'Microsoft cloud security benchmark' initiative). A standalone policy assignment, even if it has the 'Audit' effect, will not appear as a recommendation in Defender for Cloud unless it is included in an initiative that Defender for Cloud monitors.

Exam trap

The trap here is that candidates assume any Azure Policy with an 'Audit' effect will automatically generate a recommendation in Defender for Cloud, but in reality, only policies that are part of a Defender for Cloud security initiative are surfaced as recommendations.

How to eliminate wrong answers

Option A is wrong because the 'Audit' effect is specifically designed to log non-compliant resources and generate compliance results; changing it to 'Deny' would block non-compliant VMs but would not cause recommendations to appear in Defender for Cloud. Option B is wrong because this particular built-in policy ('Audit VMs that do not use managed disks') does not require a managed identity; it uses the Azure Resource Manager to evaluate resource properties without needing to perform any action that requires authentication. Option D is wrong because if the policy were assigned to the wrong subscription, it would simply evaluate resources in that subscription (or fail to evaluate the intended ones), but it would not prevent recommendations from appearing in Defender for Cloud for the assigned subscription; the core issue is the lack of initiative membership, not the subscription scope.

87
MCQmedium

Refer to the exhibit. You are reviewing the encryption configuration of an Azure Log Analytics workspace used by Microsoft Sentinel. The configuration shows infrastructure encryption enabled and customer-managed key (CMK) from Azure Key Vault. What additional step must be taken to ensure that the CMK is used for all data?

A.Enable double encryption on Sentinel
B.Enable purge protection on the Key Vault
C.Grant the Log Analytics workspace access to the Key Vault key
D.Ensure the Key Vault is in a different region than the workspace
AnswerC

For Sentinel to use a customer-managed key, the Log Analytics workspace that stores Sentinel data must present a managed identity and be granted explicit cryptographic permissions on the Key Vault key. Specifically, the workspace needs Key Vault operations such as Get, WrapKey, and UnwrapKey to encrypt and decrypt the workspace's data encryption key. This access is granted through a Key Vault access policy, so provisioning that policy is the correct remediation.

Why this answer

When you configure a customer-managed key (CMK) for a Log Analytics workspace, you must explicitly grant the workspace (via its managed identity) the 'Get', 'Unwrap Key', and 'Wrap Key' permissions on the Key Vault key. Without this access, the workspace cannot use the CMK to encrypt data at rest. Option C correctly identifies this required step.

Exam trap

The trap here is that candidates often confuse enabling CMK with simply selecting a key from Key Vault, forgetting that the workspace must be explicitly granted cryptographic permissions on that key to actually use it for encryption.

How to eliminate wrong answers

Option A is wrong because 'double encryption' is not a configurable setting in Microsoft Sentinel; infrastructure encryption already provides encryption at the storage layer, and enabling CMK adds a second layer, but no separate 'double encryption' toggle exists. Option B is wrong because purge protection is a Key Vault soft-delete feature that prevents permanent deletion of keys, but it does not affect whether the workspace can use the CMK for encryption. Option D is wrong because the Key Vault can be in any region; there is no requirement for it to be in a different region than the workspace, and placing it in a different region would add latency without any security benefit.

88
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Defender for Cloud's regulatory compliance dashboard? (Select two.)

Select 2 answers
A.Create custom regulatory compliance recommendations.
B.Automatically remediate non-compliant resources.
C.View the compliance status for built-in standards like SOC 2 or PCI DSS.
D.Assign a compliance standard (e.g., SOC 2) to a subscription.
E.Enable or disable Microsoft Defender plans for a subscription.
AnswersC, D

The regulatory compliance view in Microsoft Defender for Cloud displays a continuous assessment of Azure resources against built-in regulatory standards such as SOC 2, PCI DSS, ISO 27001, and GDPR. For each assigned standard, the dashboard shows controls, policy mappings, and pass/fail status, making it the primary interface for monitoring compliance posture across subscriptions. This is a read-only visibility function, distinct from modifying standards or plans.

Why this answer

The regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance status against built-in standards such as SOC 2, PCI DSS, ISO 27001, and Azure CIS. This dashboard aggregates security assessments and displays pass/fail status for each control, allowing you to track your compliance posture without manual configuration.

Exam trap

The trap here is that candidates often confuse the regulatory compliance dashboard's ability to assign standards (which is correct) with the ability to create custom recommendations or auto-remediate, which are separate functions handled by Azure Policy and Defender for Cloud's security recommendations, not the compliance dashboard itself.

89
MCQmedium

You are configuring Microsoft Defender for Cloud's regulatory compliance dashboard. Your organization must comply with SOC 2. You have enabled the SOC 2 regulatory compliance standard. After a week, some controls show as 'Unhealthy'. What is the most likely reason for the 'Unhealthy' status?

A.The standard is not fully enabled for all subscriptions.
B.The SOC 2 standard is not supported by Defender for Cloud.
C.You need to manually attest to the controls to mark them as healthy.
D.The underlying Azure Policy initiatives have resources that are non-compliant.
AnswerD

Regulatory compliance in Defender for Cloud is built on Azure Policy initiatives: each control is backed by one or more policy definitions that continuously audit your resources. When a resource is found to be non-compliant with a policy assignment, the corresponding control is marked 'Unhealthy', since compliance is aggregated at the control level across all evaluated resources. This is the direct and expected cause of the unhealthy status you are seeing, rather than a misconfiguration of the standard assignment.

Why this answer

The 'Unhealthy' status in Defender for Cloud's regulatory compliance dashboard indicates that the underlying Azure Policy initiatives associated with the SOC 2 standard have identified resources that are non-compliant. Defender for Cloud maps regulatory standards to Azure Policy definitions, and the compliance score is derived from the compliance state of those policies. Therefore, when controls show as 'Unhealthy', it is because the corresponding Azure Policy evaluations have found resources that do not meet the required configuration or security controls defined by SOC 2.

Exam trap

The trap here is that candidates often assume 'Unhealthy' means the standard is misconfigured or not fully enabled, rather than understanding that it directly reflects Azure Policy non-compliance results from the underlying resources.

How to eliminate wrong answers

Option A is wrong because enabling the SOC 2 standard for all subscriptions is not required for the standard to show controls; the standard is enabled at the management group or subscription scope, and partial enablement would not cause individual controls to show as 'Unhealthy'—it would simply not evaluate those subscriptions. Option B is wrong because SOC 2 is a supported regulatory compliance standard in Microsoft Defender for Cloud, as documented in the list of available standards. Option C is wrong because manual attestation is not a feature for marking controls as healthy; compliance is determined automatically by Azure Policy evaluations, and there is no manual attestation mechanism for SOC 2 controls in Defender for Cloud.

90
MCQeasy

Your company uses Microsoft Defender for Cloud's 'Vulnerability Assessment' solution for Azure VMs. You have enabled the 'Microsoft Defender for Servers' plan and deployed the integrated Qualys agent. You need to view the vulnerability assessment findings for all VMs in a single dashboard in Microsoft Defender for Cloud. Which blade in the Defender for Cloud portal should you navigate to?

A.Inventory
B.Security alerts
C.Regulatory compliance
D.Recommendations
AnswerD

In Defender for Cloud, every vulnerability assessment result is represented as a recommendation; the 'Remediate vulnerabilities' recommendation contains all discovered findings across your machines. When you open it, you see affected resources, CVE IDs, severity scores, and remediation guidance, and the findings update as scans complete. This is the dedicated location where vulnerability data is surfaced for action.

Why this answer

The correct option is D, Recommendations. In Microsoft Defender for Cloud, vulnerability assessment findings from the integrated Qualys agent (part of the Defender for Servers plan) are surfaced as security recommendations, so navigating to the Recommendations blade lets you view and filter findings such as 'Vulnerabilities in your virtual machines should be remediated' across all VMs in one place. The Inventory blade only lists resources and their security posture, not aggregated vulnerability findings.

Security alerts shows active threat detections rather than vulnerability assessment results. Regulatory compliance maps controls to standards and does not present the raw vulnerability findings dashboard.

91
Multi-Selectmedium

Which TWO actions should you take to integrate on-premises servers with Microsoft Defender for Cloud for unified security management? (Choose two.)

Select 2 answers
A.Install the Log Analytics agent on each server.
B.Migrate the servers to Azure Stack HCI.
C.Enroll the servers in Microsoft Intune.
D.Deploy the Azure Connected Machine agent (Azure Arc) on each server.
E.Establish a site-to-site VPN connection to Azure.
AnswersA, D

This is a correct action because the Log Analytics agent (or its successor, the Azure Monitor Agent) is required to collect security-relevant data from each server's event logs, performance counters, and syslog. Defender for Cloud correlates this data into security alerts, vulnerabilities, and compliance recommendations. Without the agent, the on-premises server would be invisible to Defender for Cloud's detection engine, so installing it is a direct prerequisite for the integration.

Why this answer

The Log Analytics agent (now the Azure Monitor Agent) is required to collect security events and performance data from on-premises servers and send it to the Log Analytics workspace used by Microsoft Defender for Cloud. This enables Defender for Cloud to apply security policies, detect threats, and provide unified security management across hybrid environments.

Exam trap

The trap here is that candidates often confuse network connectivity (VPN) with agent-based data collection, or they mistakenly think Intune or Azure Stack HCI are valid integration methods for Defender for Cloud's hybrid security management.

92
MCQmedium

You are a security analyst in a company that uses Microsoft Sentinel. You need to create a hunting query that identifies failed sign-in attempts from a specific IP address range and then automatically create an incident if the count exceeds a threshold. Which Microsoft Sentinel feature should you use?

A.Create a scheduled analytics rule that runs the query and triggers an incident based on the threshold.
B.Configure a workbook that visualizes failed sign-ins and set up an alert rule in Azure Monitor to create an incident.
C.Create a playbook that runs the query on a schedule and sends an email to the security team.
D.Use the hunting dashboard to run the query and manually create an incident from the results.
AnswerA

Scheduled analytics rules in Microsoft Sentinel are designed to run queries at regular intervals, evaluate results against a threshold, and generate incidents automatically. You can write a query to filter failed sign-ins from the IP range, set the rule to trigger when the number of results exceeds a specified threshold, and configure incident creation. This directly meets the requirement for automated detection and incident generation.

Why this answer

Scheduled analytics rules are the correct feature for automated detection and incident creation in Microsoft Sentinel. They allow you to define a query, set a schedule, and specify a threshold for generating incidents. When the query returns results exceeding the threshold, Sentinel creates an incident with the mapped entities.

This is ideal for detecting patterns like multiple failed sign-ins from a specific IP range. Other features like hunting or workbooks do not provide this automated incident creation capability.

Exam trap

The trap here is confusing hunting queries with scheduled analytics rules; hunting is for manual exploration, while scheduled analytics rules are for automated detection and incident generation.

93
MCQeasy

Your organization uses Microsoft Defender for Cloud. You need to ensure that all Azure subscriptions have the 'Auto-provisioning' extension enabled for Log Analytics agent on new VMs. What should you configure?

A.Configure Azure Automation State Configuration to push the agent.
B.Set up data connectors in Microsoft Sentinel.
C.Enable 'Auto-provisioning' in Defender for Cloud's environment settings.
D.Create an Azure Policy assignment to deploy the Log Analytics agent.
AnswerC

In Defender for Cloud's environment settings, enabling 'Auto-provisioning' deploys the Log Analytics agent extension automatically to new VMs without manual intervention. This satisfies the stem's requirement for a subscription-wide, automated mechanism that ensures all new VMs receive the agent, as opposed to per-VM manual installation or policy-based assignment.

Why this answer

Defender for Cloud's environment settings include a dedicated 'Auto-provisioning' toggle for the Log Analytics agent. When enabled, Defender for Cloud automatically installs the agent on any new Azure VM that is provisioned in the selected subscriptions, ensuring continuous monitoring without manual intervention. This is the native mechanism within Defender for Cloud to enforce agent deployment at scale.

Exam trap

The trap here is that candidates often confuse the Azure Policy-based deployment of the Log Analytics agent (which is a valid method but not the one specified in the question) with Defender for Cloud's native auto-provisioning toggle, leading them to select option D instead of C.

How to eliminate wrong answers

Option A is wrong because Azure Automation State Configuration (DSC) is a configuration management tool that can install software, but it is not the built-in method for auto-provisioning the Log Analytics agent across all subscriptions; it requires custom DSC configurations and does not integrate with Defender for Cloud's auto-provisioning logic. Option B is wrong because data connectors in Microsoft Sentinel are used to ingest logs from various sources into Sentinel, not to enable auto-provisioning of the Log Analytics agent on new VMs; Sentinel relies on the agent being already present or deployed separately. Option D is wrong because while an Azure Policy assignment can deploy the Log Analytics agent via the 'Deploy Log Analytics agent' built-in policy, it is a separate mechanism from Defender for Cloud's auto-provisioning setting; the question specifically asks for the configuration within Defender for Cloud, not a policy-based approach.

94
MCQmedium

Your organization uses Microsoft Defender for Cloud to protect Azure workloads. You notice that a critical Azure VM is not covered by any of the Defender for Cloud plans. You need to ensure that the VM is protected by the Defender for Servers plan. What should you do?

A.Create a custom Azure Policy to assign the Defender for Servers plan to the VM.
B.Enable the Defender for Servers plan in the Defender for Cloud environment settings for the subscription containing the VM.
C.Enable the Defender for Servers plan directly on the VM's security configuration blade.
D.Ensure the VM is running a supported operating system; the plan is automatically enabled for all VMs.
AnswerB

Navigate to Defender for Cloud > Environment settings, select the subscription that contains the VM, and under 'Defender plans' toggle the Defender for Servers plan to On. This activation is a subscription-scoped configuration that immediately protects the target VM as well as all other current and future VMs in that subscription (assuming the subscription is the plan's scope). The environment settings blade is the authoritative place for enabling any Defender plan; once enabled, the VM's Defender for Cloud status changes to covered, and you will start accruing per-resource billing according to the plan's pricing model.

Why this answer

Defender for Cloud plans are enabled at the subscription level, not per resource. By enabling the Defender for Servers plan in the Defender for Cloud environment settings for the subscription containing the VM, all current and future VMs in that subscription will be automatically protected, including the critical VM in question.

Exam trap

The trap here is that candidates often think Defender for Cloud plans can be enabled per resource (like a VM) or via Azure Policy, when in fact they are subscription-level settings that must be enabled in the Defender for Cloud environment settings.

How to eliminate wrong answers

Option A is wrong because custom Azure Policy can enforce compliance but cannot directly enable a Defender for Cloud plan; plans are enabled at the subscription or management group level in Defender for Cloud settings, not via policy assignment. Option C is wrong because there is no 'Defender for Servers plan' toggle on a VM's security configuration blade; Defender for Cloud plans are configured at the subscription level in the Defender for Cloud environment settings, not per VM. Option D is wrong because while supported OS is required for protection, the plan is not automatically enabled for all VMs; it must be explicitly enabled at the subscription level.

95
MCQhard

You are a security engineer for Contoso Ltd. The company has a hybrid environment with Azure VMs and on-premises servers running Windows Server 2022. You have enabled Microsoft Defender for Cloud's multi-cloud posture management for AWS and GCP. Recently, you deployed Microsoft Sentinel in a Log Analytics workspace named 'ContosoWorkspace'. The security team needs to centralize security alerts from all sources: Azure, on-premises, AWS, and GCP. They also require automated investigation and response for common threats. Specifically, they want to automatically disable a compromised user account when a high-severity alert is generated. You have configured data connectors for Azure Activity, Microsoft Entra ID, and AWS CloudTrail. For on-premises servers, you installed the Azure Monitor Agent (AMA) and enabled Defender for Cloud's plan for servers. For GCP, you are using the GCP Security Command Center connector. The team needs to create a playbook that runs when a high-severity alert from any source is triggered. The playbook should disable the user account in Microsoft Entra ID. You have created a playbook using Azure Logic Apps and granted it the necessary permissions. Which step should you take to ensure the playbook runs automatically when alerts are generated?

A.Create an automation rule in Microsoft Sentinel that triggers the playbook when a high-severity alert is created.
B.Create an automation rule in Microsoft Defender for Cloud that triggers the playbook when a high-severity alert is generated.
C.Create an analytics rule in Microsoft Sentinel that triggers the playbook when a high-severity alert is created.
D.Configure the Logic App to run on a schedule and query Sentinel for high-severity alerts.
AnswerA

In Microsoft Sentinel, automation rules are the native mechanism for executing a playbook when an incident or alert is generated; you configure a condition such as 'Alert severity equals High' and an action of 'Run playbook' on the selected Logic App. This triggers immediately at alert creation time, without requiring polling or scheduled jobs. It is the correct and recommended approach for real-time response to high-severity Sentinel alerts.

Why this answer

The correct option is A: create an automation rule in Microsoft Sentinel that triggers the playbook when a high-severity alert is created. Automation rules in Microsoft Sentinel are the native mechanism for automatically invoking playbooks (Logic Apps) in response to incidents or alerts, and they can filter by severity so the playbook runs only for high-severity alerts. Option B is wrong because automation rules in Microsoft Defender for Cloud govern Defender for Cloud alerts and cannot directly trigger a Sentinel playbook for alerts from all connected sources.

Option C is wrong because analytics rules generate alerts/incidents from ingested data; they do not trigger playbooks. Option D is wrong because a scheduled Logic App polling Sentinel would not provide the required automatic, event-driven response when an alert is generated.

96
MCQmedium

You are a security engineer for a company that uses Microsoft Sentinel. The security operations center (SOC) wants to automatically assign new incidents to the on-call analyst based on the incident's severity and product name. You need to configure this with minimal administrative effort. What should you do?

A.Create an automation rule that triggers when an incident is created and uses conditions on severity and product name to assign the incident to a specific owner.
B.Use an analytics rule that groups related alerts into incidents and sets the owner based on severity and product name.
C.Configure a playbook that runs on incident creation and uses the 'Update incident' action to assign the incident to the on-call analyst.
D.Modify the incident settings in Microsoft Sentinel to enable automatic assignment of incidents to the on-call analyst based on severity and product name.
AnswerA

Automation rules in Microsoft Sentinel are designed to automatically triage incidents. They can trigger on incident creation and evaluate conditions such as severity and product name. The action 'Assign owner' allows you to set the incident owner dynamically, fulfilling the requirement with minimal effort.

Why this answer

Automation rules in Microsoft Sentinel are the native mechanism for automatically triaging incidents. They can trigger on incident creation, evaluate conditions such as severity and product name, and perform actions like assigning an owner. This approach requires minimal configuration and directly addresses the SOC's requirement without the overhead of building a playbook.

Exam trap

The trap here is assuming that analytics rules or incident settings can automatically assign incident owners, when in fact that capability resides in automation rules.

97
MCQmedium

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. The query returns a list of IP addresses that have attempted to sign in more than 10 times in the last day. You notice that the query does not filter out successful sign-ins. You need to modify the query to count only failed sign-in attempts. What should you add?

A.Add '| where Status == "Failure"' before the summarize
B.Add '| where Result == "Failure"' before the summarize
C.Add '| where ResultType == "0"' before the summarize
D.Add '| where ResultType != "0"' before the summarize
AnswerD

Placing `ResultType != '0'` before the summarize filters the stream down to failed authentication attempts, because every successful sign-in shares ResultType 0 and every non-zero code represents a specific failure condition. Kusto evaluates row filters before aggregations, so the subsequent summarize counts only the intended failure events and produces the required hourly failure trend. This predicate also avoids the non-existent columns and string labels used in the incorrect options.

Why this answer

In Microsoft Sentinel, the KQL query for sign-in logs uses the 'ResultType' field to indicate success or failure. A 'ResultType' of '0' represents a successful sign-in, while any non-zero value indicates a failure. Therefore, to count only failed sign-in attempts, you must filter with '| where ResultType != "0"' before the summarize operator.

Option D correctly applies this filter, excluding successful sign-ins and ensuring the count reflects only failures.

Exam trap

The trap here is that candidates may confuse the field names (e.g., 'Status' or 'Result') or mistakenly filter for 'ResultType == "0"' (success) instead of 'ResultType != "0"' (failure), because the question explicitly asks to count only failed attempts.

How to eliminate wrong answers

Option A is wrong because 'Status' is not a standard field in Azure AD sign-in logs; the correct field for sign-in outcome is 'ResultType'. Option B is wrong because 'Result' is not a valid field name in the SigninLogs table; the actual field is 'ResultType'. Option C is wrong because 'ResultType == "0"' would filter for successful sign-ins only, which is the opposite of what is needed.

98
MCQmedium

Your company uses Microsoft Defender for Cloud to assess the security posture of Azure subscriptions. The security team receives an alert about a critical vulnerability in an Azure VM that was remediated two weeks ago. What is the most likely reason the alert is still active?

A.The VM has not been rescanned after the remediation was applied.
B.The alert is a false positive due to a known issue in the vulnerability assessment engine.
C.The alert has a 30-day retention period and cannot be dismissed before that.
D.Silent Remediation was enabled, preventing the alert from being dismissed.
AnswerA

Defender for Cloud evaluates VMs against the last completed vulnerability scan, not in real time. Applying a patch or configuration change does not automatically clear the finding; the VM must be rescanned (via the 'Rescan' action or the next scheduled scan) for the vulnerability status to refresh. Without that rescan, the vulnerability management dashboard continues to show the VM as vulnerable, even though the remediation actually succeeded.

Why this answer

The alert remains active because Microsoft Defender for Cloud relies on periodic vulnerability scans to update the security findings. Remediating the vulnerability on the VM does not automatically trigger a rescan; the alert status is only updated after the next scheduled scan or a manual rescan is initiated. Until the VM is rescanned, Defender for Cloud continues to display the previous vulnerable state.

Exam trap

The trap here is that candidates assume remediation automatically clears the alert, but Microsoft Defender for Cloud requires a rescan to update the vulnerability state, and the alert will persist until the next scan cycle or manual rescan.

How to eliminate wrong answers

Option B is wrong because false positives in the vulnerability assessment engine are rare and typically documented; the question states the vulnerability was actually remediated, so the alert is not a false positive. Option C is wrong because alerts in Defender for Cloud do not have a mandatory 30-day retention period that prevents dismissal; alerts can be dismissed or closed manually once the issue is resolved, and retention policies affect historical data, not active alert status. Option D is wrong because Silent Remediation is a feature for automatically applying certain recommendations, but it does not prevent alerts from being dismissed; it actually helps resolve vulnerabilities, and the alert would still update after a rescan.

99
MCQmedium

You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). You need to collect sign-in logs and audit logs. Which data connector should you enable?

A.Azure AD Identity Protection
B.Office 365
C.Azure AD Authentication
D.Azure Active Directory (now Microsoft Entra ID)
AnswerD

The Azure Active Directory (now Microsoft Entra ID) connector is the correct choice because it directly ingests both SignInLogs and AuditLogs into Sentinel. This enables monitoring of user sign-in attempts, multi-factor authentication challenges, and directory configuration changes, providing the core identity telemetry needed for investigations.

Why this answer

The Azure Active Directory (now Microsoft Entra ID) data connector is the correct choice because it is specifically designed to ingest both sign-in logs and audit logs from Microsoft Entra ID into Microsoft Sentinel. This connector enables the collection of user sign-in activities and directory audit events, which are essential for security monitoring and incident detection.

Exam trap

The trap here is that candidates may confuse the 'Office 365' connector (which handles Exchange, SharePoint, and Teams logs) with Azure AD logs, or mistakenly think 'Azure AD Authentication' is a valid connector name, when the correct name is 'Azure Active Directory' (now Microsoft Entra ID).

How to eliminate wrong answers

Option A is wrong because Azure AD Identity Protection is a separate service that provides risk detection and conditional access policies, not a data connector for ingesting sign-in and audit logs into Sentinel. Option B is wrong because the Office 365 connector ingests logs from Exchange Online, SharePoint Online, and Teams, not from Azure AD sign-in or audit activities. Option C is wrong because Azure AD Authentication is not a valid data connector name in Sentinel; the correct connector is named 'Azure Active Directory' (now Microsoft Entra ID).

100
MCQhard

Your organization has Microsoft Sentinel deployed in the East US region. You need to ensure that security logs are retained for 2 years to meet compliance requirements. The workspace retention policy is set to 90 days. What should you do?

A.Configure data retention for the specific tables that need long-term retention
B.Change the workspace retention setting to 730 days
C.Use Azure Policy to enforce retention on the Log Analytics workspace
D.Export logs to an Azure Storage account and set a lifecycle management policy
AnswerA

Configuring table-level retention in Log Analytics is the most precise way to meet long-term retention requirements because each table (e.g., SecurityEvent, SigninLogs) can have its own retention period, independent of the workspace default. This allows you to keep security-critical tables for up to 730 days (or 2 years for some data types) while avoiding the cost of retaining verbose, low-value tables like Perf or Heartbeat for that long. The Azure portal, Azure CLI, and the Tables API all support setting per-table retention, making it a supported and audit-friendly solution.

Why this answer

Microsoft Sentinel allows you to configure table-level retention in Log Analytics workspaces, overriding the workspace default retention of 90 days. By setting the retention period to 730 days (2 years) on specific tables containing security logs, you meet compliance requirements without affecting other tables. This is the recommended approach for long-term retention of security data in Sentinel.

Exam trap

The trap here is that candidates often assume workspace-level retention is the only option, overlooking the table-level retention feature in Log Analytics that Sentinel uses to meet specific compliance needs without exporting data.

How to eliminate wrong answers

Option B is wrong because changing the workspace retention setting to 730 days would apply to all tables in the workspace, which may not be necessary or cost-effective for non-security tables, and it does not leverage Sentinel's table-level retention capabilities. Option C is wrong because Azure Policy can enforce compliance rules but cannot directly set retention periods on Log Analytics tables; it would require custom policy definitions and still relies on table-level settings. Option D is wrong because exporting logs to Azure Storage with lifecycle management retains the data but removes it from Sentinel's queryable workspace, breaking the ability to run security analytics and incident investigations within Sentinel.

101
MCQeasy

Your company has multiple Azure subscriptions. You need to centralize security alerts and incidents in a single dashboard for the security operations center (SOC) team. The solution should provide advanced analytics and threat detection. Which service should you use?

A.Azure Monitor
B.Microsoft Sentinel
C.Microsoft 365 Defender
D.Microsoft Defender for Cloud
AnswerB

Microsoft Sentinel is a cloud-native SIEM and SOAR solution specifically designed to collect and centralize security alerts and data from all Azure subscriptions and external sources. It uses built-in analytics, fusion, and UEBA to detect threats, and provides incident management, investigation, and automated response across the enterprise. For the requirement to centralize security alerts across multiple Azure subscriptions, Sentinel is the correct choice because it aggregates alerts from Defender for Cloud and other sources into a single, actionable incident queue.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that centralizes security alerts and incidents from multiple Azure subscriptions into a single dashboard. It provides advanced analytics, built-in threat detection, and AI-driven investigation capabilities, making it ideal for a SOC team requiring a unified view across the enterprise.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM and workload protection tool) with a SIEM solution, but Defender for Cloud lacks the centralized incident management and advanced analytics capabilities that Microsoft Sentinel provides for a SOC dashboard.

How to eliminate wrong answers

Option A is wrong because Azure Monitor is a platform monitoring service focused on collecting and analyzing telemetry from Azure resources (metrics, logs) for performance and health, not for aggregating security alerts and incidents with advanced threat detection. Option C is wrong because Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite for endpoints, identities, email, and apps, but it does not natively centralize security alerts from multiple Azure subscriptions into a single SOC dashboard; it integrates with Sentinel for that purpose. Option D is wrong because Microsoft Defender for Cloud (formerly Azure Security Center) provides security posture management and threat protection for cloud workloads, but it lacks the full SIEM capabilities (e.g., custom analytics, incident management, and SOAR) required for a centralized SOC dashboard across subscriptions; it feeds alerts into Sentinel for advanced correlation.

102
Multi-Selectmedium

Which TWO of the following are valid data sources for Microsoft Sentinel's UEBA (User and Entity Behavior Analytics)? (Select two.)

Select 2 answers
A.Microsoft Entra ID sign-in logs.
B.Microsoft Entra ID audit logs.
C.Azure SQL Database audit logs.
D.Azure Activity Logs.
E.Azure Firewall logs.
AnswersA, B

Microsoft Entra ID sign-in logs are a core UEBA data source in Microsoft Sentinel because UEBA profiles entities based on authentication behavior, such as successful/failed logons, anomalous locations, impossible travel, and device attributes. These logs feed the UEBA engine to establish baselines and detect risky sign-in patterns. Without them, UEBA would lack the primary signal for user identity and access activity.

Why this answer

Microsoft Sentinel UEBA is designed to ingest identity-centric telemetry, and Microsoft Entra ID sign-in logs (option A) are a core data source because they provide the authentication events (user, application, IP, location, device, risk level) that UEBA uses to build behavioral baselines and detect anomalous sign-in activity. Microsoft Entra ID audit logs (option B) are also a valid UEBA source, since they record directory-level changes such as user, group, role, and application modifications that feed entity behavior profiling and help correlate administrative actions with other activity. Options C, D, and E are not among the documented UEBA data sources: Azure SQL Database audit logs, Azure Activity Logs, and Azure Firewall logs are resource/network telemetry that can be collected into Sentinel for analytics, but they are not identity behavior sources used by the UEBA engine.

103
Multi-Selecteasy

Your organization wants to use Microsoft Sentinel to detect and respond to threats. You need to ensure that Sentinel can ingest data from Azure Firewall logs. Which three components are required? (Choose three.)

Select 3 answers
A.Enable diagnostic logs on Azure Firewall.
B.A Log Analytics workspace.
C.Assign an Azure Policy to enforce diagnostic logs on all firewalls.
D.Install the Log Analytics agent on the Azure Firewall.
E.The Azure Firewall data connector in Sentinel.
AnswersA, B, E

Azure Firewall does not emit its logs to Sentinel by default. Instead, you must enable diagnostic settings on the firewall resource itself, selecting the relevant log categories (e.g., AzureFirewallNetworkRule, AzureFirewallApplicationRule, AzureFirewallDnsProxy) and streaming them to a Log Analytics workspace. This is the foundational ingestion step that makes firewall data available to Sentinel; without it, no traffic analysis or detection can occur.

Why this answer

Azure Firewall logs must be enabled via diagnostic settings to send data to a Log Analytics workspace. Without diagnostic logs, the firewall does not produce the necessary log data for Sentinel to ingest. This is the foundational step for log collection.

Exam trap

The trap here is that candidates often assume the Log Analytics agent is required for all Azure resources, but Azure Firewall (and other PaaS services) use diagnostic settings instead, making Option D a common distractor.

104
MCQeasy

A company uses Microsoft Sentinel to centralize security logs. They need to ensure that incidents from Microsoft Defender XDR are synchronized into Sentinel. Which data connector should they enable?

A.Office 365 connector
B.Windows Security Events connector
C.Microsoft Defender XDR connector
D.Azure Activity connector
AnswerC

The Microsoft Defender XDR connector is the correct data connector to centralize security incidents in Microsoft Sentinel. It connects to the Microsoft Graph Security API and imports incidents and alerts from all Defender XDR workloads—Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps—into Sentinel. This connector keeps incident status, severity, and classification synchronized bidirectionally, so you can manage the full incident lifecycle from Sentinel. Without this connector, Defender XDR incidents would not appear in Sentinel at all, making it the only option that directly satisfies the requirement.

Why this answer

The Microsoft Defender XDR connector (option C) is the correct choice because it is the built-in Microsoft Sentinel data connector designed to ingest and synchronize incidents and alerts from Microsoft Defender XDR into Sentinel, enabling unified incident management across Defender products. The Office 365 connector (option A) only ingests Office 365 audit and activity logs, not Defender XDR incidents. The Windows Security Events connector (option B) collects Windows event logs from agents, and the Azure Activity connector (option D) ingests Azure subscription control-plane activity, neither of which synchronizes Defender XDR incidents.

105
MCQmedium

You are configuring Microsoft Defender for Cloud's continuous export feature. You need to export security alerts and recommendations to a Log Analytics workspace for long-term retention and custom analysis. The export should include only high-severity alerts and recommendations. What should you do?

A.Set up Microsoft Sentinel to ingest Defender for Cloud alerts and then export to the workspace.
B.Enable continuous export in Defender for Cloud and select high-severity alerts and recommendations.
C.Configure diagnostic settings on each Azure resource to send logs to the workspace.
D.Use Azure Event Hubs to stream security alerts to the workspace.
AnswerB

Enabling continuous export in Defender for Cloud is the native, centralized method to stream security data to a Log Analytics workspace. You can filter to high-severity alerts and recommendations at the subscription or management-group level, ensuring only actionable events are stored. This is the intended configuration for satisfying the requirement directly.

Why this answer

Microsoft Defender for Cloud's continuous export feature allows you to directly export security alerts and recommendations to a Log Analytics workspace with granular filtering by severity. This meets the requirement for long-term retention and custom analysis without additional services. Selecting 'high-severity' in the export configuration ensures only the specified alerts and recommendations are exported.

Exam trap

The trap here is that candidates often confuse the continuous export feature with diagnostic settings or assume that a SIEM like Sentinel is required for custom analysis, when in fact Defender for Cloud's built-in export can directly filter and send data to a Log Analytics workspace.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM solution that ingests alerts from Defender for Cloud, but it adds unnecessary complexity and cost; the continuous export feature in Defender for Cloud can directly export to a Log Analytics workspace without Sentinel. Option C is wrong because diagnostic settings on individual Azure resources export resource-level logs (e.g., activity logs, metrics), not Defender for Cloud's security alerts and recommendations, which are generated at the subscription or workspace level. Option D is wrong because Azure Event Hubs is used for real-time streaming to external systems, not for direct export to a Log Analytics workspace; continuous export already supports direct workspace export without Event Hubs.

106
MCQeasy

You need to ensure that all Azure subscriptions in your tenant are automatically assessed for security misconfigurations and compliance against Microsoft cloud security benchmark. What should you configure?

A.Deploy Microsoft Sentinel with automatic data connectors
B.Assign an initiative via Azure Policy to all subscriptions
C.Enable continuous export in Microsoft Defender for Cloud
D.Create a blueprint definition and assign it to management group
AnswerB

Assigning the built-in Microsoft cloud security benchmark initiative through Azure Policy to all subscriptions is the correct and native way to ensure ongoing assessment. This initiative bundles dozens of policy definitions that audit and enforce security controls, such as encryption, network security, and identity management, and Azure Policy continuously evaluates resources against these rules without additional deployment. Assigning the initiative at the subscription scope triggers immediate compliance assessment and produces a compliance report that can be monitored in Defender for Cloud.

Why this answer

The Microsoft cloud security benchmark is a built-in initiative in Azure Policy. By assigning this initiative to all subscriptions, you automatically assess them for security misconfigurations and compliance. Defender for Cloud uses these policies, but ensuring the assessment requires the initiative assignment.

Option C is incorrect because enabling continuous export only streams completed assessment data; it does not trigger the assessment itself.

Exam trap

The trap is confusing Azure Policy initiatives (which enforce compliance) with Defender for Cloud's continuous export (which streams assessment data). The benchmark assessment is triggered by assigning the built-in Azure Policy initiative, not by continuous export.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response, not a tool for automated compliance assessment against the Microsoft cloud security benchmark; it can ingest data from Defender for Cloud but does not itself perform the benchmark assessment. Option B is wrong because assigning an initiative via Azure Policy enforces compliance rules and remediates resources, but it does not automatically assess subscriptions for security misconfigurations against the Microsoft cloud security benchmark; the benchmark assessment is a feature of Defender for Cloud, not Azure Policy. Option D is wrong because Azure Blueprints are used to define a repeatable set of Azure resources and policies for environment deployment, not for ongoing automated security assessment; they are deprecated in favor of deployment stacks and do not provide continuous compliance monitoring against the benchmark.

107
MCQeasy

Your organization wants to use Microsoft Sentinel to automatically respond to high-severity incidents. Which feature should you configure?

A.Create an analytics rule with a high severity.
B.Create an automation rule that triggers a playbook on incident creation.
C.Create a workbook to visualize incidents.
D.Enable entity behavior analytics.
AnswerB

Automation rules are the native orchestration component in Microsoft Sentinel for centrally managing incident responses. You can configure a trigger such as 'When incident is created' and conditionally invoke an Azure Logic Apps-based playbook to perform actions like opening a ticket, notifying analysts, or applying remediation. This directly achieves automated response because it links incident creation to an executable workflow without manual intervention.

Why this answer

Microsoft Sentinel automation rules allow you to define automated responses to incidents, such as triggering a playbook (a collection of actions based on Azure Logic Apps) when an incident is created. This directly meets the requirement to automatically respond to high-severity incidents without manual intervention.

Exam trap

The trap here is that candidates often confuse analytics rules (which generate incidents) with automation rules (which respond to incidents), leading them to select Option A thinking severity configuration alone enables automated response.

How to eliminate wrong answers

Option A is wrong because creating an analytics rule with a high severity only generates incidents based on detection logic; it does not configure any automated response. Option C is wrong because a workbook is used for visualizing and analyzing data, not for automating responses to incidents. Option D is wrong because entity behavior analytics provides behavioral insights and anomaly detection but does not trigger automated actions like playbooks.

108
MCQeasy

Your company wants to use Microsoft Defender for Cloud's just-in-time (JIT) VM access to reduce the attack surface. You have enabled JIT for a set of VMs. A security administrator reports that they cannot connect via RDP even after requesting access. What is the most likely cause?

A.The JIT policy is set at the subscription level and does not apply to individual VMs.
B.The administrator's source IP address is not in the allowed list for the JIT policy.
C.The VM is not located in a region that supports JIT.
D.The VM does not have the Azure VM agent installed.
AnswerB

The administrator's current source IP address must be included in the allowed source IP/CIDR list when a JIT access request is made. JIT creates an NSG rule that only permits traffic from the specified IP ranges, so if the admin's external IP is not among them, Defender for Cloud will reject the request or no temporary rule is created. The request also must satisfy RBAC permissions, but the source IP match is a separate, mandatory condition for the connection to be opened.

Why this answer

The most likely cause is that the administrator's source IP address is not included in the allowed list for the JIT policy. When a user requests JIT access, Defender for Cloud opens the specified ports (e.g., 3389 for RDP) only to the source IP addresses that are explicitly permitted in the policy. If the administrator's IP is not in the allowed list, the request may be approved but the network security group (NSG) or Azure Firewall rule will not include that IP, resulting in a connection failure.

Exam trap

The trap here is that candidates often assume JIT access automatically allows any authenticated user to connect, but in reality the source IP must be explicitly permitted in the policy, and a common mistake is to overlook the IP restriction when troubleshooting connectivity.

How to eliminate wrong answers

Option A is wrong because JIT policies can be applied at the subscription, resource group, or individual VM level; enabling JIT for a set of VMs means the policy is applied directly to those VMs, not just at the subscription level. Option C is wrong because JIT VM access is supported in all Azure regions where Defender for Cloud is available; there is no regional restriction that would block access. Option D is wrong because while the Azure VM agent is required for some Defender for Cloud features (like vulnerability assessment), JIT access does not depend on the VM agent; it works by modifying NSG or Azure Firewall rules at the platform level.

109
MCQeasy

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to create a custom analytic rule that triggers an incident when a user signs in from an unfamiliar location. Which data source should you use?

A.Azure Activity Logs
B.Microsoft Entra ID Sign-in Logs
C.Azure AD Audit Logs
D.Microsoft 365 Defender Alerts
AnswerB

Microsoft Entra ID Sign-in Logs record every authentication attempt for interactive and non-interactive sign-ins, including the client IP, approximate geolocation, browser/device, and conditional access results. These logs are designed for identity security scenarios, and when streamed to Microsoft Sentinel they enable analytics rules for unfamiliar sign-in detection. The location data is essential, making these logs the correct answer. This is why Sign-in Logs are the appropriate data source.

Why this answer

Microsoft Entra ID Sign-in Logs contain detailed information about user sign-in events, including location data. A custom analytic rule in Microsoft Sentinel can use these logs to detect sign-ins from unfamiliar locations by comparing the location against a user's typical sign-in pattern, which is a common UEBA (User and Entity Behavior Analytics) scenario.

Exam trap

The trap here is that candidates often confuse Azure AD Audit Logs (which track configuration changes) with Sign-in Logs (which track authentication events), leading them to select the audit logs for a sign-in behavior detection rule.

How to eliminate wrong answers

Option A is wrong because Azure Activity Logs track control-plane operations on Azure resources (e.g., creating a VM), not user sign-in events or location data. Option C is wrong because Azure AD Audit Logs record administrative changes in Entra ID (e.g., role assignments, group modifications), not user sign-in attempts or location details. Option D is wrong because Microsoft 365 Defender Alerts are pre-built security alerts from Microsoft 365 Defender, not raw sign-in logs; they do not provide the granular location data needed to define a custom unfamiliar location rule.

110
Multi-Selectmedium

Which TWO of the following are valid methods to ingest data into Microsoft Sentinel? (Select two.)

Select 2 answers
A.Using the Log Analytics agent to send custom logs.
B.Using the Azure PowerShell cmdlets to send events directly.
C.Using Power BI to stream data.
D.Using Azure Policy to forward logs.
E.Using a data connector from the content hub.
AnswersA, E

Custom logs are a legitimate ingestion path in Microsoft Sentinel because the Log Analytics agent can be configured to monitor specific local text files and send their contents to an Azure Log Analytics workspace. Since Sentinel is built on a Log Analytics workspace, data collected by this agent is automatically available for security analytics. This method is useful for legacy on-premises or IaaS workloads where installing an agent is feasible, and it is a first-class ingestion method for custom log sources.

Why this answer

Option A is correct because the Log Analytics agent (MMA/AMA) can be installed on machines to collect custom logs and Windows/Linux events and forward them to the Log Analytics workspace that backs Microsoft Sentinel, including custom log ingestion via the Log Analytics Data Collector API or custom tables. Option E is correct because Microsoft Sentinel ingests data through data connectors, many of which are available from the Content Hub (e.g., Microsoft 365 Defender, Azure Activity, AWS, syslog via AMA), and these connectors are the primary supported ingestion method. Option B is not a valid ingestion method because Azure PowerShell cmdlets manage resources and configuration but do not stream event data directly into Sentinel; ingestion occurs via agents, connectors, or the Data Collector API.

Option C is not valid because Power BI is a visualization and reporting tool, not a data streaming or ingestion pipeline into Sentinel. Option D is not valid because Azure Policy enforces governance and compliance on resources; it does not forward logs to Microsoft Sentinel, though diagnostic settings or connectors are used for that purpose.

Exam trap

The trap here is that candidates often confuse Azure Policy (which enforces rules) with diagnostic settings or data connectors (which actually forward logs), leading them to select Option D incorrectly.

111
MCQhard

Your organization uses Microsoft Sentinel to detect threats across multiple Azure subscriptions. Security analysts need to query threat intelligence data from Microsoft Defender Threat Intelligence (MDTI) directly within Sentinel. However, analysts report that MDTI indicators are not appearing in ThreatIntelligenceIndicator table. What is the most likely cause?

A.The MDTI data connector is not enabled in Microsoft Sentinel.
B.The Sentinel workspace is located in a region where MDTI is not supported.
C.The subscriptions are not onboarded to Microsoft Defender for Cloud.
D.The Sentinel workspace is not using Azure Lighthouse for cross-subscription management.
AnswerA

The Microsoft Defender Threat Intelligence (MDTI) data connector is the explicit integration point that imports threat indicators — malicious domains, IP addresses, and other observables — into the Log Analytics workspace's ThreatIntelligenceIndicator table. Without this connector enabled in the Sentinel Content hub and properly authenticated via Microsoft Graph, no MDTI indicators will be ingested, so any analytics rules that depend on those indicators will produce no alerts. This directly explains the absence of MDTI-derived detections regardless of the workspace region, subscription posture, or management architecture.

Why this answer

The most likely cause is that the MDTI data connector is not enabled in Microsoft Sentinel. Without enabling this connector, threat intelligence indicators from Microsoft Defender Threat Intelligence will not be ingested into the ThreatIntelligenceIndicator table, regardless of other configurations. The connector must be explicitly installed and configured to pull MDTI data into the workspace.

Exam trap

The trap here is that candidates may assume cross-subscription or cross-tenant configurations (like Azure Lighthouse or Defender for Cloud onboarding) are required for data ingestion, when in fact the missing connector is the direct and most likely cause.

How to eliminate wrong answers

Option B is wrong because MDTI is a global cloud service and is supported in all Azure regions where Microsoft Sentinel is available; regional unavailability is not a known limitation. Option C is wrong because onboarding subscriptions to Microsoft Defender for Cloud is not a prerequisite for ingesting MDTI indicators into Sentinel; MDTI data flows through its own connector independent of Defender for Cloud. Option D is wrong because Azure Lighthouse is used for managing multiple tenants, not for cross-subscription data ingestion within a single tenant; Sentinel can query multiple subscriptions without Lighthouse.

112
MCQhard

Your organization uses Microsoft Defender for Cloud to protect Azure SQL databases. You receive a recommendation that 'SQL databases should have vulnerability findings resolved'. You run a vulnerability assessment scan and find a high-severity finding about a missing firewall rule. How should you resolve this finding?

A.Change the SQL database auditing settings to capture all events.
B.Add a firewall rule to the SQL server allowing traffic from the required IP addresses.
C.Enable Advanced Threat Protection for Azure SQL Database.
D.Enable the 'Defender for SQL' plan on the server.
AnswerB

Add a server-level firewall rule to the Azure SQL Server with the exact start and end IP addresses or CIDR range used by the application clients. By default Azure SQL blocks all external traffic; creating this rule explicitly permits those source IPs to connect while still denying all other ranges. This action directly addresses the Defender for Cloud finding that flagged missing firewall configuration.

Why this answer

The vulnerability assessment finding about a missing firewall rule indicates that the SQL server is accessible from an overly broad range of IP addresses or lacks a necessary restriction. Adding a firewall rule to the SQL server that allows traffic only from the required IP addresses directly resolves the misconfiguration, reducing the attack surface. This aligns with the recommendation to remediate vulnerability findings by applying network access controls.

Exam trap

The trap here is that candidates often confuse vulnerability assessment findings with threat detection or auditing features, mistakenly thinking that enabling security monitoring (like ATP or Defender for SQL) will automatically fix configuration issues, when in fact the finding requires a direct network configuration change.

How to eliminate wrong answers

Option A is wrong because changing SQL database auditing settings to capture all events does not address the missing firewall rule; auditing only logs activities, it does not restrict network access. Option C is wrong because enabling Advanced Threat Protection (ATP) for Azure SQL Database provides threat detection and alerting, but it does not remediate a missing firewall rule or change network access controls. Option D is wrong because enabling the 'Defender for SQL' plan on the server activates additional security features like vulnerability assessment and threat detection, but it does not automatically add or modify firewall rules to resolve the specific finding.

113
MCQeasy

Your company uses Microsoft Defender for Cloud's regulatory compliance dashboard to track compliance with the PCI DSS standard. You have enabled the PCI DSS initiative on the management group. The dashboard shows that some controls are 'Not started' even though you have implemented the required security configurations. You suspect that the assessment might not be running correctly. You need to ensure that the compliance assessments are triggered for all resources. The environment consists of: - 3 subscriptions under a management group. - All subscriptions have Defender for Cloud enabled with the CSPM plan. - The PCI DSS initiative was assigned at the management group level. - Some resources are in regions that do not support certain policy effects. What is the most likely reason for the 'Not started' status?

A.The compliance dashboard only displays results if you manually run an assessment.
B.The PCI DSS initiative must be assigned to each subscription individually.
C.The Defender Cloud Security Posture Management (CSPM) plan is not enabled on all subscriptions.
D.Some policies in the PCI DSS initiative use effects that are not supported in certain regions, causing the assessment to not run.
AnswerD

Regulatory compliance initiatives like PCI DSS contain a mix of policy effects, including AuditIfNotExists and DeployIfNotExists, some of which depend on resource providers or resource types that may not be available in every Azure region. When a policy's effect cannot run in a given region—either because the needed resource type is unavailable or the effect is unsupported for that region's policy evaluation—the policy engine skips the evaluation, leaving the resource's compliance status as 'Not started' rather than 'Compliant' or 'Non-Compliant'. This regional limitation directly explains the dashboard showing 'Not started' while the initiative is correctly assigned and the CSPM plan is enabled.

Why this answer

The correct answer is D: some policies in the PCI DSS initiative use effects that are not supported in certain regions, causing the assessment to not run. Azure Policy effects such as AuditIfNotExists or DeployIfNotExists depend on regional support and resource provider capabilities; if an effect is unsupported in a resource's region, the policy assignment cannot evaluate that resource, so the control remains 'Not started' rather than showing a compliant or non-compliant result. This matches the scenario's hint that some resources are in regions that do not support certain policy effects.

Option A is wrong because Defender for Cloud continuously evaluates assigned initiatives and does not require manual assessment runs. Option B is wrong because an initiative assigned at the management group level is inherited by all subscriptions in that group. Option C is wrong because the scenario states Defender for Cloud with the CSPM plan is already enabled on all subscriptions.

Exam trap

A common trap is assuming that enabling the CSPM plan is enough, or that management group assignments always work without issue. The real pitfall is regional support for policy effects.

114
MCQeasy

Your organization uses Microsoft Defender for Cloud to protect Azure resources. You need to ensure that storage accounts are only accessible via HTTPS. What should you configure?

A.Configure a storage account firewall to block HTTP
B.Use a private endpoint for the storage account
C.Enable 'Secure transfer required' in the storage account's configuration
D.Create an Azure Policy to audit storage accounts that do not require secure transfer
AnswerC

Enabling 'Secure transfer required' (the supportsHttpsTrafficOnly property) makes Azure Storage reject any request sent over HTTP, including requests via the REST API, Azure SDKs, and file shares, and returns an error requiring the client to use HTTPS. It forces all data-plane traffic to be encrypted in transit and can be combined with a minimum TLS version for further control. This is the account-level control that directly implements the requirement to disallow insecure HTTP.

Why this answer

Enabling 'Secure transfer required' on a storage account enforces HTTPS for all requests to the storage account, rejecting any HTTP traffic. This setting ensures that data in transit is encrypted using TLS, which aligns with the requirement to only allow HTTPS access.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall, private endpoint) with protocol-level enforcement, mistakenly thinking they can block HTTP when they only restrict network access or provide private connectivity.

How to eliminate wrong answers

Option A is wrong because a storage account firewall controls network access based on IP addresses or virtual networks, not the protocol (HTTP vs. HTTPS); it cannot block HTTP traffic specifically. Option B is wrong because a private endpoint provides a private IP address for the storage account within a virtual network, but it does not enforce HTTPS; it still allows HTTP traffic unless combined with other settings.

Option D is wrong because an Azure Policy can audit or enforce compliance, but it does not directly configure the storage account to require HTTPS; it only reports or remediates non-compliant resources, not block HTTP access at the storage account level.

115
MCQhard

Refer to the exhibit. You are reviewing a policy assignment in Microsoft Defender for Cloud that deploys the Log Analytics agent to Azure VMs. The policy uses 'DeployIfNotExists' effect and specifies a workspace. However, newly created VMs are not showing the agent installed. What is the most likely cause?

A.The workspace ID is incorrect.
B.The policy assignment does not have a managed identity assigned.
C.The policy effect is set to 'Disabled'.
D.The Log Analytics workspace is in a different region than the VMs.
AnswerB

DeployIfNotExists policies require a managed identity to execute the deployment template that installs the Log Analytics agent. Without a system-assigned or user-assigned managed identity on the policy assignment, Azure Policy cannot perform any remediation actions, so the agent is never deployed. The exhibit likely omits this identity, making it the most probable reason no installation occurs.

Why this answer

The 'DeployIfNotExists' effect in Azure Policy requires a managed identity to perform remediation tasks, such as installing the Log Analytics agent. Without a managed identity assigned to the policy assignment, the policy can evaluate compliance but cannot execute the deployment action. This is the most likely cause because the policy is correctly configured but lacks the necessary identity to write resources (agent installation) to the VM.

Exam trap

The trap here is that candidates often assume a policy with 'DeployIfNotExists' automatically has permissions to deploy resources, but Azure Policy requires an explicit managed identity assignment for remediation actions, which is a common oversight in exam scenarios.

How to eliminate wrong answers

Option A is wrong because an incorrect workspace ID would cause the agent to install but connect to the wrong workspace, not fail to install entirely; the policy deployment action would still run. Option C is wrong because if the policy effect were set to 'Disabled', the policy would not evaluate at all, and the question states the policy is assigned and evaluating (new VMs are not showing the agent, implying evaluation occurs but deployment fails). Option D is wrong because the Log Analytics agent can connect to workspaces in any region; region mismatch does not prevent agent installation, only may cause data latency or cross-region charges.

116
MCQhard

Your organization runs a critical application on an Azure VM that generates sensitive data. You need to ensure that only approved applications can execute on the VM to prevent malware. You have Microsoft Defender for Cloud enabled with the Defender for Servers plan P2. Which feature provides application control without requiring custom rules?

A.Configure AppLocker via Group Policy.
B.Enable Just-in-time VM access on the VM.
C.Enable Windows Defender Application Control (WDAC) on the VM.
D.Enable Adaptive application controls in Defender for Cloud.
AnswerD

Adaptive application controls in Microsoft Defender for Cloud are the correct solution because they automatically build an allowlist of known-good processes using machine learning and behavioral analysis. Defender for Cloud monitors running processes across the VM, generates a baseline, and applies an application control policy that permits only trusted applications while blocking untrusted executables. It also provides security recommendations and alerts when deviations occur, all managed from the Defender for Cloud portal without the need to manually construct rule sets, making it the only option that meets the requirement for an automatic, centrally managed application control.

Why this answer

Adaptive application controls in Microsoft Defender for Cloud (option D) is the correct choice because, with the Defender for Servers P2 plan, it uses machine learning to automatically analyze VM behavior and create a baseline of approved applications, generating allowlist recommendations without requiring you to author custom rules. It then enforces these allowlists to block untrusted executables, directly meeting the requirement to prevent malware execution. AppLocker via Group Policy (A) also provides application control but requires manually defining and maintaining rules, so it does not fit the 'no custom rules' requirement.

Just-in-time VM access (B) only restricts inbound network access to management ports and does not control which applications can execute. WDAC (C) is a valid application control mechanism, but it likewise requires you to create and manage policies rather than automatically generating them from Defender for Cloud's adaptive recommendations.

117
MCQmedium

You manage a Microsoft Sentinel workspace. Your security operations team wants to automatically notify the on-call analyst via Microsoft Teams whenever a new high-severity incident is created, and also create a corresponding ticket in ServiceNow. The team does not want to write code. Which Microsoft Sentinel feature should you use to accomplish this?

A.Workbooks
B.Automation rules
C.Watchlists
D.Analytics rules
AnswerB

Automation rules in Microsoft Sentinel allow you to define trigger conditions (such as incident creation with high severity) and then execute actions like running a playbook. Playbooks can post to Microsoft Teams and create ServiceNow tickets without custom code. This directly meets the requirement of no-code automation for incident response.

Why this answer

Automation rules in Microsoft Sentinel provide a no-code way to trigger playbooks based on incident creation, severity, or other conditions. By creating an automation rule that runs when a high-severity incident is created, you can launch a playbook that posts to Microsoft Teams and creates a ServiceNow ticket. This satisfies the requirement without writing code.

Exam trap

The trap here is confusing analytics rules with automation rules; analytics rules generate incidents, while automation rules respond to them.

118
Multi-Selectmedium

Your organization uses Microsoft Defender for Cloud to monitor Azure resources. You need to ensure that security recommendations are automatically remediated for non-compliant resources. Which TWO options can you use to achieve this?

Select 2 answers
A.Create a Logic Apps playbook that runs on a schedule.
B.Assign an Azure Policy with a DeployIfNotExists effect that deploys the required configuration.
C.Configure Microsoft Sentinel to automatically remediate based on alerts.
D.Enable 'Quick Fix!' for supported recommendations in Defender for Cloud.
E.Use Azure Automation runbooks to manually run remediation.
AnswersB, D

Assigning an Azure Policy definition with the DeployIfNotExists effect automatically deploys required settings whenever Azure Resource Manager evaluates a resource that lacks them, both on creation and on each compliance scan. After initial evaluation, the policy generates remediation tasks that actively bring existing non-compliant resources into compliance without manual intervention. This method is native, event-driven, and deeply integrated with Defender for Cloud's regulatory compliance and secure-score dashboards, making it the correct answer.

Why this answer

Option B is correct because an Azure Policy with a DeployIfNotExists effect automatically deploys the required configuration to non-compliant resources, which is the standard mechanism Defender for Cloud uses for automatic remediation at scale. Option D is correct because Defender for Cloud's 'Quick Fix!' feature provides one-click, automated remediation for supported recommendations, directly fixing non-compliant resources. Option A is incorrect because a scheduled Logic Apps playbook is not an automatic remediation trigger tied to non-compliance; playbooks in Defender for Cloud are triggered by alerts or recommendations, not schedules.

Option C is incorrect because Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response, not the service that remediates Defender for Cloud compliance recommendations. Option E is incorrect because manually running Azure Automation runbooks is not automatic remediation, which the scenario explicitly requires.

Exam trap

The trap here is that candidates often confuse manual remediation options (like runbooks or scheduled playbooks) with automatic remediation, or they incorrectly assume Sentinel is the primary tool for automatic remediation of Defender for Cloud recommendations, when in fact Azure Policy and Quick Fix! are the direct, built-in mechanisms.

119
MCQeasy

Your security team uses Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) to detect insider threats. To enable UEBA, which data source must be connected to Sentinel?

A.Microsoft Entra ID data connector
B.Azure Key Vault data connector
C.Office 365 data connector
D.Azure Activity log data connector
AnswerA

The Microsoft Entra ID data connector is the correct choice because it ingests sign-in logs, audit logs, and user properties that are the foundation of UEBA. UEBA in Microsoft Sentinel relies on identity data to build a behavior baseline for each user, detect anomalous sign-ins, and generate risk-based alerts. Without Entra ID (formerly Azure AD) identity telemetry, UEBA lacks the context needed to correlate user actions with security incidents.

Why this answer

Microsoft Sentinel's UEBA relies on Azure Active Directory (now Microsoft Entra ID) as the primary identity source to build behavioral baselines for users and entities. The Entra ID data connector ingests sign-in logs, audit logs, and risk detections, which are essential for UEBA to analyze patterns and detect anomalies indicative of insider threats. Without this identity telemetry, UEBA cannot establish the necessary behavioral profiles.

Exam trap

The trap here is that candidates often assume Office 365 or Azure Activity logs provide sufficient user context for UEBA, but Microsoft explicitly requires the Microsoft Entra ID data connector as the prerequisite identity source.

How to eliminate wrong answers

Option B is wrong because Azure Key Vault data connector only provides logs for key vault operations (e.g., key access, secret retrieval) and does not supply user identity or behavioral data required for UEBA. Option C is wrong because the Office 365 data connector provides mailbox and SharePoint activity logs, which are useful for threat detection but are not the foundational identity source that UEBA requires to enable its core analytics. Option D is wrong because the Azure Activity log data connector captures resource-level management events (e.g., VM creation, policy changes) and lacks the user authentication and risk signals that UEBA needs to profile user behavior.

← PreviousPage 2 of 2 · 119 questions total

Ready to test yourself?

Try a timed practice session using only Defender Cloud Sentinel questions.