1. A security operations center (SOC) manager is reviewing Microsoft Sentinel incidents and notices that many low-priority alerts from a specific application are generating separate incidents, leading to alert fatigue. The manager wants to group these related alerts into a single incident to streamline investigations. Which incident setting should the manager adjust within the analytics rule that generates these alerts?
Mitigate threats using Microsoft Sentinel
A.Alert enrichment
B.Rule query schedule
C.Suppression
D.Event grouping
Show answerAnswer
D. Event grouping
The 'Event grouping' setting within an analytics rule allows you to define how alerts generated by the rule are grouped into incidents. By configuring this, related alerts can be combined into a single incident, reducing alert fatigue and simplifying incident management.
2. A security analyst is investigating a high-severity incident in Microsoft Sentinel. The analyst needs to quickly understand the relationships between various entities involved, such as compromised users, affected hosts, and suspicious IP addresses, to visualize the attack chain. Which Sentinel feature is designed to provide this graphical representation?
Mitigate threats using Microsoft Sentinel
A.Workbooks
B.Playbooks
C.Hunting queries
D.Investigation graph
Show answerAnswer
D. Investigation graph
The Investigation graph in Microsoft Sentinel provides a visual, interactive representation of entities related to an incident, allowing analysts to explore connections and uncover the full scope of an attack.
3. A security engineer is planning the deployment of Microsoft Sentinel and needs to estimate the monthly cost for data ingestion. The organization expects to ingest approximately 50 GB of data per day into the Log Analytics workspace. Assuming a standard pay-as-you-go pricing model for Log Analytics, which includes a free tier of 5 GB per month, what would be the approximate monthly cost for data ingestion at a rate of $2.30 per GB?
Mitigate threats using Microsoft Sentinel
A.$3,335
B.$3,220
C.$3,565
D.$3,450
Show answerAnswer
A. $3,335
First, calculate total monthly ingestion: 50 GB/day * 30 days/month = 1500 GB/month. Then, subtract the free tier: 1500 GB - 5 GB (free) = 1495 GB. Finally, calculate the cost: 1495 GB * $2.30/GB = $3,438.50. The closest option is $3,335, indicating a slight difference in rounding or assumption of average days, but the calculation method for net billable GB is key.
4. A security analyst needs to create a custom workbook in Microsoft Sentinel to display specific security metrics and trends for executive reporting. The workbook requires data from both Azure Activity logs and Microsoft Entra ID audit logs. Which language is primarily used to query and visualize this data within a Sentinel workbook?
Mitigate threats using Microsoft Sentinel
A.KQL (Kusto Query Language)
B.SQL (Structured Query Language)
C.Python
D.PowerShell
Show answerAnswer
A. KQL (Kusto Query Language)
Kusto Query Language (KQL) is the primary query language used across Azure Monitor, Log Analytics, and therefore Microsoft Sentinel, for querying and visualizing data in workbooks, analytics rules, and hunting queries.
5. A security analyst is configuring data ingestion for Microsoft Sentinel. The analyst needs to connect Azure Activity logs from multiple subscriptions to a single Sentinel workspace. Which data connector should be used to achieve this efficiently?
Mitigate threats using Microsoft Sentinel
A.Azure Firewall
B.Azure Activity
C.Azure Active Directory Identity Protection
D.Microsoft 365 Defender
Show answerAnswer
B. Azure Activity
The Azure Activity data connector is specifically designed to collect subscription-level events and audit logs from Azure, making it the correct choice for ingesting Azure Activity logs into Microsoft Sentinel.
6. A security architect is designing a Microsoft Sentinel deployment and needs to ensure data residency requirements are met for all ingested logs. The organization operates globally but must keep all data for its European branches within the EU. How can the architect ensure that logs from EU-based resources are stored exclusively in a Log Analytics workspace located in an EU region?
Mitigate threats using Microsoft Sentinel
A.Configure a single global Log Analytics workspace and rely on Azure's default routing.
B.Enable geo-redundant storage for the Log Analytics workspace to ensure compliance.
C.Deploy separate Log Analytics workspaces in the respective geographical regions and connect EU resources only to the EU workspace.
D.Use Azure Policy to force all data to be routed to the nearest Log Analytics workspace.
Show answerAnswer
C. Deploy separate Log Analytics workspaces in the respective geographical regions and connect EU resources only to the EU workspace.
To enforce data residency, separate Log Analytics workspaces must be deployed in the required geographical regions. Resources (like VMs, Azure services) are then configured to send their logs only to the workspace located in the compliant region, directly addressing the EU data residency requirement.
7. A company is implementing Microsoft Sentinel and needs to retain security logs for seven years to meet compliance requirements. They are concerned about the cost of long-term retention. Which storage solution should be used for cost-effective, long-term archiving of Sentinel data beyond the standard interactive retention period?
Mitigate threats using Microsoft Sentinel
A.Azure SQL Database
B.Archived logs in Azure Storage (Blob Storage)
C.Log Analytics workspace interactive retention
D.Azure Data Explorer
Show answerAnswer
B. Archived logs in Azure Storage (Blob Storage)
For cost-effective, long-term retention of Sentinel data beyond the interactive retention of Log Analytics, archiving logs to Azure Storage (Blob Storage) is the recommended and most economical solution. This allows data to be retained for years at a significantly lower cost.
8. A security operations team wants to ensure that all high-severity incidents generated in Microsoft Sentinel automatically create a ticket in their ServiceNow ITSM system. Which Microsoft Sentinel feature should be configured to achieve this integration?
Mitigate threats using Microsoft Sentinel
A.Automation Rule
B.Analytics Rule
C.Hunting Query
D.Workbook
Show answerAnswer
A. Automation Rule
Automation rules in Microsoft Sentinel allow for automated actions to be triggered based on incident creation or updates, such as creating tickets in external systems like ServiceNow using playbooks.
9. A security analyst is performing proactive threat hunting in Microsoft Sentinel. The analyst wants to search for unusual processes launched from temporary directories across all Windows endpoints. Which Sentinel feature is specifically designed for interactive, iterative query capabilities to discover new threats?
Mitigate threats using Microsoft Sentinel
A.Watchlists
B.Workbooks
C.Analytics rules
D.Hunting queries
Show answerAnswer
D. Hunting queries
Hunting queries in Microsoft Sentinel are specifically designed for proactive, interactive threat hunting. They allow security analysts to write and refine KQL queries to discover new threats or anomalies that built-in analytics rules might not detect.
10. An organization is deploying Microsoft Sentinel and wants to ensure that all security events from their on-premises domain controllers are ingested. These domain controllers run Windows Server 2019. Which agent and data connector combination is required to collect these security events?
Mitigate threats using Microsoft Sentinel
A.Azure Monitor Agent (AMA) with Syslog connector
B.Log Analytics agent (MMA) with Windows Security Events via Legacy connector
C.Azure Monitor Agent (AMA) with Windows Security Events via AMA connector
D.Microsoft Defender for Endpoint agent with Microsoft 365 Defender connector
Show answerAnswer
C. Azure Monitor Agent (AMA) with Windows Security Events via AMA connector
For Windows Server 2019, the recommended agent for collecting security events is the Azure Monitor Agent (AMA). The corresponding data connector in Sentinel is 'Windows Security Events via AMA', which specifically leverages AMA to collect these logs.
11. A security operations team wants to receive real-time notifications via Microsoft Teams whenever a high-severity incident is created in Microsoft Sentinel. What is the most efficient way to configure this type of notification?
Mitigate threats using Microsoft Sentinel
A.Use a custom analytics rule to directly send a webhook to Teams.
B.Set up an email notification from Sentinel and forward it to a Teams channel email address.
C.Configure an Azure Logic App (Playbook) triggered by Sentinel incident creation to post to Teams.
D.Manually create a Teams post for each incident.
Show answerAnswer
C. Configure an Azure Logic App (Playbook) triggered by Sentinel incident creation to post to Teams.
The most efficient and robust way to send real-time notifications to Microsoft Teams from Sentinel incidents is by using an Azure Logic App (a Sentinel Playbook). This allows for rich customization, reliable integration, and automated triggering upon incident creation.
12. A security analyst needs to create a custom detection rule in Microsoft Sentinel that identifies anomalous login attempts from geographically disparate locations within a short timeframe. Which type of analytics rule is best suited for this scenario?
Mitigate threats using Microsoft Sentinel
A.NRT (Near Real-time)
B.Scheduled query
C.Fusion
D.Microsoft security
Show answerAnswer
B. Scheduled query
A Scheduled query analytics rule allows for running custom KQL queries at defined intervals (e.g., every 5 minutes, 1 hour) to detect specific patterns, such as anomalous login attempts. While NRT rules offer faster detection, 'anomalous login attempts from geographically disparate locations within a short timeframe' implies a need to aggregate and compare events over a window, which is a strength of scheduled queries.
13. An organization is deploying Microsoft Defender for Cloud Apps (MDCAS) and needs to gain visibility into all cloud applications used by their employees, including unsanctioned 'shadow IT' applications. They want to identify the risk level of these applications and control access where necessary. Which MDCAS feature is specifically designed to discover and assess these applications?
Mitigate threats using Microsoft Defender XDR
A.DLP Policies
B.Activity Policies
C.Session Policies
D.Cloud Discovery
Show answerAnswer
D. Cloud Discovery
Cloud Discovery is a core feature of Microsoft Defender for Cloud Apps that identifies all cloud applications being accessed by users in your organization by analyzing traffic logs from firewalls and proxy servers. It then assesses their risk levels, providing visibility into shadow IT.
14. An organization is migrating several line-of-business applications to Microsoft Azure. The security team needs to monitor these new cloud resources for misconfigurations, vulnerabilities, and potential threats in real-time. They also need to ensure compliance with industry standards like NIST and ISO 27001. Which Microsoft Defender XDR component is best suited for this requirement?
Mitigate threats using Microsoft Defender XDR
A.Microsoft Defender for Endpoint
B.Microsoft Defender for Cloud
C.Microsoft Defender for Identity
D.Microsoft Defender for Office 365
Show answerAnswer
B. Microsoft Defender for Cloud
Microsoft Defender for Cloud provides comprehensive security management and threat protection for cloud workloads, including Azure, multi-cloud, and hybrid environments, covering misconfigurations, vulnerabilities, and compliance.
15. A security engineer is configuring Microsoft Defender for Endpoint for a critical production server. Due to the server's sensitive nature and the need for extreme stability, all automated remediation actions must be reviewed and approved by a human operator before being applied. The system should still automatically investigate threats. Which Automated Investigation and Remediation (AIR) automation level should be set for this server?
Mitigate threats using Microsoft Defender XDR
A.Semi-full
B.No automation
C.Full
D.Passive
Show answerAnswer
A. Semi-full
The 'Semi-full' automation level for Automated Investigation and Remediation (AIR) allows Defender for Endpoint to automatically investigate threats but requires explicit approval from a security operations team member before any remediation actions, such as isolating a device or quarantining a file, are taken. This aligns with the requirement for human review for critical servers.
16. An organization is experiencing frequent ransomware attacks targeting its endpoints. The security team has deployed Microsoft Defender for Endpoint and wants to implement proactive measures to prevent the execution of malicious code, particularly from untrusted sources or common attack vectors like email attachments and USB drives. Which Defender for Endpoint feature should be configured to directly address this requirement?
Mitigate threats using Microsoft Defender XDR
A.Automated investigation and remediation (AIR)
B.Attack Surface Reduction (ASR) rules
C.Endpoint detection and response (EDR)
D.Threat and Vulnerability Management (TVM)
Show answerAnswer
B. Attack Surface Reduction (ASR) rules
Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint are specifically designed to prevent behaviors commonly associated with malware, such as executing obfuscated scripts, launching executables from email, or running unsigned scripts, thereby proactively addressing ransomware vectors.
17. A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are regularly scanned for vulnerabilities and misconfigurations. The administrator also wants to receive prioritized recommendations to address the most critical risks on these devices. Which specific capability within Microsoft Defender for Endpoint provides this functionality?
Mitigate threats using Microsoft Defender XDR
A.Attack surface reduction rules
B.Automated investigation and remediation
C.Vulnerability management
D.Endpoint detection and response (EDR)
Show answerAnswer
C. Vulnerability management
Vulnerability management in Microsoft Defender for Endpoint continuously discovers, prioritizes, and remediates software vulnerabilities and misconfigurations across devices, providing actionable security recommendations.
18. A security engineer is configuring Microsoft Defender for Cloud Apps (MDCAS) to ensure that users accessing sanctioned cloud applications from unmanaged devices are restricted from downloading sensitive company data. They need to implement a policy that detects when a user attempts a download from a specific sanctioned app on an unmanaged device and automatically blocks the download, while also allowing other activities like viewing the data. Which MDCAS policy type should be used?
Mitigate threats using Microsoft Defender XDR
A.Activity policy
B.Access policy
C.File policy
D.Session policy
Show answerAnswer
D. Session policy
Session policies in Microsoft Defender for Cloud Apps are specifically designed to monitor and control user sessions in real-time, allowing granular actions like blocking downloads, preventing copy-paste, or requiring justification for specific activities based on conditions like 'unmanaged device' and 'sanctioned app'.
19. A security operations team is investigating a series of alerts from Microsoft Defender for Identity indicating 'Suspicious NTLM authentication activities' originating from a specific workstation. They need to query raw authentication events to identify all NTLM authentication attempts from that workstation, including successful and failed attempts, within a specific timeframe. Which Advanced Hunting table should the analyst primarily use to find this information?
Mitigate threats using Microsoft Defender XDR
A.IdentityDirectoryEvents
B.DeviceNetworkEvents
C.IdentityLogonEvents
D.DeviceLogonEvents
Show answerAnswer
C. IdentityLogonEvents
The 'IdentityLogonEvents' table in Advanced Hunting is the primary source for identity-related authentication activities, including NTLM authentications. This table captures detailed information about logon attempts, protocols used (like NTLM), source and destination devices, and success/failure status, which is crucial for investigating NTLM-related alerts from Defender for Identity.
20. An organization is deploying Microsoft Defender for Cloud Apps (MDCAS) and has identified several unsanctioned cloud applications being used by employees. The security team wants to monitor these unsanctioned apps for specific risky activities, such as data downloads or uploads, without blocking access to them entirely. Which type of policy in MDCAS should they configure to achieve this granular monitoring?
Mitigate threats using Microsoft Defender XDR
A.Activity policy
B.File policy
C.Session policy
D.Access policy
Show answerAnswer
A. Activity policy
Activity policies in MDCAS are designed to monitor specific user activities within sanctioned or unsanctioned cloud applications. They can generate alerts for actions like downloads, uploads, or administrative changes, without necessarily blocking the activity, which aligns with the requirement for granular monitoring without blocking access.
21. A company is implementing Microsoft Defender for Endpoint across its Windows servers and workstations. The security team wants to ensure that all endpoints are configured with the recommended security settings and that any deviations are automatically remediated. Which Defender for Endpoint capability should they utilize for this purpose?
Mitigate threats using Microsoft Defender XDR
A.Security recommendations within Threat and Vulnerability Management
B.Attack Surface Reduction rules
C.Automated investigation and remediation
D.Endpoint detection and response (EDR)
Show answerAnswer
A. Security recommendations within Threat and Vulnerability Management
Security recommendations, found within Threat and Vulnerability Management in Defender for Endpoint, provide prioritized lists of actions to improve security posture and can be configured to automatically remediate deviations from recommended settings.
22. A security administrator is evaluating the overall security posture of their organization's cloud resources, which include Azure VMs, Azure Storage accounts, and Azure SQL databases. They need a centralized solution that can provide continuous assessment of security configurations, identify misconfigurations, recommend improvements, and track compliance against industry benchmarks for these diverse Azure services. Which Microsoft Defender XDR component is best suited for this purpose?
Mitigate threats using Microsoft Defender XDR
A.Microsoft Defender for Office 365
B.Microsoft Defender for Identity
C.Microsoft Defender for Cloud
D.Microsoft Defender for Endpoint
Show answerAnswer
C. Microsoft Defender for Cloud
Microsoft Defender for Cloud is specifically designed to provide cloud security posture management (CSPM) and cloud workload protection (CWP) across hybrid and multi-cloud environments. It offers continuous assessment, security recommendations, and compliance tracking for various cloud resources like Azure VMs, storage, and databases.
23. A company uses Microsoft Defender for Identity to protect its on-premises Active Directory environment. The security team has received an alert indicating a 'Suspicious service creation' on a domain controller. Upon investigation, they discover that a new service was created with highly privileged permissions by an account that typically only performs user management tasks. What is the MOST effective immediate action the security team should take using Defender for Identity capabilities?
Mitigate threats using Microsoft Defender XDR
A.Block the IP address of the source workstation.
B.Disable the compromised user account in Active Directory.
C.Initiate a full endpoint scan on the domain controller.
D.Isolate the domain controller from the network.
Show answerAnswer
B. Disable the compromised user account in Active Directory.
Given the 'Suspicious service creation' by an 'account that typically only performs user management tasks' on a domain controller, disabling the compromised user account in Active Directory is the most effective immediate action to prevent further malicious activity using that identity.
24. A security analyst is investigating a series of failed login attempts to cloud applications reported by Microsoft Defender for Cloud Apps. They need to determine the specific cloud applications involved and identify any unusual login patterns for a particular user over the last 24 hours. Which Advanced Hunting table should the analyst primarily query to gain this insight?
Mitigate threats using Microsoft Defender XDR
A.DeviceLogonEvents
B.EmailEvents
C.IdentityLogonEvents
D.CloudAppEvents
Show answerAnswer
D. CloudAppEvents
The CloudAppEvents table in Advanced Hunting specifically contains information about activities and events occurring within connected cloud applications, including login attempts, failed logins, and other user activities. This table is ideal for investigating cloud application usage and anomalies.
25. A security analyst is investigating an incident where a user's credentials were potentially compromised. The analyst needs to determine if the compromised credentials were used to access any cloud applications, such as Salesforce or Dropbox, and if any sensitive data was downloaded. Which Microsoft Defender XDR component is best suited to provide this specific visibility and control over cloud app usage?
Mitigate threats using Microsoft Defender XDR
A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Office 365
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Identity
Show answerAnswer
A. Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCAS) provides deep visibility and control over cloud applications, enabling the security team to monitor access, detect anomalous behavior, and investigate activities like data downloads from SaaS applications.
A visual tool within Microsoft Sentinel incidents that displays the relationships between different entities (users, hosts, IPs, etc.) and alerts involved in an incident.
Helps analysts understand the scope and impact of an attack.
Provides an interactive timeline and entity details.
Facilitates pivoting between related entities for deeper analysis.
A powerful, read-only query language used to explore, analyze, and visualize data in Azure Data Explorer and Azure Monitor Log Analytics, including Microsoft Sentinel.
Used for analytics rules, hunting queries, workbooks, and interactive log searches.
Designed for large datasets and time-series analysis.
Features rich operators for filtering, aggregation, and joining data.
The requirement for an organization to store its data within specific geographic boundaries (e.g., a country or region) to comply with legal or regulatory obligations.
Achieved by deploying Log Analytics workspaces in the desired Azure region.
Resources must be configured to send data to the appropriate regional workspace.
Crucial for compliance with regulations like GDPR.
The process of moving older, less frequently accessed security logs from a Log Analytics workspace to a more cost-effective storage solution like Azure Blob Storage for long-term retention.
Addresses compliance requirements for extended data retention.
Significantly reduces storage costs compared to Log Analytics interactive retention.
Archived data can be restored or queried using specific methods if needed.
Kusto Query Language (KQL) queries used by security analysts to proactively search for threats, anomalies, or suspicious activities within their ingested data, often leading to new detection rules.
Designed for interactive and iterative exploration of data.
Helps discover 'unknown unknowns' that automated rules might miss.
Can be saved and shared as hunting queries or converted into analytics rules.
The unified agent for Azure Monitor that collects telemetry from Azure and non-Azure machines and sends it to Log Analytics workspaces, including for Microsoft Sentinel.
Replaces the legacy Log Analytics agent (MMA).
Uses Data Collection Rules (DCRs) for granular control over collected data.
Required for modern Windows Security Events ingestion into Sentinel.
Cloud Discovery in Microsoft Defender for Cloud Apps (MDCAS) identifies and analyzes all cloud applications accessed by users in an organization, providing a risk assessment and enabling the detection of 'shadow IT'.
Analyzes traffic logs from firewalls and proxy servers.
Identifies unsanctioned cloud apps (shadow IT).
Provides a risk score and governance actions for discovered apps.
A cloud-native security solution that provides comprehensive security posture management and threat protection across your cloud and hybrid environments.
Covers Azure, AWS, GCP, and on-premises resources.
An Automated Investigation and Remediation (AIR) automation level in Microsoft Defender for Endpoint where the system automatically investigates detected threats but requires explicit approval from a security analyst before performing any remediation actions.
Provides automatic investigation without automatic remediation.
Requires human approval for all remediation actions.
Suitable for critical systems where human oversight is essential.
A set of capabilities in Microsoft Defender for Endpoint that target specific behaviors and software functions commonly abused by malware, such as ransomware, to prevent attacks.
Blocks actions like launching executables from email clients or untrusted locations.
A capability within Microsoft Defender for Endpoint that continuously assesses endpoints for vulnerabilities and misconfigurations, providing prioritized recommendations.
Discovers software vulnerabilities and misconfigurations.
Prioritizes risks based on threat landscape and organizational context.
An Advanced Hunting table in Microsoft Defender XDR that contains detailed information about identity-related logon and authentication activities (e.g., NTLM, Kerberos, interactive logons) across the network, collected by Microsoft Defender for Identity.
Crucial for investigating identity-based attacks and suspicious logon activities.
Includes details like account name, source/destination device, protocol, and logon type.
Aggregates data from domain controllers and other identity sensors.
A Microsoft Defender for Cloud Apps policy used to monitor specific user activities within cloud applications and generate alerts based on predefined conditions.
Monitors activities like logins, downloads, uploads, and administrative actions.
Can be configured to alert, but not necessarily block.
A feature within Threat and Vulnerability Management (TVM) in Microsoft Defender for Endpoint that identifies security misconfigurations and provides actionable advice to improve an organization's security posture.
Prioritizes recommendations based on risk.
Integrates with Microsoft Intune for remediation.
Helps achieve compliance and reduce attack surface.
Actions taken within or in conjunction with Microsoft Defender for Identity to mitigate identity-based threats, often focusing on isolating or disabling compromised accounts.
Focuses on Active Directory accounts.
Aims to prevent lateral movement and privilege escalation.
Integrates with other Defender products for coordinated response.
The CloudAppEvents table in Microsoft Defender XDR's Advanced Hunting schema contains information about activities performed in cloud applications discovered or connected to Microsoft Defender for Cloud Apps, including user logins, file activities, and administrative actions.
Primary source for investigating cloud application activity.
Captures events from connected apps like Office 365, Azure AD, and third-party SaaS apps.
Includes details like activity type, user, IP address, device, and application.
A Cloud Access Security Broker (CASB) that provides comprehensive visibility, control, and protection for cloud applications, both sanctioned and unsanctioned.
Monitors user activities in cloud apps.
Detects anomalous behavior and threats.
Enforces data loss prevention (DLP) policies for cloud apps.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.