What is the default retentian period for Defender for Endpoint data? And what is the minimum retentian that can be set?
180 is the default, and 30 days is the minimum
A user needs to be able to view incidents and manage playbooks within Microsoft Sentinel. Which combination of roles should be assigned to fulfill this requirement?
Microsoft Sentinel Responder and Microsoft Sentinel Automation Contributor
Microsoft Sentinel Contributor and Microsoft Sentinel Responder
Microsoft Sentinel Reader and Logic App Contributor
C
Which role should be granted to a user to allow them to configure Microsoft Sentinel to run playbooks without granting them permissions to view or manage incidents?
Microsoft Sentinel Contributor
Microsoft Sentinel Responder
Logic App Contributor
C
Your organization wants to configure long-term data retention for Microsoft Sentinel logs beyond the default 30-day retention period. How can you achieve this?
Extend the table’s total retention period up to 12 years.
Configure Basic Logs for extended retention.
Use Auxiliary Logs for extended retention up to two years.
A
Which permission level is required to enable Microsoft Sentinel on a workspace?
Owner permissions on the Log Analytics workspace
Contributor permissions on the subscription
Reader permissions on the resource group
A
In Threat Intelligence, indicators are considered as which of the following?
Strategic
Operational
Tactical
C
What is a Azure subscription?
billing container/ boundary for resources
What is a scope?
A scope defines where a role assignment applies, ex: you would assign a user a “reader” role on a single resource group so they only see things there, and not for the whole subscriptionx
How many workspaces can be connected to the Defender portal?
1
If you want to connect to a different workspace that has Microsoft Sentinel enabled, disconnect the current workspace and connect the other workspace.
Which portal supports the functionality of adding entities to threat intelligence from incidents in Microsoft Sentinel?
Both Azure and Defender portals
Azure portal
Defender portal
B
What happens when a workspace is disconnected from the Defender portal in Microsoft Sentinel?
The Microsoft Sentinel section is removed from the left-hand side navigation of the Defender portal
The workspace is deleted from Microsoft Sentinel
Data from Microsoft Sentinel is still included on the Overview page
A
Which table (data type) would you query for the Microsoft Entra data?
OfficeActivity
SigninLogs
SecurityAlert
B
Which table (data type) would you query for the Microsoft 365 data?
OfficeActivity
SecurityAlert
SigninLogs
A
Which table (data type) would you query for the Microsoft Entra ID Protection data?
OfficeActivity
SigninLogs
SecurityAlert
C
Which connector do you use to collect Windows security events?
Windows Security Events via AMA
Common Event Format
Syslog
A
To collect Sysmon events with the Security Events connector, what is the log name used to collect it in advanced settings?
Microsoft-Windows-Sysmon/Operational
Microsoft-Windows-Sysmon/Events
Microsoft-Windows-Sysmon/Logs
A
Which table contains the ingested Sysmon events?
A
The CEF connector can be deployed on which platform?
Azure Windows Virtual Machine
On-premises Windows Host
Azure Linux Virtual Machine
C
The CEF connector deploys what type of forwarder?
Syslog
Event
Sysmon
A
The CEF connector writes to which table?
CommonSecurityLog
SecurityEvent
Syslog
Log Analytics supports collecting messages sent by what daemons?
rsyslog or syslog-ng
What port does local Syslog deamon forward to? Sending from local host to Azure Monitor Agent for Linux then to Log Analytics workspace.
TCP port 25224 then over HTTP to Log Analytics workspace
To create a parser in the Log query window, save the query as which of the following?
Module
Function
Table
B
MDTI
Microsoft Defender Threat Intelligence