Free AZ-500 Exam Braindumps (page: 55)

Page 54 of 128

You have an Azure subscription that contains several Azure SQL databases and an Azure Sentinel workspace.
You need to create a saved query in the workspace to find events reported by Azure Defender for SQL.
What should you do?

  1. From Azure CLI, run the Get-AzOperationalInsightsWorkspace cmdlet.
  2. From the Azure SQL Database query editor, create a Transact-SQL query.
  3. From the Azure Sentinel workspace, create a Kusto query language query.
  4. From Microsoft SQL Server Management Studio (SSMS), create a Transact-SQL query.

Answer(s): C



HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You plan to use Azure Sentinel to create an analytic rule that will detect suspicious threats and automate responses.
Which components are required for the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook



You are collecting events from Azure virtual machines to an Azure Log Analytics workspace.
You plan to create alerts based on the collected events.
You need to identify which Azure services can be used to create the alerts.
Which two services should you identify? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  1. Azure Monitor
  2. Azure Security Center
  3. Azure Analysis Services
  4. Azure Sentinel
  5. Azure Advisor

Answer(s): A,D



Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You use Microsoft Defender for Cloud for the centralized policy management of three Azure subscriptions.
You use several policy definitions to manage the security of the subscriptions.
You need to deploy the policy definitions as a group to all three subscriptions.
Solution: You create an initiative and an assignment that is scoped to a management group.
Does this meet the goal?

  1. Yes
  2. No

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/governance/policy/overview






Post your Comments and Discuss Microsoft AZ-500 exam with other Community members:

AZ-500 Exam Discussions & Posts