MS-500 Exam Question 81
Refer to exhibit.

Microsoft Defender for Endpoint contains the incidents shown in the following table.

For each of the following statements, select yes if the statement is true. Otherwise. select No.


Microsoft Defender for Endpoint contains the incidents shown in the following table.

For each of the following statements, select yes if the statement is true. Otherwise. select No.

MS-500 Exam Question 82
You create an Azure Sentinel workspace.
You configure Azure Sentinel to ingest data from Azure Active Directory (Azure AD).
In the Azure Active Directory admin center, you discover Azure AD Identity Protection alerts. The Azure Sentinel workspace shows the status as shown in the following exhibit.

In Azure Log Analytics, you can see Azure AD data in the Azure Sentinel workspace.
What should you configure in Azure Sentinel to ensure that incidents are created for detected threats?
You configure Azure Sentinel to ingest data from Azure Active Directory (Azure AD).
In the Azure Active Directory admin center, you discover Azure AD Identity Protection alerts. The Azure Sentinel workspace shows the status as shown in the following exhibit.

In Azure Log Analytics, you can see Azure AD data in the Azure Sentinel workspace.
What should you configure in Azure Sentinel to ensure that incidents are created for detected threats?
MS-500 Exam Question 83
Which policies apply to which devices? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

NOTE: Each correct selection is worth one point.

MS-500 Exam Question 84
Your company has a main office and a Microsoft 365 subscription.
You need to enforce Microsoft Azure Multi-Factor Authentication (MFA) by using conditional access for all users who are NOT physically present in the office.
What should you include in the configuration?
You need to enforce Microsoft Azure Multi-Factor Authentication (MFA) by using conditional access for all users who are NOT physically present in the office.
What should you include in the configuration?
MS-500 Exam Question 85
You have a Microsoft Defender for Endpoint deployment that has custom network indicators turned on.
Microsoft Defender for Endpoint protects two computers that run Windows 10 as shown in the following table.

Microsoft Defender foe Endpoint has the device groups shown in the following table.


Microsoft Defender for Endpoint protects two computers that run Windows 10 as shown in the following table.

Microsoft Defender foe Endpoint has the device groups shown in the following table.








