MS-500 Exam Question 111

You have a Microsoft 365 E5 subscription and an Sentinel workspace named Sentinel1.
You need to launch the Guided investigation - Process Alerts notebooks= in Sentinel.
What should you create first?
  • MS-500 Exam Question 112

    You have a Microsoft 365 E5 subscription without a Microsoft Azure subscription.
    Some users are required to use an authenticator app to access Microsoft SharePoint Online.
    You need to view which users have used an authenticator app to access SharePoint Online. The solution must minimize costs.
    What should you do?
  • MS-500 Exam Question 113

    You haw a Microsoft 365 subscription that contains the users shown in the following table.

    You need to ensure that User1, User2 , and User3 can use self-service password reset (SSPR). The solution must not affect User 4.
    Solution: You enable SSPR for Group1.
    Does this meet the goal?
  • MS-500 Exam Question 114

    You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) connector and an Office 365 connector.
    From the workspace, you plan to create a scheduled query rule that will use a custom query. The rule will be used to generate alerts when inbound access to Office 365 from specific user accounts is detected.
    You need to ensure that when multiple alerts are generated by the rule, the alerts are consolidated as a single incident per user account.
    What should you do?
  • MS-500 Exam Question 115

    You have an Azure Active Directory (Azure AD) tenant named contoso.com and a Microsoft 365 subscription.
    Contoso.com contains the groups shown in the following table.

    You plan to create a supervision policy named Policy1.
    You need to identify which groups can be supervised by using Policy1.
    Which groups should you identify?