SC-100 Exam Question 76

Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel. You plan to integrate Microsoft Sentinel with Splunk.
You need to recommend a solution to send security events from Microsoft Sentinel to Splunk. What should you include in the recommendation?
  • SC-100 Exam Question 77

    You have an Azure subscription that contains a resources group named RG1. RG1 contains multiple Azure Files shares.
    You need to recommend a solution to deploy a backup solution for the shares. The solution must meet the following requirements:
    * Prevent the deletion of backups and the vault used to store the backups.
    * Prevent privilege escalation attacks against the backup solution.
    * Prevent the modification of the backup retention period.
    Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    SC-100 Exam Question 78

    Your company has a Microsoft 365 subscription and uses Microsoft Defender for Identity.
    You are informed about incidents that relate to compromised identities.
    You need to recommend a solution to expose several accounts for attackers to exploit. When the attackers attempt to exploit the accounts, an alert must be triggered. Which Defender for Identity feature should you include in the recommendation?
  • SC-100 Exam Question 79

    You have a Microsoft Entra tenant that is linked to a Microsoft 365 subscription and an Azure subscription.
    The tenant contains service principals that are used to access applications in the Azure subscription.
    You need to recommend a solution to detect risky sign-ins and other risky activities performed by the service principals in the tenant. The solution must minimize costs.
    What should you include in the recommendation? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-100 Exam Question 80

    Your company wants to optimize ransomware incident investigations.
    You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and Response Team (DART) approach.
    Which three actions should you recommend performing in sequence in the plan? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.