exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 324 discussion

Actual exam question from Microsoft's MS-102
Question #: 324
Topic #: 1
[All MS-102 Questions]

HOTSPOT
-

You have an Azure subscription.

You have a Microsoft 365 E5 subscription.

You are licensed to use Microsoft Defender XDR.

You need to monitor activities from suspicious IP addresses and unusual administrative activities in Azure.

What should you use to monitor the activities, and what should you use to integrate Azure with Microsoft Defender XDR? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
0b29bdf
Highly Voted 6 months, 3 weeks ago
Monitor: Microsoft Defender for Identity: This is your go-to for monitoring suspicious activities and behaviors, including those linked to IP addresses and administrative actions. Integrate: A data connector: This allows integration of Azure activities with Microsoft Defender XDR, ensuring seamless data flow and monitoring capabilities.
upvoted 10 times
alsouqinet
5 months, 2 weeks ago
Microsoft Defender for Identity & A data connector
upvoted 6 times
...
...
justITtopics
Highly Voted 6 months ago
https://learn.microsoft.com/en-us/defender-cloud-apps/protect-azure Monitor: Microsoft Defender four Cloud Apps -> Activity from suspicious IP addresses Integrate: An app connector -> "This section provides instructions for connecting Microsoft Defender for Cloud Apps to your existing Azure account using the app connector API"
upvoted 5 times
...
Dr_Lawrence
Most Recent 6 months, 1 week ago
Activities from suspicious IP addresses: Data connector To guard against suspicious IP addresses, employ Microsoft Sentinel’s data connector in concert with threat intelligence tools. This integration, joined with Microsoft Defender XDR, ensures alerts flow seamlessly when suspicious IPs arise. Additionally, Sentinel’s Threat Intelligence and Indicators enrich understanding, revealing origins and identities of these addresses. Microsoft Sentinel Threat Intelligence and Indicators: https://learn.microsoft.com/en-us/azure/sentinel/understand-threat-intelligence#view-your-geolocation-and-whois-data-enrichments-public-preview Microsoft Defender XDR integration with Microsoft Sentinel: https://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-sentinel-integration?tabs=azure-portal * * * * * * * * * * * * Monitor unusual administrative activities in Azure: Microsoft Defender for Identity Microsoft Defender for Identity: https://learn.microsoft.com/en-us/defender-for-identity/what-is#identify-suspicious-activities-across-the-cyber-attack-kill-chain
upvoted 2 times
...
JohnDoe47
6 months, 1 week ago
Monitor: Microsoft Defender for Cloud Apps Integrate: An app connector https://learn.microsoft.com/en-us/defender-cloud-apps/protect-azure
upvoted 4 times
004b54b
1 month ago
https://learn.microsoft.com/en-us/defender-cloud-apps/protect-azure#control-azure-with-built-in-policies-and-policy-templates Built-in anomaly detection policy Activity from anonymous IP addresses Activity from infrequent country >>Activity from suspicious IP addresses<< Activity performed by terminated user (requires Microsoft Entra ID as IdP) Multiple failed login attempts >>Unusual administrative activities<< Unusual multiple storage deletion activities (preview) Multiple delete VM activities Unusual multiple VM creation activities (preview)
upvoted 1 times
...
...
Preeb
6 months, 3 weeks ago
Answers are Monitor: Microsoft Defender for Cloud Integrate: A data connector
upvoted 3 times
Ody
6 months, 1 week ago
Microsoft Defender for Cloud is different than Microsoft Defender for Cloud Apps.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago