Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AZ-500 topic 4 question 46 discussion

Actual exam question from Microsoft's AZ-500
Question #: 46
Topic #: 4
[All AZ-500 Questions]

DRAG DROP -
You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) data connector.
You are threat hunting suspicious traffic from a specific IP address.
You need to annotate an intermediate event stored in the workspace and be able to reference the IP address when navigating through the investigation graph.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/bookmarks

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
teamaws
Highly Voted 2 years, 11 months ago
Answer is correct but the word choices are terrible
upvoted 15 times
...
Pinto
Highly Voted 3 years ago
Seems correct as per https://docs.microsoft.com/en-us/azure/sentinel/bookmarks#exploring-bookmarks-in-the-investigation-graph
upvoted 10 times
...
majstor86
Most Recent 1 year ago
CORRECT
upvoted 2 times
...
ligu
1 year ago
The answer is correct
upvoted 1 times
...
WhalerTom
2 years, 2 months ago
Correct. In exam Dec 21. 40 questions, 1 case study, no labs.
upvoted 3 times
...
kam117
2 years, 6 months ago
## Exam Question - 24 Sept 2021 ##
upvoted 2 times
...
rsharma007
2 years, 7 months ago
To reference an entity from the investigation graph you need entity associated with the alert mapped first. Run query and map the IP address entity.
upvoted 3 times
...
Sandomj55
2 years, 7 months ago
In Exam 8/4/2021
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...