You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
You deploy Azure Sentinel.
You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
In Microsoft Sentinel, playbooks are Azure Logic Apps that automate responses to alerts or incidents. To use an existing Logic App as a playbook in Sentinel, it must start with the ''Microsoft Sentinel alert'' trigger. This trigger allows Sentinel to call and pass alert details to the Logic App automatically.
When an existing Logic App has a manual trigger, it cannot be invoked directly by Sentinel. Therefore, the first step is to modify the trigger to replace the manual trigger with the ''When a response to an Azure Sentinel alert is triggered'' trigger. After that, you can link it within Sentinel incidents or automation rules.
This process is detailed in Microsoft Defender XDR and Sentinel documentation under ''Connect a Logic App to Sentinel as a playbook.''
Hence, the correct answer is D. Modify the trigger in the logic app.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to implement deception rules. The solution must ensure that you can limit the scope of the rules.
What should you create first?
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.
You need to add threat indicators for all the IP addresses in a range of 171.23.3432-171.2334.63. The solution must minimize administrative effort.
What should you do in the Microsoft 365 Defender portal?
This will add all the IP addresses in the range of 171.23.34.32/27 as threat indicators. This is the simplest and most efficient way to add all the IP addresses in the range.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to implement deception rules. The solution must ensure that you can limit the scope of the rules.
What should you create first?
You need to ensure that the configuration of HuntingQuery1 meets the Microsoft Sentinel requirements.
What should you do?
Emily Harris
2 days agoRichard Wright
15 days agoCarol Evans
30 days agoMelissa Torres
2 months agoDaniel Taylor
1 month agoAmanda Nelson
1 month agoKenneth Martinez
1 month agoKaren Green
30 days agoStephen Hill
26 days agoKattie
2 months agoPansy
2 months agoEun
3 months agoKayleigh
3 months agoAhmed
3 months agoErnest
3 months agoKristofer
4 months agoOretha
4 months agoArleen
4 months agoVincenza
4 months agoWade
5 months agoBlondell
5 months agoPaola
5 months agoAlba
5 months agoLeota
6 months agoLorrie
6 months agoBok
6 months agoJeannetta
6 months agoLuis
7 months agoAndra
7 months agoLing
7 months agoPenney
7 months agoHerminia
8 months agoJoye
8 months agoNadine
8 months agoFreeman
8 months agoGlennis
9 months agoAhmed
9 months agoRuthann
9 months agoRhea
9 months agoLynda
11 months agoNina
1 year agoGayla
1 year agoAnnabelle
1 year agoRoxane
1 year agoPatrick
1 year agoLettie
1 year agoHorace
1 year agoMacy
2 years agoAlishia
2 years agoAdell
2 years agoJennifer
2 years agoLucina
2 years agoAsha
2 years agoRyan
2 years agoMichal
2 years agoLeigha
2 years agoLinsey
2 years agoDell
2 years agoSantos
2 years agoSabra
2 years agoClaudio
2 years agoMila
2 years agoJoni
2 years agoDella
2 years agoMaryann
2 years agoGerald
2 years agoTenesha
2 years agodarrena
2 years agokalasan
2 years ago