Microsoft SC-200 Custom Detections Sentinel Analytics MITRE ATTACK And Anomalies Practice Test

 

Skills 1.4 • 35 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on custom detections sentinel analytics mitre attack and anomalies through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a threat-hunting campaign at Alpine Ski House, the security operations analyst must turn the validated Advanced Hunting logic into a recurring Defender XDR detection. Which action most directly satisfies the requirement for the Tier 1 queue, response wave 1? The design priority is to improve detection coverage.

  1. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  2. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace
  3. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: C

Why: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Option review:

A: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

B: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

C: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Learning point: Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Question 2

Wide World Importers is revising its SOC runbook after a SOC handoff review. Analysts need to update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule. Which implementation should the Sentinel administrator select for the Tier 2 queue, response wave 1 while trying to support repeatable response?

  1. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  2. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  3. Create a custom log table in the Log Analytics workspace for the ingested custom data
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: B

Why: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Option review:

A: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

B: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

C: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Learning point: Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Question 3

A ticket escalated to the security engineer at Wingtip Toys states one non-negotiable goal: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source. Which choice is the strongest fit for the identity-response team, response wave 1? The team also wants to separate collection from detection logic.

  1. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  2. Configure the appropriate email notification rule in Microsoft Defender XDR
  3. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  4. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace
  5. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Correct answer: E

Why: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Option review:

A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

C: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

D: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

E: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Learning point: Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Question 4

For the endpoint-response team, response wave 1 at Fabrikam Retail, a audit investigation can proceed only if the team can evaluate detection coverage and gaps against adversary tactics and techniques. What should the Tier 2 analyst configure first if the operational goal is to preserve investigation context?

  1. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  2. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  3. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  4. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: B

Why: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Option review:

A: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

B: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

C: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

D: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Learning point: Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Question 5

The security architecture review at Adventure Works focuses on this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds. Which Microsoft security action is most appropriate for the cloud-security team, response wave 1, given the need to minimize manual analyst steps?

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  3. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  4. Configure Windows Security Events via AMA and the required data collection rule
  5. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view

Correct answer: B

Why: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

B: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

D: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

E: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Learning point: Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Question 6

A change advisory board at Alpine Ski House asks how to turn the validated Advanced Hunting logic into a recurring Defender XDR detection during a lateral-movement investigation. Which proposed action should the security engineer approve for the night shift, response wave 2? The change should minimize manual analyst steps.

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  3. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Select the Microsoft Sentinel data connector that matches the source type and required event stream

Correct answer: C

Why: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

B: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

C: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

E: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Learning point: Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Question 7

Wide World Importers has ruled out a manual one-off workaround. For the EMEA SOC, response wave 2, the remaining requirement is to update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule. Which choice best addresses it and helps retain evidence for follow-up analysis?

  1. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  2. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  3. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  4. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  5. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Correct answer: B

Why: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Option review:

A: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

B: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

C: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

D: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

E: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Learning point: Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Question 8

During post-incident review at Wingtip Toys, the threat hunter identifies a gap: the SOC still needs to implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source. Which action should be added for the Americas SOC, response wave 2 before the next incident, with an emphasis on trying to avoid unnecessary alert noise?

  1. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  2. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  3. Configure Windows Security Events via AMA and the required data collection rule
  4. Configure Defender for Endpoint device groups with the required permissions and automation level
  5. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Correct answer: E

Why: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Option review:

A: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

B: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

C: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

E: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Learning point: Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Question 9

The SOC analyst at Fabrikam Retail is comparing several Microsoft security options for a ransomware response. Which one directly enables the team to evaluate detection coverage and gaps against adversary tactics and techniques for the high-value-assets group, response wave 2 while helping preserve least privilege?

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  4. Create a custom log table in the Log Analytics workspace for the ingested custom data
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: C

Why: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

C: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

D: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Learning point: Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Question 10

A security-operations workshop at Adventure Works defines the desired outcome as follows: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds. Which implementation should be chosen for the privileged-users group, response wave 2? The team wants to reduce mean time to respond.

  1. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  5. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal

Correct answer: D

Why: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Option review:

A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

D: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Learning point: Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Question 11

Which Microsoft security action best matches this technical purpose for the remote-user fleet, response wave 3: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. The SOC is trying to reduce mean time to respond.

  1. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  2. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  3. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  4. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  5. Configure Windows Security Events via AMA and the required data collection rule

Correct answer: D

Why: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Option review:

A: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

B: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

C: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

D: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

E: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Learning point: Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Question 12

An analyst at Wide World Importers describes the needed capability this way: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. Which option should be associated with that requirement for the production subscription, response wave 3 while the team tries to scope the change to the affected security domain?

  1. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: A

Why: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Option review:

A: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

D: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Learning point: Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Question 13

During a design validation for the research subscription, response wave 3, Wingtip Toys documents the following behavior: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. Which Microsoft security feature or action is being described? The objective is to keep the workflow auditable.

  1. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace
  4. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: D

Why: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Option review:

A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

C: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

D: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Learning point: Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Question 14

The incident responder must identify the Microsoft security capability that provides this function for the regulated workload segment, response wave 3: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. Which choice is correct if the SOC also needs to avoid changing an unrelated control plane?

  1. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace
  2. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  3. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  4. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  5. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Correct answer: C

Why: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Option review:

A: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

B: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

C: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

D: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

E: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Learning point: Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Question 15

A runbook for the Tier 1 queue, response wave 3 contains this description: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. Which implementation belongs in that runbook during a lateral-movement investigation? The process should improve detection coverage.

  1. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  2. Create a custom log table in the Log Analytics workspace for the ingested custom data
  3. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  4. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  5. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Correct answer: D

Why: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Option review:

A: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

B: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

D: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

E: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Learning point: Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Question 16

Alpine Ski House is troubleshooting a SOC tuning initiative. Evidence shows that the decisive requirement is to turn the validated Advanced Hunting logic into a recurring Defender XDR detection. Which action should the Defender administrator investigate first for the identity-response team, response wave 4, without losing the ability to improve detection coverage?

  1. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  4. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace
  5. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Correct answer: A

Why: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Option review:

A: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

D: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

E: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Learning point: Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Question 17

After eliminating network and licensing causes, the incident responder at Wide World Importers determines that success depends on the ability to update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule. Which security action should be checked next for the endpoint-response team, response wave 4? The team must support repeatable response.

  1. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  4. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  5. Create a custom log table in the Log Analytics workspace for the ingested custom data

Correct answer: D

Why: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Option review:

A: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

C: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

D: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

E: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Learning point: Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Question 18

A service-desk escalation during a identity compromise review has been narrowed to one security-operations requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source. Which configuration is the most relevant starting point for the cloud-security team, response wave 4 if the SOC wants to separate collection from detection logic?

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  4. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  5. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Correct answer: E

Why: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

C: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

D: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

E: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Learning point: Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Question 19

The failure pattern at Fabrikam Retail affects the messaging-security team, response wave 4. Before making unrelated policy changes, the Sentinel administrator needs a solution that will evaluate detection coverage and gaps against adversary tactics and techniques. Which action is most directly relevant and helps preserve investigation context?

  1. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  2. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  3. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Correct answer: A

Why: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Option review:

A: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

B: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Learning point: Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Question 20

While investigating a phishing investigation, Adventure Works confirms the environment must detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds. Which Microsoft security capability should be validated for the night shift, response wave 4? The investigation should minimize manual analyst steps.

  1. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  4. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  5. Review and apply relevant Microsoft Sentinel SOC optimization recommendations

Correct answer: A

Why: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Option review:

A: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

C: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

E: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Learning point: Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Question 21

Two teams at Alpine Ski House propose different approaches for the Americas SOC, response wave 5. The selection criterion is simple: the chosen approach must turn the validated Advanced Hunting logic into a recurring Defender XDR detection. Which option should win the technical comparison if the SOC also wants to minimize manual analyst steps?

  1. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  2. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  3. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: A

Why: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Option review:

A: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

B: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

C: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Learning point: Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Question 22

For the high-value-assets group, response wave 5, Wide World Importers wants the least indirect solution to this goal: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule. Which action aligns most closely with that requirement and the need to retain evidence for follow-up analysis?

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  3. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  4. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  5. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability

Correct answer: D

Why: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

C: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

D: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

E: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Learning point: Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Question 23

A modernization plan at Wingtip Toys includes a detection-engineering sprint. The security engineer is asked to choose the control that specifically helps the organization implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source. Which choice fits best for the privileged-users group, response wave 5 while supporting the goal to avoid unnecessary alert noise?

  1. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  2. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  3. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace

Correct answer: A

Why: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Option review:

A: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

B: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

C: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

E: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Learning point: Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Question 24

The server fleet, response wave 5 is moving into a controlled rollout at Fabrikam Retail. Which action should be included when the stated security objective is to evaluate detection coverage and gaps against adversary tactics and techniques? The operational standard is to preserve least privilege.

  1. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  2. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  5. Configure the appropriate table or tier retention setting for the required investigation and cost objective

Correct answer: A

Why: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Option review:

A: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

B: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

E: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Learning point: Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Question 25

Adventure Works is replacing an ad hoc process during a SOC tuning initiative. The replacement must reliably detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds. Which security-operations approach should the threat hunter implement for the remote-user fleet, response wave 5 if the team also wants to reduce mean time to respond?

  1. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  2. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  3. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  4. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: A

Why: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Option review:

A: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

B: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

C: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

D: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Learning point: Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Question 26

An audit finding for the research subscription, response wave 6 says the current process does not consistently turn the validated Advanced Hunting logic into a recurring Defender XDR detection. Which Microsoft security action most directly closes that gap while helping the SOC reduce mean time to respond?

  1. Create a custom log table in the Log Analytics workspace for the ingested custom data
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  5. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action

Correct answer: D

Why: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Option review:

A: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

D: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Learning point: Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Question 27

The Tier 2 analyst at Wide World Importers needs a repeatable configuration for the regulated workload segment, response wave 6. It must update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule. Which choice should be implemented instead of relying on manual incident work if the goal is to scope the change to the affected security domain?

  1. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  2. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  3. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  4. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: C

Why: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Option review:

A: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

B: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

C: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

D: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Learning point: Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Question 28

During readiness testing at Wingtip Toys, the Tier 1 queue, response wave 6 fails a business requirement because analysts cannot yet implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source. Which action should be implemented before rollout continues? The SOC also needs to keep the workflow auditable.

  1. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  2. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  3. Configure Windows Security Events via AMA and the required data collection rule
  4. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  5. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Correct answer: D

Why: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Option review:

A: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

B: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

C: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

D: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

E: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Learning point: Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Question 29

A governance review asks the SOC analyst to justify the control selected for the Tier 2 queue, response wave 6. The requirement is to evaluate detection coverage and gaps against adversary tactics and techniques. Which action has the clearest technical alignment while supporting the goal to avoid changing an unrelated control plane?

  1. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  2. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  3. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  4. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  5. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Correct answer: C

Why: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Option review:

A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

B: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

C: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

D: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Learning point: Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Question 30

For a threat-hunting campaign, Adventure Works needs a Microsoft security capability with this effect: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. Which option most accurately provides that capability for the identity-response team, response wave 6? The process should improve detection coverage.

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Correct answer: E

Why: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

E: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Learning point: Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Question 31

The operational standard for the cloud-security team, response wave 7 is being rewritten. Which action should be documented when the standard requires analysts to turn the validated Advanced Hunting logic into a recurring Defender XDR detection and the SOC wants to improve detection coverage?

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  3. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  4. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  5. Create a custom log table in the Log Analytics workspace for the ingested custom data

Correct answer: C

Why: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

B: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

C: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. This directly addresses the requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

E: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: turn the validated Advanced Hunting logic into a recurring Defender XDR detection.

Learning point: Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Question 32

Wide World Importers is creating a response playbook for the messaging-security team, response wave 7. Which Microsoft security step belongs in the playbook when the objective is to update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule? The playbook should also help support repeatable response.

  1. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  2. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  3. Configure the appropriate email notification rule in Microsoft Defender XDR
  4. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  5. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Correct answer: B

Why: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Option review:

A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

B: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. This directly addresses the requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

D: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

E: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: update or maintain an existing Defender XDR custom detection without replacing it with a Sentinel rule.

Learning point: Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Question 33

During a telemetry modernization at Wingtip Toys, the Defender administrator must implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source. Which action most directly satisfies the requirement for the night shift, response wave 7? The design priority is to separate collection from detection logic.

  1. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  2. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  3. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  4. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  5. Configure the appropriate table or tier retention setting for the required investigation and cost objective

Correct answer: D

Why: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Option review:

A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

B: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

D: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. This directly addresses the requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

E: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: implement the Sentinel detection using the analytics-rule type that best matches the required timing and signal source.

Learning point: Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements

Question 34

Fabrikam Retail is revising its SOC runbook after a data-ingestion rollout. Analysts need to evaluate detection coverage and gaps against adversary tactics and techniques. Which implementation should the incident responder select for the EMEA SOC, response wave 7 while trying to preserve investigation context?

  1. Configure Windows Security Events via AMA and the required data collection rule
  2. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  3. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  4. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  5. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Correct answer: C

Why: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Option review:

A: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

B: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

C: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. This directly addresses the requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

D: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

E: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: evaluate detection coverage and gaps against adversary tactics and techniques.

Learning point: Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Question 35

A ticket escalated to the security operations analyst at Adventure Works states one non-negotiable goal: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds. Which choice is the strongest fit for the Americas SOC, response wave 7? The team also wants to minimize manual analyst steps.

  1. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Correct answer: A

Why: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Option review:

A: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. This directly addresses the requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

C: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: detect unusual behavior through Sentinel anomaly-based detection rather than only static thresholds.

Learning point: Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Popular posts

img