You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel. Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and MicrosoftDefender Antivirus in passive mode. You need to ensure that the devices are protected frommalicious artifacts that were undetected by the third-party antivirus product. Solution: You configureControlled folder access. Does this meet the goal?
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains the
devices shown in the following table.You initiate a live response session on each device.
You need to collect a Defender for Endpoint investigation package from each device.On which devices can you collect the package by running advanced live response commands from
the command-line interface (CLI)?
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains the
devices shown in the following table.You initiate a live response session on each device.
You need to collect a Defender for Endpoint investigation package from each device.On which devices can you collect the package by running advanced live response commands from
the command-line interface (CLI)?