FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 7

Question 243

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1. WS1 has the Azure Activity connector and the Microsoft Entra ID connector configured. You need to investigate which accounts have the most alerts and any corresponding incident information for each alert. The solution must minimize administrative effort. What should you do first in WS1?

  • AUse User and Entity Behavior Analytics (UEBA) to detect anomalies.
  • BEnable User and Entity Behavior Analytics (UEBA).
  • CFrom Content hub, install the Microsoft Purview insider risk management solution.
  • DFrom Content hub, install Cloud Identity Threat Protection Essentials.