You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/2-analyze-investigate-sign-logs-to-troubleshoot-access-issues.yml
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/3-review-monitor-azure-active-directory-audit-logs.yml
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/4-connect-data-from-azure-active-directory-to-azure-sentinel.yml
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/5-export-logs-to-third-party-security-information.yml
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/6-analyze-azure-active-directory-workbooks-reporting.yml
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/7-monitor-security-posture-identity-secure-score.yml
- content: "Microsoft Entra audit logs provide a comparison of budgeted Azure usage compared to actual."
22
24
isCorrect: false
23
-
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You'll see things like adding or removing users, apps, groups, roles, and policies."
25
+
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You see things like adding or removing users, apps, groups, roles, and policies."
24
26
- content: "Microsoft Entra audit logs provide records of system activities for compliance reporting."
25
27
isCorrect: true
26
28
explanation: "Correct. An audit log has a default list view that shows data like the date and time of the occurrence. Additional information includes the service that logged the occurrence, and the category of the activity. Finally, the name of the activity (what), the status of the activity (success or failure), the target, and the initiator/actor (who) of an activity."
27
29
- content: "Microsoft Entra audit logs allow customer to monitor activity when provisioning new services within Azure."
28
30
isCorrect: false
29
-
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You'll see things like adding or removing users, apps, groups, roles, and policies."
31
+
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You see things like adding or removing users, apps, groups, roles, and policies."
30
32
- content: "Can Azure export logging data to third-party SIEM (security information and event management) tools?"
31
33
choices:
32
34
- content: "Yes, Azure supports exporting log data to several common third-party SIEM tools."
@@ -37,7 +39,7 @@ quiz:
37
39
explanation: "Incorrect. Azure Sentinel is a Microsoft first-party SIEM tool, but we do support using other tools, such as Splunk, IBM QRadar, and ArcSight."
38
40
- content: "Yes, Splunk is the third party SIEM Azure can export to."
39
41
isCorrect: false
40
-
explanation: "Incorrect. While Splunk is one of the third-party SIEM tools we can export data to, it is not the only one. We also support other third-party SIEM tools, such as IBM QRadar and ArcSight."
42
+
explanation: "Incorrect. While Splunk is one of the third-party SIEM tools we can export data to, it isn't the only one. We also support other third-party SIEM tools, such as IBM QRadar and ArcSight."
41
43
- content: "John wants to configure email notifications to be sent from Microsoft Entra Domain Services (AD DS) when issues are detected. In Azure, where would notifications be configured?"
42
44
choices:
43
45
- content: "Azure Microsoft Portal - Microsoft Entra ID - Monitoring - Notifications - Add email recipient."
@@ -48,4 +50,4 @@ quiz:
48
50
explanation: "Correct. The health of a Microsoft Entra Domain Services (MEDS) managed domain is monitored by the Azure platform. The health status page in the Azure Microsoft Portal shows any alerts for the managed domain. To make sure issues are responded to in a timely manner, email notifications can be configured to report on health alerts as soon as they're detected in the Microsoft Entra Domain Services managed domain."
49
51
- content: "Azure Microsoft Portal - Notification Hubs - Microsoft Entra ID - Add email recipient."
50
52
isCorrect: false
51
-
explanation: "Incorrect. Azure Notification Hubs are to provide push notification to any platform (iOS, Android, Windows, and so on.) to share breaking news, promotional content, or other Azure App information to users."
53
+
explanation: "Incorrect. Azure Notification Hubs are to provide push notification to any platform to share breaking news, promotional content, or other Azure App information to users."
0 commit comments