Implement and Manage Threat Protection - Questions Flashcards

1
Q

Office 365 ATP Plan 1 comes with ___.

Office 365 ATP Plan 2 comes with ___.

A

O365 ATP Plan 1 comes with real-time detections.

O365 ATP Plan 2 comes with the Threat Mgmt Explorer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the Threat Trackers and what license is required?

A

Widgets that can provide more information on global threats to keep admin informed about what is happening across cyber security.
-> Required O365 ATP Plan 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How do you access O365 ATP incidents?

A

Security & Compliance Portal

  • > Threat Management
  • > Review
  • > Incidents
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What license is required for using Attack Simulator? What 3 tools are included?

A

Required O365 ATP Plan2
->3 tools
1. Spear Phishing
2. Brute-force password attack (dictionary attack)
3. Password Spray Attack
MFA is required for your account before launching any attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do you access the Attack Simulator?

A

in Security & Compliance at protection.office.com

  • > choose Threat Mgmt
  • > Attack Simulator
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Azure Sentinel?

A

It is a next-generation SIEM because it includes the ability to respond automatically to events using Playbooks, bringing Security Orchestration Automated Response (SOAR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is needed to implement Azure Sentinel?

A
  • > An Active Azure Subscription
  • > A Log Analytics Workspace
  • > At least Contributor permissions to the Azure Subscription
  • > At least Contributor or Reader permissions on the Resource group to which Workspace belongs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you access Azure Sentinel?

A

Azure Portal portal.azure.com

  • > in Search field type “Azure Sentinel”
  • > select Add
  • > select or create Workspace
  • > select Add Azure Sentinel
  • > click Data Connectors
  • > select Data Connectors
  • > click Open Connector Page to configure Connector
How well did you know this?
1
Not at all
2
3
4
5
Perfectly