ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 65 - SC-200 discussion

Report
Export

You have the following advanced hunting query in Microsoft 365 Defender.

You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Create a detection rule.

Answers
A.

Create a detection rule.

B.

Create a suppression rule.

Answers
B.

Create a suppression rule.

C.

Add | order by Timestamp to the query.

Answers
C.

Add | order by Timestamp to the query.

D.

Replace DeviceProcessEvents with DeviceNetworkEvents.

Answers
D.

Replace DeviceProcessEvents with DeviceNetworkEvents.

E.

Add Deviceld and Reportldto the output of the query.

Answers
E.

Add Deviceld and Reportldto the output of the query.

Suggested answer: A, E

Explanation:

Reference:

https://docs.mic rosoftcom/en-us/windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules

asked 05/10/2024
marwan albahar
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first