ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 71 - SC-200 discussion

Report
Export

You receive a security bulletin about a potential attack that uses an image file.

You need to create an indicator of compromise (loC) in Microsoft Defender for Endpoint to prevent the attack.

Which indicator type should you use?

A.

a URL/domain indicator that has Action set to Alert only

Answers
A.

a URL/domain indicator that has Action set to Alert only

B.

a URL/domain indicator that has Action set to Alert and block

Answers
B.

a URL/domain indicator that has Action set to Alert and block

C.

a file hash indicator that has Action set to Alert and block

Answers
C.

a file hash indicator that has Action set to Alert and block

D.

a certificate indicator that has Action set to Alert and block

Answers
D.

a certificate indicator that has Action set to Alert and block

Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.eom/en-us/microsoft-365/securitv/defender-endpoint/i nd icator-file?view=o365-worldwide

asked 05/10/2024
Jari Tetteroo
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first