ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 31 - SC-200 discussion

Report
Export

You use Azure Sentinel.

You need to receive an immediate alert whenever Azure Storage account keys are enumerated.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Create a livestream

Answers
A.

Create a livestream

B.

Add a data connector

Answers
B.

Add a data connector

C.

Create an analytics rule

Answers
C.

Create an analytics rule

D.

Create a hunting query.

Answers
D.

Create a hunting query.

E.

Create a bookmark.

Answers
E.

Create a bookmark.

Suggested answer: B, C

Explanation:

B: To add a data connector, you would use the Azure Sentinel data connectors feature to connect to your Azure subscription and to configure log data collection for Azure Storage account key enumeration events.C: After adding the data connector, you need to create an analytics rule to analyze the log data from the Azure storage connector, looking for the specific event of Azure storage account keys enumeration. This rule will trigger an alert when it detects the specific event, allowing you to take immediate action.

asked 05/10/2024
Luis Antonio Sanchez Estrada
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first