ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 59 - SC-200 discussion

Report
Export

You have an Azure subscription named Sub1 and a Microsoft 365 subscription. Sub1 is linked to an Azure Active Directory (Azure AD) tenant named contoso.com.

You create an Azure Sentinel workspace named workspace1. In workspace1, you activate an Azure AD connector for contoso.com and an Office 365 connector for the Microsoft 365 subscription.

You need to use the Fusion rule to detect multi-staged attacks that include suspicious sign-ins to contoso.com followed by anomalous Microsoft Office 365 activity.

Which two actions should you perform? Each correct answer present part of the solution.

NOTE: Each correct selection is worth one point.

A.

Create custom rule based on the Office 365 connector templates.

Answers
A.

Create custom rule based on the Office 365 connector templates.

B.

Create a Microsoft incident creation rule based on Microsoft Defender for Cloud.

Answers
B.

Create a Microsoft incident creation rule based on Microsoft Defender for Cloud.

C.

Create a Microsoft Cloud App Security connector.

Answers
C.

Create a Microsoft Cloud App Security connector.

D.

Create an Azure AD Identity Protection connector.

Answers
D.

Create an Azure AD Identity Protection connector.

Suggested answer: A, B

Explanation:


asked 05/10/2024
Michele Lorengo
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first