ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 120 - SC-200 discussion

Report
Export

You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled.

You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1.

What should you do first?

A.

From Azure Security Center, add a workflow automation.

Answers
A.

From Azure Security Center, add a workflow automation.

B.

On VM1, run the Get-MPThreatCatalog cmdlet.

Answers
B.

On VM1, run the Get-MPThreatCatalog cmdlet.

C.

On VM1 trigger a PowerShell alert.

Answers
C.

On VM1 trigger a PowerShell alert.

D.

From Azure Security Center, export the alerts to a Log Analytics workspace.

Answers
D.

From Azure Security Center, export the alerts to a Log Analytics workspace.

Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-alerts?view=o365-worldwide

asked 05/10/2024
garima sharma
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first