ExamGecko
Home / Microsoft / SC-200 / List of questions
Ask Question

Microsoft SC-200 Practice Test - Questions Answers, Page 10

List of questions

Question 91

Report
Export
Collapse

You need to ensure that the configuration of HuntingQuery1 meets the Microsoft Sentinel requirements.

What should you do?

Add HuntingQuery1 to a livestream.

Add HuntingQuery1 to a livestream.

Create a watch list.

Create a watch list.

Create an Azure Automation rule.

Create an Azure Automation rule.

Add HuntingQuery1 to favorites.

Add HuntingQuery1 to favorites.

Suggested answer: D
asked 05/10/2024
Hakan Köroğlu
34 questions

Question 92

Report
Export
Collapse

HOTSPOT

You need to implement the Microsoft Sentinel NRT rule for monitoring the designated break glass account. The solution must meet the Microsoft Sentinel requirements.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 92 107806 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 92 107806 10052024010847000
asked 05/10/2024
e m
34 questions

Question 93

Report
Export
Collapse

HOTSPOT

You need to monitor the password resets. The solution must meet the Microsoft Sentinel requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 93 107807 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 93 107807 10052024010847000
asked 05/10/2024
Alex Bu
45 questions

Question 94

Report
Export
Collapse

You need to ensure that the processing of incidents generated by rulequery1 meets the Microsoft Sentinel requirements.

What should you create first?

a playbook with an incident trigger

a playbook with an incident trigger

a playbook with an entity trigger

a playbook with an entity trigger

an Azure Automation rule

an Azure Automation rule

a playbook with an alert trigger

a playbook with an alert trigger

Suggested answer: A
asked 05/10/2024
Suraj Patil
34 questions

Question 95

Report
Export
Collapse

You need to implement the Defender for Cloud requirements.

Which subscription-level role should you assign to Group1?

Security Admin

Security Admin

Owner

Owner

Security Assessment Contributor

Security Assessment Contributor

Contributor

Contributor

Suggested answer: B
asked 05/10/2024
Ronald Armas
34 questions

Question 96

Report
Export
Collapse

You need to implement the scheduled rule for incident generation based on rulequery1.

What should you configure first?

entity mapping

entity mapping

custom details

custom details

event grouping

event grouping

alert details

alert details

Suggested answer: D
asked 05/10/2024
Cynthia Gutknecht
46 questions

Question 97

Report
Export
Collapse

You need to ensure that the Group1 members can meet the Microsoft Sentinel requirements.

Which role should you assign to Group1?

Microsoft Sentinel Automation Contributor

Microsoft Sentinel Automation Contributor

Logic App Contributor

Logic App Contributor

Automation Operator

Automation Operator

Microsoft Sentinel Playbook Operator

Microsoft Sentinel Playbook Operator

Suggested answer: D
asked 05/10/2024
PKE Holding AG Leitgeb
33 questions

Question 98

Report
Export
Collapse

HOTSPOT

You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 98 107812 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 98 107812 10052024010847000

Explanation:

asked 05/10/2024
Manuel Ortega
42 questions

Question 99

Report
Export
Collapse

You need to remediate active attacks to meet the technical requirements.

What should you include in the solution?

Azure Automation runbooks

Azure Automation runbooks

Azure Logic Apps

Azure Logic Apps

Azure Functions

Azure Functions

Azure Sentinel livestreams

Azure Sentinel livestreams

Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks

asked 05/10/2024
Cesar Castillo
31 questions

Question 100

Report
Export
Collapse

HOTSPOT

You need to create an advanced hunting query to investigate the executive team issue.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 100 107842 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 100 107842 10052024010847000
asked 05/10/2024
Lakshmi Yechuri
40 questions
Total 307 questions
Go to page: of 31
Search

Related questions