Microsoft SC-200 Practice Test - Questions Answers, Page 11
List of questions
Question 101
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
HOTSPOT
You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants
Question 102
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
You need to complete the query for failed sign-ins to meet the technical requirements.
Where can you find the column name to complete the where clause?
Security alerts in Azure Security Center
Activity log in Azure
Azure Advisor
the query windows of the Log Analytics workspace
Explanation:
Question 103
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
The issue for which team can be resolved by using Microsoft Defender for Endpoint?
executive
sales
marketing
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-atp-ios
Question 104
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
The issue for which team can be resolved by using Microsoft Defender for Office 365?
executive
marketing
security
sales
Explanation:
Reference:
https://docs.mic rosoft. co m/en-us/microsoft-365/securitv/office-365-security/atp-for-spo-odb-and-teams?view=o365-worldwide
Question 105
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
You need to recommend a solution to meet the technical requirements for the Azure virtual machines.
What should you include in the recommendation?
just-in-time (JIT) access
Azure Defender
Azure Firewall
Azure Application Gateway
Explanation:
Reference:
https://docsmicrosoft.com/en-us/azure/security-center/azure-defender
Question 106
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
HOTSPOT
You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.
What should you recommend for each threat? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/key-vault/general/security-features
https://docs.microsoft.com/en-us/azure/key-vault/general/secure-your-key-vault
Question 107
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
You need to assign a role-based access control (RBAC) role to admin! to meet the Azure Sentinel requirements and the business requirements.
Which role should you assign?
Automation Operator
Automation Run book Operator
Azure Sentinel Contributor
Logic App Contributor
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/roles
Question 108
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
You need to create the test rule to meet the Azure Sentinel requirements.
What should you do when you create the rule?
From Set rule logic, turn off suppression.
From Analytics rule details, configure the tactics.
From Set rule logic, map the entities.
From Analytics rule details, configure the severity.
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom
Question 109
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
DRAG DROP
You need to add notes to the events to meet the Azure Sentinel requirements.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/bookmarks
Question 110
![Export Export](https://examgecko.com/assets/images/icon-download-24.png)
HOTSPOT
You need to configure the Azure Sentinel integration to meet the Azure Sentinel requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation:
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/siem-sentinel
Question