Microsoft SC-200 Practice Test - Questions Answers, Page 15
List of questions
Related questions
HOTSPOT
You have the following SQL query.
You have a Microsoft 365 E5 subscription that is linked to a hybrid Azure AD tenant.
You need to identify all the changes made to Domain Admins group during the past 30 days.
What should you use?
the Azure Active Directory Provisioning Analysis workbook
the Overview settings of Insider risk management
the Modifications of sensitive groups report in Microsoft Defender for Identity
the identity security posture assessment in Microsoft Defender for Cloud Apps
You have a Microsoft Sentinel workspace.
You need to prevent a built-in Advance Security information Model (ASIM) parse from being updated automatically.
What are two ways to achieve this goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Redeploy the built-in parse and specify a CallerContext parameter of any and a SourceSpecificParse parameter of any.
Create a hunting query that references the built-in parse.
Redeploy the built-in parse and specify a CallerContext parameter of built-in.
Build a custom unify parse and include the build- parse version
Create an analytics rule that includes the built-in parse
You have a Microsoft Sentinel workspace.
You receive multiple alerts for failed sign in attempts to an account.
You identify that the alerts are false positives.
You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements.
• Ensure that failed sign-in alerts are generated for other accounts.
• Minimize administrative effort
What should do?
Create an automation rule.
Create a watchlist.
Modify the analytics rule.
Add an activity template to the entity behavior.
DRAG DROP
A company wants to analyze by using Microsoft 365 Apps.
You need to describe the connected experiences the company can use.
Which connected experiences should you describe? To answer, drag the appropriate connected experiences to the correct description. Each connected experience may be used once, more than once, or not at all. You may need to drag the split between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
You have a custom Microsoft Sentinel workbook named Workbooks.
You need to add a grid to Workbook1. The solution must ensure that the grid contains a maximum of 100 rows.
What should you do?
In the query editor interface, configure Settings.
In the query editor interface, select Advanced Editor
In the grid query, include the project operator.
In the grid query, include the take operator.
You have an Azure subscription that uses Microsoft Defender for Cloud and contains a resource group named RG1. RG1. You need to configure just in time (JIT) VM access for the virtual machines in RG1.
The solution must meet the following
• Limit the maximum request time to two hours.
• Limit protocol access to Remote Desktop Protocol (RDP) only.
• Minimize administrative effort.
What should you use?
Azure AD Privileged Identity Management (PIM)
Azure Policy
Azure Front Door
Azure Bastion
You have a Microsoft Sentinel workspace named Workspace1.
You need to exclude a built-in, source-specific Advanced Security information Model (ASIM) parse from a built-in unified ASIM parser.
What should you create in Workspace1?
a watch list
an analytic rule
a hunting query
a workbook
You have an Azure subscription that uses Microsoft Defender for Endpoint.
You need to ensure that you can allow or block a user-specified range of IP addresses and URLs.
What should you enable first in the advanced features from the Endpoints Settings in the Microsoft 365 Defender portal?
endpoint detection and response (EDR) in block mode
custom network indicators
web content filtering
Live response for servers
You have an Azure subscription that uses Microsoft Defender for Cloud and contains a storage account named storage1. You receive an alert that there was an unusually high volume of delete operations on the blobs in storage1.
You need to identify which blobs were deleted.
What should you review?
the Azure Storage Analytics logs
the activity logs of storage1
the alert details
the related entities of the alert
Question