ExamGecko
Home Home / Microsoft / SC-200

Microsoft SC-200 Practice Test - Questions Answers, Page 18

Question list
Search
Search

List of questions

Search

Related questions











HOTSPOT

You have an Azure subscription that has Azure Defender enabled for all supported resource types.

You create an Azure logic app named LA1.

You plan to use LA1 to automatically remediate security risks detected in Defenders for Cloud.

You need to test LA1 in Defender for Cloud.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 171
Correct answer: Question 171

DRAG DROP

You are investigating an incident by using Microsoft 365 Defender.

You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop. CEOLaptop, and COOLaptop.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE Each correct selection is worth one point


Question 172
Correct answer: Question 172

HOTSPOT

You have an Azure subscription.

You plan to implement an Microsoft Sentinel workspace. You anticipate that you will ingest 20 GB of security log data per day.

You need to configure storage for the workspace. The solution must meet the following requirements:

• Minimize costs for daily ingested data.

• Maximize the data retention period without incurring extra costs.

What should you do for each requirement? To answer, select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.


Question 173
Correct answer: Question 173

HOTSPOT

Your on-premises network contains 100 servers that run Windows Server.

You have an Azure subscription that uses Microsoft Sentinel.

You need to upload custom logs from the on-premises servers to Microsoft Sentinel.

What should you do? To answer, select the appropriate options m the answer area.


Question 174
Correct answer: Question 174

Explanation:

To upload custom logs from the on-premises servers to Microsoft Sentinel, you should install the Log

Analytics agent on each of the 100 servers. The Log Analytics agent is a lightweight agent that runs on the server and allows it to connect to the cloud-based Microsoft Defender Security Center. Once installed, the agent will allow the Microsoft Sentinel service to collect and analyze the custom log data from the servers.

HOTSPOT

You have a Microsoft Sentinel workspace

You develop a custom Advanced Security information Model (ASIM) parser named Parser1 that produces a schema named Schema1.

You need to validate Schema1.

How should you complete the command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 175
Correct answer: Question 175

Explanation:

HOTSPOT

You have a Microsoft Sentinel workspace that has User and Entity Behavior Analytics (UEBA) enabled.

You need to identify all the log entries that relate to security-sensitive user actions performed on a server named Server1. The solution must meet the following requirements:

• Only include security-sensitive actions by users that are NOT members of the IT department.

• Minimize the number of false positives.

How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Question 176
Correct answer: Question 176

Explanation:

You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server.

You need to configure Defender for Cloud to collect event data from the virtual machines. The solution must minimize administrative effort and costs.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

From the workspace created by Defender for Cloud, set the data collection level to Common

A.

From the workspace created by Defender for Cloud, set the data collection level to Common

Answers
B.

From the Microsoft Endpoint Manager admin center, enable automatic enrollment.

B.

From the Microsoft Endpoint Manager admin center, enable automatic enrollment.

Answers
C.

From the Azure portal, create an Azure Event Grid subscription.

C.

From the Azure portal, create an Azure Event Grid subscription.

Answers
D.

From the workspace created by Defender for Cloud, set the data collection level to All Events

D.

From the workspace created by Defender for Cloud, set the data collection level to All Events

Answers
E.

From Defender for Cloud in the Azure portal, enable automatic provisioning for the virtual machines.

E.

From Defender for Cloud in the Azure portal, enable automatic provisioning for the virtual machines.

Answers
Suggested answer: D, E

You have an Azure subscription that use Microsoft Defender for Ctoud and contains a user named User1.

You need to ensure that User1 can modify Microsoft Defender for Cloud security policies. The solution must use the principle of least privilege.

Which role should you assign to User1?

A.

Security operator

A.

Security operator

Answers
B.

Security Admin

B.

Security Admin

Answers
C.

Owner

C.

Owner

Answers
D.

Contributor

D.

Contributor

Answers
Suggested answer: B

DRAG DROP

You have an Azure subscription that contains 100 Linux virtual machines.

You need to configure Microsoft Sentinel to collect event logs from the virtual machines.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Question 179
Correct answer: Question 179

You have an Azure subscription that contains an Azure logic app named app1 and a Microsoft Sentinel workspace that has an Azure AD connector. You need to ensure that app1 launches when Microsoft Sentinel detects an Azure AD- generated alert. What should you create first?

A.

a repository connection

A.

a repository connection

Answers
B.

a watchlist

B.

a watchlist

Answers
C.

an analytics rule

C.

an analytics rule

Answers
D.

an automation rule

D.

an automation rule

Answers
Suggested answer: D
Total 295 questions
Go to page: of 30