ExamGecko
Home Home / Microsoft / SC-200

Microsoft SC-200 Practice Test - Questions Answers, Page 19

Question list
Search
Search

List of questions

Search

Related questions











You have an Azure subscription that contains a user named User1.

User1 is assigned an Azure Active Directory Premium Plan 2 license

You need to identify whether the identity of User1 was compromised during the last 90 days.

What should you use?

A.

the risk detections report

A.

the risk detections report

Answers
B.

the risky users report

B.

the risky users report

Answers
C.

Identity Secure Score recommendations

C.

Identity Secure Score recommendations

Answers
D.

the risky sign-ins report

D.

the risky sign-ins report

Answers
Suggested answer: B

You have an Azure subscription that uses Microsoft Defender fof Ctoud.

You have an Amazon Web Services (AWS) account that contains an Amazon Elastic Compute Cloud (EC2) instance named EC2-1.

You need to onboard EC2-1 to Defender for Cloud.

What should you install on EC2-1?

A.

the Log Analytics agent

A.

the Log Analytics agent

Answers
B.

the Azure Connected Machine agent

B.

the Azure Connected Machine agent

Answers
C.

the unified Microsoft Defender for Endpoint solution package

C.

the unified Microsoft Defender for Endpoint solution package

Answers
D.

Microsoft Monitoring Agent

D.

Microsoft Monitoring Agent

Answers
Suggested answer: A

You have a Microsoft Sentinel workspace named Workspace1 and 200 custom Advanced Security Information Model (ASIM) parsers based on the DNS schema. You need to make the 200 parsers available in Workspace1. The solution must minimize administrative effort. What should you do first?

A.

Copy the parsers to the Azure Monitor Logs page.

A.

Copy the parsers to the Azure Monitor Logs page.

Answers
B.

Create a JSON file based on the DNS template.

B.

Create a JSON file based on the DNS template.

Answers
C.

Create an XML file based on the DNS template.

C.

Create an XML file based on the DNS template.

Answers
D.

Create a YAML file based on the DNS template.

D.

Create a YAML file based on the DNS template.

Answers
Suggested answer: A

Explanation:


You use Microsoft Sentinel.

You need to receive an alert in near real-time whenever Azure Storage account keys are enumerated.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE:

Each correct selection is worth one point

A.

Create a bookmark.

A.

Create a bookmark.

Answers
B.

Create an analytics rule.

B.

Create an analytics rule.

Answers
C.

Create a livestream.

C.

Create a livestream.

Answers
D.

Create a hunting query.

D.

Create a hunting query.

Answers
E.

Add a data connector.

E.

Add a data connector.

Answers
Suggested answer: D, E

You need to minimize the effort required to investigate the Microsoft Defender for Identity false positive alerts. What should you review?

A.

the status update time

A.

the status update time

Answers
B.

the alert status

B.

the alert status

Answers
C.

the certainty of the source computer

C.

the certainty of the source computer

Answers
D.

the resolution method of the source computer

D.

the resolution method of the source computer

Answers
Suggested answer: B

HOTSPOT

You need to meet the Microsoft Defender for Cloud Apps requirements

What should you do? To answer. select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 186
Correct answer: Question 186

You need to deploy the native cloud connector to Account! to meet the Microsoft Defender for Cloud requirements. What should you do in Account! first?

A.

Create an AWS user for Defender for Cloud.

A.

Create an AWS user for Defender for Cloud.

Answers
B.

Create an Access control (1AM) role for Defender for Cloud.

B.

Create an Access control (1AM) role for Defender for Cloud.

Answers
C.

Configure AWS Security Hub.

C.

Configure AWS Security Hub.

Answers
D.

Deploy the AWS Systems Manager (SSM) agent

D.

Deploy the AWS Systems Manager (SSM) agent

Answers
Suggested answer: D

HOTSPOT

You need to create a query to investigate DNS-related activity. The solution must meet the Microsoft Sentinel requirements. How should you complete the Query? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.


Question 188
Correct answer: Question 188

Explanation:

HOTSPOT

You need to assign role-based access control (RBAQ roles to Group1 and Group2 to meet The Microsoft Defender for Cloud requirements and the business requirements Which role should you assign to each group? To answer, select the appropriate options in the answer area NOTE Eachcorrect selection is worth one point.


Question 189
Correct answer: Question 189

You need to ensure that you can run hunting queries to meet the Microsoft Sentinel requirements.

Which type of workspace should you create?

A.

Azure Synapse AnarytKS

A.

Azure Synapse AnarytKS

Answers
B.

AzureDalabricks

B.

AzureDalabricks

Answers
C.

Azure Machine Learning

C.

Azure Machine Learning

Answers
D.

LogAnalytics

D.

LogAnalytics

Answers
Suggested answer: D
Total 295 questions
Go to page: of 30