ExamGecko
Home / Microsoft / SC-200 / List of questions
Ask Question

Microsoft SC-200 Practice Test - Questions Answers, Page 20

Add to Whishlist

List of questions

Question 191

Report Export Collapse

HOTSPOT

You have a Microsoft Sentinel workspace

You develop a custom Advanced Security information Model (ASIM) parser named Parser1 that produces a schema named Schema1.

You need to validate Schema1.

How should you complete the command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 191 107944 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 191 107944 10052024010847000
Explanation:

Microsoft SC-200 image Question 57 explanation 107944 10052024010847000000

asked 05/10/2024
Shameez Mohammed
44 questions

Question 192

Report Export Collapse

HOTSPOT

You have a Microsoft Sentinel workspace that has User and Entity Behavior Analytics (UEBA) enabled.

You need to identify all the log entries that relate to security-sensitive user actions performed on a server named Server1. The solution must meet the following requirements:

β€’ Only include security-sensitive actions by users that are NOT members of the IT department.

β€’ Minimize the number of false positives.

How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 192 107945 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 192 107945 10052024010847000
Explanation:

Microsoft SC-200 image Question 58 explanation 107945 10052024010847000000

asked 05/10/2024
SULIMAN ALGHURAIR
41 questions

Question 193

Report Export Collapse

You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server.

You need to configure Defender for Cloud to collect event data from the virtual machines. The solution must minimize administrative effort and costs.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Become a Premium Member for full access
  Unlock Premium Member

Question 194

Report Export Collapse

You have an Azure subscription that use Microsoft Defender for Ctoud and contains a user named User1.

You need to ensure that User1 can modify Microsoft Defender for Cloud security policies. The solution must use the principle of least privilege.

Which role should you assign to User1?

Become a Premium Member for full access
  Unlock Premium Member

Question 195

Report Export Collapse

DRAG DROP

You have an Azure subscription that contains 100 Linux virtual machines.

You need to configure Microsoft Sentinel to collect event logs from the virtual machines.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Become a Premium Member for full access
  Unlock Premium Member

Question 196

Report Export Collapse

You have an Azure subscription that contains an Azure logic app named app1 and a Microsoft Sentinel workspace that has an Azure AD connector. You need to ensure that app1 launches when Microsoft Sentinel detects an Azure AD- generated alert. What should you create first?

Become a Premium Member for full access
  Unlock Premium Member

Question 197

Report Export Collapse

You have an Azure subscription that contains a user named User1.

User1 is assigned an Azure Active Directory Premium Plan 2 license

You need to identify whether the identity of User1 was compromised during the last 90 days.

What should you use?

Become a Premium Member for full access
  Unlock Premium Member

Question 198

Report Export Collapse

You have an Azure subscription that uses Microsoft Defender fof Ctoud.

You have an Amazon Web Services (AWS) account that contains an Amazon Elastic Compute Cloud (EC2) instance named EC2-1.

You need to onboard EC2-1 to Defender for Cloud.

What should you install on EC2-1?

Become a Premium Member for full access
  Unlock Premium Member

Question 199

Report Export Collapse

You have a Microsoft Sentinel workspace named Workspace1 and 200 custom Advanced Security Information Model (ASIM) parsers based on the DNS schema. You need to make the 200 parsers available in Workspace1. The solution must minimize administrative effort. What should you do first?

Become a Premium Member for full access
  Unlock Premium Member

Question 200

Report Export Collapse

You use Microsoft Sentinel.

You need to receive an alert in near real-time whenever Azure Storage account keys are enumerated.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE:

Each correct selection is worth one point

Become a Premium Member for full access
  Unlock Premium Member
Total 323 questions
Go to page: of 33
Search

Related questions