ExamGecko
Home Home / Microsoft / SC-200

Microsoft SC-200 Practice Test - Questions Answers, Page 20

Question list
Search
Search

List of questions

Search

Related questions











You need to correlate data from the SecurityEvent Log Anarytks table to meet the Microsoft Sentinel requirements for using UEBA. Which Log Analytics table should you use?

A.

SentwlAuoNt

A.

SentwlAuoNt

Answers
B.

AADRiskyUsers

B.

AADRiskyUsers

Answers
C.

IdentityOirectoryEvents

C.

IdentityOirectoryEvents

Answers
D.

Identityinfo

D.

Identityinfo

Answers
Suggested answer: C

You need to identify which mean time metrics to use to meet the Microsoft Sentinel requirements.

Which workbook should you use?

A.

Analytics Efficiency

A.

Analytics Efficiency

Answers
B.

Security Operations Efficiency

B.

Security Operations Efficiency

Answers
C.

Event Analyzer

C.

Event Analyzer

Answers
D.

Investigation insights

D.

Investigation insights

Answers
Suggested answer: C

You need to meet the Microsoft Sentinel requirements for App1. What should you configure for App1?

A.

an API connection

A.

an API connection

Answers
B.

a trigger

B.

a trigger

Answers
C.

an connector

C.

an connector

Answers
D.

authorization

D.

authorization

Answers
Suggested answer: B

HOTSPOT

You need to meet the Microsoft Sentinel requirements for collecting Windows Security event logs.

What should you do? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point.


Question 194
Correct answer: Question 194

HOTSPOT

You have 100 Azure subscriptions that have enhanced security features m Microsoft Defender for Cloud enabled. All the subscriptions are linked to a single Azure AD tenant. You need to stream the Defender for Cloud togs to a syslog server. The solution must minimize administrative effort What should you do? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point


Question 195
Correct answer: Question 195

HOTSPOT

You have a Microsoft 365 E5 subscription that contains two users named User! and User2. You have the hunting query shown in the following exhibit.

The users perform the following anions:

• User1 assigns User2 the Global administrator role.

• User1 creates a new user named User3 and assigns the user a Microsoft Teams license.

• User2 creates a new user named User4 and assigns the user the Security reader role.

• User2 creates a new user named User5 and assigns the user the Security operator role.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.


Question 196
Correct answer: Question 196

You have an Azure subscription that uses resource type for Cloud. You need to filter the security alerts view to show the following alerts:

• Unusual user accessed a key vault

• Log on from an unusual location

• Impossible travel activity

Which severity should you use?

A.

Informational

A.

Informational

Answers
B.

Low

B.

Low

Answers
C.

Medium

C.

Medium

Answers
D.

High

D.

High

Answers
Suggested answer: C

Explanation:


HOTSPOT

You need to implement Microsoft Sentinel queries for Contoso and Fabrikam to meet the technical requirements.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 198
Correct answer: Question 198

Explanation:


HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft 365 Defender for Endpoint.

You need to ensure that you can initiate remote shell connections to Windows servers by using the Microsoft 365 Defender portal.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 199
Correct answer: Question 199

You have an Azure subscription that contains an Microsoft Sentinel workspace.

You need to create a playbook that will run automatically in response to an Microsoft Sentinel alert.

What should you create first?

A.

a trigger in Azure Functions

A.

a trigger in Azure Functions

Answers
B.

an Azure logic app

B.

an Azure logic app

Answers
C.

a hunting query in Microsoft Sentinel

C.

a hunting query in Microsoft Sentinel

Answers
D.

an automation rule in Microsoft Sentinel

D.

an automation rule in Microsoft Sentinel

Answers
Suggested answer: D
Total 295 questions
Go to page: of 30