ExamGecko
Home / Microsoft / SC-200 / List of questions
Ask Question

Microsoft SC-200 Practice Test - Questions Answers, Page 21

List of questions

Question 201

Report
Export
Collapse

You have a Microsoft Sentinel workspace.

You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant:

* App name: App1

* IP address: 192.168.1.2

* Computer name: Device1

* Used client app: Microsoft Edge

* Email address: [email protected]

* Sign-in URL: https://www.company.com

Which entities can be investigated by using UEBA?

app name, computer name, IP address, email address, and used client app only

app name, computer name, IP address, email address, and used client app only

IP address and email address only

IP address and email address only

used client app and app name only

used client app and app name only

IP address only

IP address only

Suggested answer: D
asked 05/10/2024
Vipulkumar Shukal
37 questions

Question 202

Report
Export
Collapse

You have a Microsoft 365 subscription. The subscription uses Microsoft 365 Defender and has data loss prevention (DLP) policies that have aggregated alerts configured.

You need to identify the impacted entities in an aggregated alert.

What should you review in the DIP alert management dashboard of the Microsoft Purview compliance portal?

the Details tab of the alert

the Details tab of the alert

Management log

Management log

the Sensitive Info Types tab of the alert

the Sensitive Info Types tab of the alert

the Events tab of the alert

the Events tab of the alert

Suggested answer: B
asked 05/10/2024
Louis Perriot
42 questions

Question 203

Report
Export
Collapse

DRAG DROP

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant.

You have a Microsoft Sentinel workspace named Sentinel1.

You need to enable User and Entity Behavior Analytics (UEBA) for Sentinel1 and collect security events from the AD DS domain.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Microsoft SC-200 image Question 203 107972 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 203 107972 10052024010847000

Explanation:

To the AD DS domain, deploy Microsoft Defender for Identity.

For Sentinel1, configure the Microsoft Defender for Indentity connector.

For Sentinel1, enable UEBA.


asked 05/10/2024
Swapnil Salunke
39 questions

Question 204

Report
Export
Collapse

DRAG DROP

You have an Azure subscription.

You need to delegate permissions to meet the following requirements:

* Enable and disable advanced features of Microsoft Defender for Cloud.

* Apply security recommendations to a resource.

The solution must use the principle of least privilege.

Which Microsoft Defender for Cloud role should you use for each requirement? To answer, drag the appropriate roles to the correct requirements. Each role may be used once, mote than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Microsoft SC-200 image Question 86 107973 10052024010847000000

Answer:

Microsoft SC-200 image Question 86 107973 10052024010847000000

Microsoft SC-200 image Question 204 107973 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 204 107973 10052024010847000
asked 05/10/2024
Elena Albu
38 questions

Question 205

Report
Export
Collapse

You have an Azure subscription that uses Microsoft Defender for Cloud.

You have a GitHub account named Account1 that contains 10 repositories.

You need to ensure that Defender for Cloud can assess the repositories in Account1.

What should you do first in the Microsoft Defender for Cloud portal?

Add an environment.

Add an environment.

Enable security policies.

Enable security policies.

Enable integrations.

Enable integrations.

Enable a plan.

Enable a plan.

Suggested answer: A
asked 05/10/2024
Brandon Walters
36 questions

Question 206

Report
Export
Collapse

You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1.

You enable agentless scanning.

You need to prevent Server1 from being scanned. The solution must minimize administrative effort.

What should you do?

Create an exclusion tag.

Create an exclusion tag.

Upgrade the subscription to Defender for Servers Plan 2.

Upgrade the subscription to Defender for Servers Plan 2.

Create a governance rule.

Create a governance rule.

Create an exclusion group.

Create an exclusion group.

Suggested answer: D
asked 05/10/2024
Channa Leang
39 questions

Question 207

Report
Export
Collapse

HOTSPOT

You have a Microsoft Sentinel workspace named sws1.

You plan to create an Azure logic app that will raise an incident in an on-premises IT service management system when an incident is generated in sws1.

You need to configure the Microsoft Sentinel connector credentials for the logic app. The solution must meet the following requirements:

* Minimize administrative effort.

* Use the principle of least privilege.

How should you configure the credentials? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 207 107976 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 207 107976 10052024010847000
asked 05/10/2024
Ahmed Khalifa
47 questions

Question 208

Report
Export
Collapse

HOTSPOT

You have a Microsoft Sentinel workspace named sws1.

You need to create a query that will detect when a user creates an unusually large numbers of Azure AD user accounts.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 208 107977 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 208 107977 10052024010847000
asked 05/10/2024
Mike Rachuj
34 questions

Question 209

Report
Export
Collapse

HOTSPOT

You have an Azure subscription that contains a quest user named Userl and a Microsoft Sentinel workspace named workspacel.

You need to ensure that User1 can triage Microsoft Sentinel incidents in workspace1. The solution must use the principle of least privilege.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 209 107978 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 209 107978 10052024010847000
asked 05/10/2024
Nivenl Surnder
33 questions

Question 210

Report
Export
Collapse

HOTSPOT

You have a custom detection rule that includes the following KQL query.

Microsoft SC-200 image Question 92 107979 10052024010847000000

For each of the following statements, select Yes if True. Otherwise select No.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 210 107979 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 210 107979 10052024010847000
asked 05/10/2024
Aaron Whitlow
32 questions
Total 307 questions
Go to page: of 31
Search

Related questions