ExamGecko
Home Home / Microsoft / SC-200

Microsoft SC-200 Practice Test - Questions Answers, Page 21

Question list
Search
Search

List of questions

Search

Related questions











You have a Microsoft Sentinel workspace.

You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant:

* App name: App1

* IP address: 192.168.1.2

* Computer name: Device1

* Used client app: Microsoft Edge

* Email address: [email protected]

* Sign-in URL: https://www.company.com

Which entities can be investigated by using UEBA?

A.

app name, computer name, IP address, email address, and used client app only

A.

app name, computer name, IP address, email address, and used client app only

Answers
B.

IP address and email address only

B.

IP address and email address only

Answers
C.

used client app and app name only

C.

used client app and app name only

Answers
D.

IP address only

D.

IP address only

Answers
Suggested answer: D

You have a Microsoft 365 subscription. The subscription uses Microsoft 365 Defender and has data loss prevention (DLP) policies that have aggregated alerts configured.

You need to identify the impacted entities in an aggregated alert.

What should you review in the DIP alert management dashboard of the Microsoft Purview compliance portal?

A.

the Details tab of the alert

A.

the Details tab of the alert

Answers
B.

Management log

B.

Management log

Answers
C.

the Sensitive Info Types tab of the alert

C.

the Sensitive Info Types tab of the alert

Answers
D.

the Events tab of the alert

D.

the Events tab of the alert

Answers
Suggested answer: B

DRAG DROP

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant.

You have a Microsoft Sentinel workspace named Sentinel1.

You need to enable User and Entity Behavior Analytics (UEBA) for Sentinel1 and collect security events from the AD DS domain.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Question 203
Correct answer: Question 203

Explanation:

To the AD DS domain, deploy Microsoft Defender for Identity.

For Sentinel1, configure the Microsoft Defender for Indentity connector.

For Sentinel1, enable UEBA.


DRAG DROP

You have an Azure subscription.

You need to delegate permissions to meet the following requirements:

* Enable and disable advanced features of Microsoft Defender for Cloud.

* Apply security recommendations to a resource.

The solution must use the principle of least privilege.

Which Microsoft Defender for Cloud role should you use for each requirement? To answer, drag the appropriate roles to the correct requirements. Each role may be used once, mote than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Answer:

Question 204
Correct answer: Question 204

You have an Azure subscription that uses Microsoft Defender for Cloud.

You have a GitHub account named Account1 that contains 10 repositories.

You need to ensure that Defender for Cloud can assess the repositories in Account1.

What should you do first in the Microsoft Defender for Cloud portal?

A.

Add an environment.

A.

Add an environment.

Answers
B.

Enable security policies.

B.

Enable security policies.

Answers
C.

Enable integrations.

C.

Enable integrations.

Answers
D.

Enable a plan.

D.

Enable a plan.

Answers
Suggested answer: A

You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1.

You enable agentless scanning.

You need to prevent Server1 from being scanned. The solution must minimize administrative effort.

What should you do?

A.

Create an exclusion tag.

A.

Create an exclusion tag.

Answers
B.

Upgrade the subscription to Defender for Servers Plan 2.

B.

Upgrade the subscription to Defender for Servers Plan 2.

Answers
C.

Create a governance rule.

C.

Create a governance rule.

Answers
D.

Create an exclusion group.

D.

Create an exclusion group.

Answers
Suggested answer: D

HOTSPOT

You have a Microsoft Sentinel workspace named sws1.

You plan to create an Azure logic app that will raise an incident in an on-premises IT service management system when an incident is generated in sws1.

You need to configure the Microsoft Sentinel connector credentials for the logic app. The solution must meet the following requirements:

* Minimize administrative effort.

* Use the principle of least privilege.

How should you configure the credentials? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 207
Correct answer: Question 207

HOTSPOT

You have a Microsoft Sentinel workspace named sws1.

You need to create a query that will detect when a user creates an unusually large numbers of Azure AD user accounts.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 208
Correct answer: Question 208

HOTSPOT

You have an Azure subscription that contains a quest user named Userl and a Microsoft Sentinel workspace named workspacel.

You need to ensure that User1 can triage Microsoft Sentinel incidents in workspace1. The solution must use the principle of least privilege.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 209
Correct answer: Question 209

HOTSPOT

You have a custom detection rule that includes the following KQL query.

For each of the following statements, select Yes if True. Otherwise select No.

NOTE: Each correct selection is worth one point.


Question 210
Correct answer: Question 210
Total 295 questions
Go to page: of 30