ExamGecko
Home Home / Microsoft / SC-200

Microsoft SC-200 Practice Test - Questions Answers, Page 22

Question list
Search
Search

List of questions

Search

Related questions











HOTSPOT

You have a Microsoft Sentinel workspace.

You need to configure a report visual for a custom workbook. The solution must meet the following requirements:

* The count and usage trend of AppDisplayName must be included

* The TrendList column must be useable in a sparkline visual,

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 211
Correct answer: Question 211

HOTSPOT

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365.

You need to identify all the interactive authentication attempts by the users in the finance department of your company.

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 212
Correct answer: Question 212

You have a Microsoft Sentinel workspace that has user and Entity Behavior Analytics (UEBA) enabled for Signin Logs.

You need to ensure that failed interactive sign-ins are detected.

The solution must minimize administrative effort.

What should you use?

A.

a scheduled alert query

A.

a scheduled alert query

Answers
B.

a UEBA activity template

B.

a UEBA activity template

Answers
C.

the Activity Log data connector

C.

the Activity Log data connector

Answers
D.

a hunting query

D.

a hunting query

Answers
Suggested answer: B

You have a Microsoft 365 subscription that uses Microsoft Purview.

Your company has a project named Project1.

You need to identify all the email messages that have the word Project1 in the subject line. The solution must search only the mailboxes of users that worked on Project1.

What should you do?

A.

Create a records management disposition.

A.

Create a records management disposition.

Answers
B.

Perform a user data search.

B.

Perform a user data search.

Answers
C.

Perform an audit search.

C.

Perform an audit search.

Answers
D.

Perform a content search.

D.

Perform a content search.

Answers
Suggested answer: D

DRAG DROP

You have an Azure subscription that contains the users shown in the following table.

You need to delegate the following tasks:

* Enable Microsoft Defender for Servers on virtual machines.

* Review security recommendations and enable server vulnerability scans.

The solution must use the principle of least privilege.

Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Answer:



Question 215
Correct answer: Question 215

You have 50 Microsoft Sentinel workspaces.

You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort.

Which page should you use in the Azure portal?

A.

Microsoft Sentinel - Incidents

A.

Microsoft Sentinel - Incidents

Answers
B.

Microsoft Sentinel - Workbooks

B.

Microsoft Sentinel - Workbooks

Answers
C.

Microsoft Sentinel

C.

Microsoft Sentinel

Answers
D.

Log Analytics workspaces

D.

Log Analytics workspaces

Answers
Suggested answer: D

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint

You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The solution must ensure that you can use the results to initiate device isolation for the affected devices.

What should you use in the Microsoft 365 Defender portal?

A.

Incidents

A.

Incidents

Answers
B.

Investigations

B.

Investigations

Answers
C.

Advanced hunting

C.

Advanced hunting

Answers
D.

Remediation

D.

Remediation

Answers
Suggested answer: A

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint

You need to create a query that will link the Alertlnfo, AlertEvidence, and DeviceLogonEvents tables. The solution must return all the rows in the tables.

Which operator should you use?

A.

join kind = inner

A.

join kind = inner

Answers
B.

evaluate hint. Remote =

B.

evaluate hint. Remote =

Answers
C.

search *

C.

search *

Answers
D.

union kind = inner

D.

union kind = inner

Answers
Suggested answer: A

DRAG DROP

You have a Microsoft 365 E5 subscription that uses Microsoft Exchange Online.

You need to identify phishing email messages.

Which three cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.

Question 219
Correct answer: Question 219

Explanation:

New-ComplianceSearch

Connect-ExchangeOnline

Search-UnifiedAuditLog


You haw the resources shown in the following Table.

You have an Azure subscription that uses Microsoft Defender for Cloud.

You need to enable Microsoft Defender lot Servers on each resource.

Which resources will require the installation of the Azure Arc agent?

A.

Server 3 only

A.

Server 3 only

Answers
B.

Server1 and 5erver4 only

B.

Server1 and 5erver4 only

Answers
C.

Server 1. Server2. arid Server4 only

C.

Server 1. Server2. arid Server4 only

Answers
D.

Server 1, Servec2, Server3. and Seiver4

D.

Server 1, Servec2, Server3. and Seiver4

Answers
Suggested answer: B
Total 295 questions
Go to page: of 30