ExamGecko
Home / Microsoft / SC-200 / List of questions
Ask Question

Microsoft SC-200 Practice Test - Questions Answers, Page 32

Add to Whishlist

List of questions

Question 311

Report Export Collapse

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains a Windows device named Device!.

You initiated a live response session on Device1.

You need to run a command that will download a 250-MB file named File! .exe from the live response library to Device1. The solution must ensure that Filel.exe is downloaded as a background process.

How should you complete the live response command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member

Question 312

Report Export Collapse

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to implement deception rules. The solution must ensure that you can limit the scope of the rules.

What should you create first?

Become a Premium Member for full access
  Unlock Premium Member

Question 313

Report Export Collapse

HOTSPOT

You need to build a KQL query in a Microsoft Sentinel workspace. The query must return the SecurityEvent record for accounts that have the last record with an EventID value of 4624. How should you complete the query' To answer, select the appropriate options in the answer area.

NOTE: Each coned selection is worth one point


Become a Premium Member for full access
  Unlock Premium Member

Question 314

Report Export Collapse

HOTSPOT

You have the resources shown in the following table.

Microsoft SC-200 image Question 180 131736 12042024232725000000

You have an Azure subscription that uses Mictosoft Defender for Cloud.

You need to use Defender for Cloud to protect VM1 and Server1. The solution must meet the following requirements:

* Support Advanced Threat Protection and vulnerability assessment

* Register each SQL Server 2022 instance as a SQL virtual machine.

* Minimize implementation and administrative effort

What should you deploy to each server? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member

Question 315

Report Export Collapse

You have a Microsoft 365 subscription.

You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode. You need to ensure that the devices are protected from malicious artifacts that were undetected by the third-party antivirus product Solution: You enable automated investigation and response (AIR) Does this meet the goal?

Become a Premium Member for full access
  Unlock Premium Member

Question 316

Report Export Collapse

You have 500 on-premises devices.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.

You onboard 100 devices to Microsoft Defender XDR.

You need to identify any unmanaged on-premises devices. The solution must ensure that only specific onboarded devices perform the discovery.

What should you do first?

Become a Premium Member for full access
  Unlock Premium Member

Question 317

Report Export Collapse

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains the devices shown in the following table.

Microsoft SC-200 image Question 183 131739 12042024232725000000

You initiate a live response session on each device.

You need to collect a Defender for Endpoint investigation package from each device.

On which devices can you collect the package by running advanced live response commands from the command-line interface (CLI)?

Become a Premium Member for full access
  Unlock Premium Member

Question 318

Report Export Collapse

HOTSPOT

You have a Microsoft 365 E5 subscription that contains the hosts shown in the following table.

Microsoft SC-200 image Question 184 131740 12042024232725000000

You have indicators in Microsoft Defender for Endpoint as shown in the following table.

D1 and ID2 reference the same tile as ID3

For each of the following statements, select Yes if the statement is true Otherwise, select No.

NOTE: Each correction selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member

Question 319

Report Export Collapse

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.

You need to identify LDAP requests by AD DS users to enumerate AD DS objects.

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member

Question 320

Report Export Collapse

HOTSPOT

You have an Azure subscription that contains a Log Analytics workspace named Workspace1.

You configure Azure activity logs and Microsoft Entra ID logs to be forwarded to Workspace1.

You need to query Workspace1 to identify all the requests that failed due to insufficient authorization.

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member
Total 323 questions
Go to page: of 33
Search

Related questions