ExamGecko
Home / Microsoft / SC-200 / List of questions
Ask Question

Microsoft SC-200 Practice Test - Questions Answers, Page 34

Add to Whishlist

List of questions

Question 331

Report Export Collapse

HOTSPOT

You have a Microsoft Sentinel workspace named Workspacel that contains a table named CommonSecurityLog. You ingest logs into CommonSecurityLog. CommonSecurityLog has an average log ingestion time of five minutes.

You need to create an analytics rule that has a lookback period of seven minutes and uses the data in the CommonSecurityLog table. The solution must meet the following requirements:

* Prevent the same event from being processed twice.

* Minimize the number of missed events due to log ingestion delays.

How should you complete the KQL query that defines the rule? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member

Question 332

Report Export Collapse

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Office 365.

You need to build a hunting query that will list events involving potentially malicious emails that were detected but NOT removed successfully from mailboxes after delivery. The solution must ensure that the events are correlated with the sign-in events of the email recipients.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member

Question 333

Report Export Collapse

Your company stores the data of every project in a different Azure subscription. All the subscriptions use the same Microsoft Entra tenant.

Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription.

You deploy Microsoft Sentinel to a new Azure subscription.

You need to perform hunting queries in Microsoft Sentinel to search across all the Log Analytics workspaces of all the subscriptions.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Become a Premium Member for full access
  Unlock Premium Member

Question 334

Report Export Collapse

You have a Microsoft 365 E5 subscription that uses Microsoft Copilot for Security. Copilot for Security has the default settings configured. You need to ensure that a user named User1 can use Copilot for Security to perform the following tasks:

* Upload files.

* View the usage dashboard.

* Share promptbooks with all users.

The solution must follow the principle of least privilege. Which role should you assign to User1?

Become a Premium Member for full access
  Unlock Premium Member

Question 335

Report Export Collapse

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR and contains two users named User1 and User2.

You need to ensure that the users can perform searches by using the Microsoft Purview portal. The solution must meet the following requirements:

* Ensure that User1 can search the Microsoft Purview Audit service logs and review the Microsoft Purview Audit service configuration.

* Ensure that User2 can search Microsoft Exchange Online mailboxes.

* Follow the principle of least privilege.

To which Microsoft Purview role group should you add each user? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Become a Premium Member for full access
  Unlock Premium Member
Total 335 questions
Go to page: of 34

Related questions