ExamGecko
Home / Microsoft / SC-200 / List of questions
Ask Question

Microsoft SC-200 Practice Test - Questions Answers, Page 8

Add to Whishlist

List of questions

Question 71

Report Export Collapse

You receive a security bulletin about a potential attack that uses an image file.

You need to create an indicator of compromise (loC) in Microsoft Defender for Endpoint to prevent the attack.

Which indicator type should you use?

a URL/domain indicator that has Action set to Alert only

a URL/domain indicator that has Action set to Alert only

a URL/domain indicator that has Action set to Alert and block

a URL/domain indicator that has Action set to Alert and block

a file hash indicator that has Action set to Alert and block

a file hash indicator that has Action set to Alert and block

a certificate indicator that has Action set to Alert and block

a certificate indicator that has Action set to Alert and block

Suggested answer: C
Explanation:

Reference:

https://docs.microsoft.eom/en-us/microsoft-365/securitv/defender-endpoint/i nd icator-file?view=o365-worldwide

asked 05/10/2024
Jari Tetteroo
47 questions

Question 72

Report Export Collapse

Your company deploys the following services:

Microsoft Defender for Identity

Microsoft Defender for Endpoint

Microsoft Defender for Office 365

You need to provide a security analyst with the ability to use the Microsoft 365 security center. The analyst must be able to approve and reject pending actions generated by Microsoft Defender for Endpoint. The solution must use the principle of least privilege.

Which two roles should assign to the analyst? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

the Compliance Data Administrator in Azure Active Directory (Azure AD)

the Compliance Data Administrator in Azure Active Directory (Azure AD)

the Active remediation actions role in Microsoft Defender for Endpoint

the Active remediation actions role in Microsoft Defender for Endpoint

the Security Administrator role in Azure Active Directory (Azure AD)

the Security Administrator role in Azure Active Directory (Azure AD)

the Security Reader role in Azure Active Directory (Azure AD)

the Security Reader role in Azure Active Directory (Azure AD)

Suggested answer: B, D
Explanation:

Reference:

https://docs.mic rosoft. co m/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide

asked 05/10/2024
Tom SÀll
42 questions

Question 73

Report Export Collapse

DRAG DROP

You are investigating an incident by using Microsoft 365 Defender.

You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop, CEOLaptop, and COOLaptop.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 73 107787 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 73 107787 10052024010847000
asked 05/10/2024
Azahar Basri
29 questions

Question 74

Report Export Collapse

DRAG DROP

You open the Cloud App Security portal as shown in the following exhibit.

Microsoft SC-200 image Question 14 107788 10052024010847000000

Your environment does NOT have Microsoft Defender for Endpoint enabled.

You need to remediate the risk for the Launchpad app.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Microsoft SC-200 image Question 74 107788 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 74 107788 10052024010847000
Explanation:

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/governance-discovery

asked 05/10/2024
Ali Alaqoul
41 questions

Question 75

Report Export Collapse

HOTSPOT

You have a Microsoft 365 E5 subscription.

You plan to perform cross-domain investigations by using Microsoft 365 Defender.

You need to create an advanced hunting query to identify devices affected by a malicious email attachment.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 75 107789 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 75 107789 10052024010847000
Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/mtp/advanced-hunting-query-emails-devices?view=o365-worldwide

asked 05/10/2024
Alvaro Campos
42 questions

Question 76

Report Export Collapse

HOTSPOT

You are informed of an increase in malicious email being received by users.

You need to create an advanced hunting query in Microsoft 365 Defender to identify whether the accounts of the email recipients were compromised. The query must return the most recent 20 sign-ins performed by the recipients within an hour of receiving the known malicious email.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 76 107790 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 76 107790 10052024010847000
Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-emails-devices?view=o365-worldwide

asked 05/10/2024
Tarnauceanu Diana
44 questions

Question 77

Report Export Collapse

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Defender and an Azure subscription that uses Azure Sentinel.

You need to identify all the devices that contain files in emails sent by a known malicious email sender. The query will be based on the match of the SHA256 hash.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 77 107791 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 77 107791 10052024010847000
Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-emails-devices?view=o365-worldwide

asked 05/10/2024
Shivanth Jha
43 questions

Question 78

Report Export Collapse

You need to configure Microsoft Cloud App Security to generate alerts and trigger remediation actions in response to external sharing of confidential files.

Which two actions should you perform in the Cloud App Security portal? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant.

From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant.

Select Investigate files, and then filter App to Office 365.

Select Investigate files, and then filter App to Office 365.

Select Investigate files, and then select New policy from search.

Select Investigate files, and then select New policy from search.

From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings.

From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings.

From Settings, select Information Protection, select Files, and then enable file monitoring.

From Settings, select Information Protection, select Files, and then enable file monitoring.

Select Investigate files, and then filter File Type to Document.

Select Investigate files, and then filter File Type to Document.

Suggested answer: D, E
Explanation:

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/tutorial-dlp

https://docs.microsoft.com/en-us/cloud-app-security/azip-integration

asked 05/10/2024
Arnaldo Martinez 2-30793
48 questions

Question 79

Report Export Collapse

HOTSPOT

You purchase a Microsoft 365 subscription.

You plan to configure Microsoft Cloud App Security.

You need to create a custom template-based policy that detects connections to Microsoft 365 apps that originate from a botnet network.

What should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft SC-200 image Question 79 107793 10052024010847000
Correct answer: Microsoft SC-200 image answer Question 79 107793 10052024010847000
Explanation:

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/anomaly-detection-policy

asked 05/10/2024
Edward Morgan
44 questions

Question 80

Report Export Collapse

Your company has a single office in Istanbul and a Microsoft 365 subscription.

The company plans to use conditional access policies to enforce multi-factor authentication (MFA).

You need to enforce MFA for all users who work remotely.

What should you include in the solution?

a fraud alert

a fraud alert

a user risk policy

a user risk policy

a named location

a named location

a sign-in user policy

a sign-in user policy

Suggested answer: C
Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition

asked 05/10/2024
Susan Brady
52 questions
Total 323 questions
Go to page: of 33
Search

Related questions