ExamGecko
Home Home / Microsoft / SC-200

Microsoft SC-200 Practice Test - Questions Answers, Page 8

Question list
Search
Search

List of questions

Search

Related questions











You receive a security bulletin about a potential attack that uses an image file.

You need to create an indicator of compromise (loC) in Microsoft Defender for Endpoint to prevent the attack.

Which indicator type should you use?

A.

a URL/domain indicator that has Action set to Alert only

A.

a URL/domain indicator that has Action set to Alert only

Answers
B.

a URL/domain indicator that has Action set to Alert and block

B.

a URL/domain indicator that has Action set to Alert and block

Answers
C.

a file hash indicator that has Action set to Alert and block

C.

a file hash indicator that has Action set to Alert and block

Answers
D.

a certificate indicator that has Action set to Alert and block

D.

a certificate indicator that has Action set to Alert and block

Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.eom/en-us/microsoft-365/securitv/defender-endpoint/i nd icator-file?view=o365-worldwide

Your company deploys the following services:

Microsoft Defender for Identity

Microsoft Defender for Endpoint

Microsoft Defender for Office 365

You need to provide a security analyst with the ability to use the Microsoft 365 security center. The analyst must be able to approve and reject pending actions generated by Microsoft Defender for Endpoint. The solution must use the principle of least privilege.

Which two roles should assign to the analyst? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

the Compliance Data Administrator in Azure Active Directory (Azure AD)

A.

the Compliance Data Administrator in Azure Active Directory (Azure AD)

Answers
B.

the Active remediation actions role in Microsoft Defender for Endpoint

B.

the Active remediation actions role in Microsoft Defender for Endpoint

Answers
C.

the Security Administrator role in Azure Active Directory (Azure AD)

C.

the Security Administrator role in Azure Active Directory (Azure AD)

Answers
D.

the Security Reader role in Azure Active Directory (Azure AD)

D.

the Security Reader role in Azure Active Directory (Azure AD)

Answers
Suggested answer: B, D

Explanation:

Reference:

https://docs.mic rosoft. co m/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide

DRAG DROP

You are investigating an incident by using Microsoft 365 Defender.

You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop, CEOLaptop, and COOLaptop.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 73
Correct answer: Question 73

DRAG DROP

You open the Cloud App Security portal as shown in the following exhibit.

Your environment does NOT have Microsoft Defender for Endpoint enabled.

You need to remediate the risk for the Launchpad app.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Question 74
Correct answer: Question 74

Explanation:

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/governance-discovery

HOTSPOT

You have a Microsoft 365 E5 subscription.

You plan to perform cross-domain investigations by using Microsoft 365 Defender.

You need to create an advanced hunting query to identify devices affected by a malicious email attachment.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 75
Correct answer: Question 75

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/mtp/advanced-hunting-query-emails-devices?view=o365-worldwide

HOTSPOT

You are informed of an increase in malicious email being received by users.

You need to create an advanced hunting query in Microsoft 365 Defender to identify whether the accounts of the email recipients were compromised. The query must return the most recent 20 sign-ins performed by the recipients within an hour of receiving the known malicious email.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 76
Correct answer: Question 76

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-emails-devices?view=o365-worldwide

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Defender and an Azure subscription that uses Azure Sentinel.

You need to identify all the devices that contain files in emails sent by a known malicious email sender. The query will be based on the match of the SHA256 hash.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 77
Correct answer: Question 77

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-emails-devices?view=o365-worldwide

You need to configure Microsoft Cloud App Security to generate alerts and trigger remediation actions in response to external sharing of confidential files.

Which two actions should you perform in the Cloud App Security portal? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant.

A.

From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant.

Answers
B.

Select Investigate files, and then filter App to Office 365.

B.

Select Investigate files, and then filter App to Office 365.

Answers
C.

Select Investigate files, and then select New policy from search.

C.

Select Investigate files, and then select New policy from search.

Answers
D.

From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings.

D.

From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings.

Answers
E.

From Settings, select Information Protection, select Files, and then enable file monitoring.

E.

From Settings, select Information Protection, select Files, and then enable file monitoring.

Answers
F.

Select Investigate files, and then filter File Type to Document.

F.

Select Investigate files, and then filter File Type to Document.

Answers
Suggested answer: D, E

Explanation:

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/tutorial-dlp

https://docs.microsoft.com/en-us/cloud-app-security/azip-integration

HOTSPOT

You purchase a Microsoft 365 subscription.

You plan to configure Microsoft Cloud App Security.

You need to create a custom template-based policy that detects connections to Microsoft 365 apps that originate from a botnet network.

What should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 79
Correct answer: Question 79

Explanation:

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/anomaly-detection-policy

Your company has a single office in Istanbul and a Microsoft 365 subscription.

The company plans to use conditional access policies to enforce multi-factor authentication (MFA).

You need to enforce MFA for all users who work remotely.

What should you include in the solution?

A.

a fraud alert

A.

a fraud alert

Answers
B.

a user risk policy

B.

a user risk policy

Answers
C.

a named location

C.

a named location

Answers
D.

a sign-in user policy

D.

a sign-in user policy

Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition

Total 295 questions
Go to page: of 30