Free SC-200 Exam Braindumps (page: 19)

Page 19 of 79

You have the following advanced hunting query in Microsoft 365 Defender.
You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.
Which two actions should you perform? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.

  1. Create a detection rule.
  2. Create a suppression rule.
  3. Add | order by Timestamp to the query.
  4. Replace DeviceProcessEvents with DeviceNetworkEvents.
  5. Add DeviceId and ReportId to the output of the query.

Answer(s): A,E


Reference:

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules



Your company stores the data of every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant.
Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription.
You deploy Azure Sentinel to a new Azure subscription.
You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions.
Which two actions should you perform? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.

  1. Add the Security Events connector to the Azure Sentinel workspace.
  2. Create a query that uses the workspace expression and the union operator.
  3. Use the alias statement.
  4. Create a query that uses the resource expression and the alias operator.
  5. Add the Azure Sentinel solution to each workspace.

Answer(s): B,E


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants



HOTSPOT
-
You have a Microsoft Sentinel workspace that contains a custom workbook named Workbook1.
You need to create a visual in Workbook1 that will display the logon count for accounts that have logon event IDs of 4624 and 4634.
How should you complete the query? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You are investigating an attacker that is known to use the Microsoft Graph API as an attack vector. The attacker performs the tactics shown the following table.



You need to search for malicious activities in your organization.
Which tactics can you analyze by using the MicrosoftGraphActivityLogs table?

  1. Tactic2 only
  2. Tactic1 and Tactic2 only
  3. Tactic2 and Tactic3 only
  4. Tactic1, Tactic2, and Tactic3

Answer(s): D



Page 19 of 79



Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

Anyah Vincent Ndubuisi commented on December 19, 2024
Microsoft SC 200 SOC, is awesomely good enough for every cybersecurity specialist. Well detailed for freshers also. From Anyah Vincent.Nigeria.
Anonymous
upvote

Vin commented on November 07, 2024
Good content
Anonymous
upvote

Lueng commented on October 21, 2024
Very professional people and accurate study content. I highly recommend.
HONG KONG
upvote

LA commented on October 18, 2024
Hi there, I have scheduled my EXAM and will share my experience if these questions are valid or not.
Anonymous
upvote

Vignesh commented on October 03, 2024
I'm writing next week, are the questions still valid?
CZECH REPUBLIC
upvote

Donjo commented on September 09, 2024
Anyone tried recently. like Sept?
Anonymous
upvote

Ma hari bahadur commented on July 12, 2024
Great passed
UNITED STATES
upvote

Tota commented on July 12, 2024
Nailed it totas
Anonymous
upvote

Heavy Guy commented on July 06, 2024
Just passed this exam.
UNITED STATES
upvote

Patrick commented on June 16, 2024
Very helpful
SWITZERLAND
upvote

Bhagwati commented on June 06, 2024
Exam dumps helped me to get 90% marks.
Anonymous
upvote

Nikhil Jagadale commented on May 10, 2024
Very helpful
INDIA
upvote

Karabo commented on April 11, 2024
Very helpful
SOUTH AFRICA
upvote

CyberThreat commented on March 12, 2024
Thank You for sharing this questions! Nice Job.
BRAZIL
upvote

Anwar commented on February 17, 2024
Thank you for your questions and the wonderful support. The PDF version really helped. Keep up the good work.
Italy
upvote

Balakrishna commented on February 17, 2024
Passed this exam today with a score of 864.
INDIA
upvote

Manish commented on February 17, 2024
Amazing Questions
INDIA
upvote

Kawah commented on February 17, 2024
I sat for my test today. I can confirm that there are about 6 new questions I didn't see in this dumps. The rest was all good.
UNITED STATES
upvote

Mohammed commented on February 17, 2024
I can say that this exam is valid and questions are same as in real exam. Passed my paper today after preparing for 1 week.
United Kingdom
upvote

John commented on January 27, 2024
is this up to date?
Anonymous
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Rebecca commented on October 08, 2023
Very useful material
SOUTH AFRICA
upvote

Rebecca commented on October 08, 2023
Very useful, the exact questions in exam
SOUTH AFRICA
upvote

Jane commented on October 08, 2023
Very useful
SOUTH AFRICA
upvote

bot commented on October 08, 2023
QUESTION: 99 You use Azure Sentinel. You need to use a built-in role to provide a security analyst with the ability to edit the queries of custom Azure Sentinel workbooks. The solution must use the principle of least privilege. Which role should you assign to the analyst? Answer is : Azure Sentinel Contributor (A) but it showing (C) Azure Sentinel Responder - WORNG
INDIA
upvote

bot commented on October 08, 2023
how many question will ask in exam
INDIA
upvote

Mark commented on July 25, 2023
Hi all, where can I find the updated questions
Anonymous
upvote

Yefferic commented on July 19, 2023
very usefull
Anonymous
upvote

Jason commented on July 05, 2023
Total Questions: 156 Exam questions 187 If I buy this dump - will I get 156 questions or 187?
AUSTRALIA
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Percy commented on June 06, 2023
Good dump to study
INDIA
upvote

Alejandro commented on May 30, 2023
This practice exam contained the exact questions and answers that I encountered in the exam. It felt like cheaing! LOL
UNITED KINGDOM
upvote

IRSHAD PASHA commented on May 30, 2023
these questions are absolutely the same what was asked in the exam
Anonymous
upvote

Mihai commented on February 15, 2023
Pass my exam. This question bank has real content from exam.
UNITED STATES
upvote