Free SC-200 Exam Braindumps (page: 30)

Page 30 of 79

You receive a security bulletin about a potential attack that uses an image file.
You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent the attack.
Which indicator type should you use?

  1. a URL/domain indicator that has Action set to Alert only
  2. a URL/domain indicator that has Action set to Alert and block
  3. a file hash indicator that has Action set to Alert and block
  4. a certificate indicator that has Action set to Alert and block

Answer(s): C


Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/indicator-file?view=o365-worldwide



HOTSPOT (Drag and Drop is not supported).
You use Azure Sentinel to monitor irregular Azure activity.
You create custom analytics rules to detect threats as shown in the following exhibit.
You do NOT define any incident settings as part of the rule definition.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom



You have a Microsoft 365 E5 subscription.
Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for Endpoint.
You have an incident involving a user that received malware-infected email messages on a managed device.
Which action requires manual remediation of the incident?

  1. soft deleting the email message
  2. hard deleting the email message
  3. isolating the device
  4. containing the device

Answer(s): C



You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
The security team at your company detects command and control (C2) agent traffic on the network. Agents communicate once every 50 hours.
You need to create a Microsoft Defender XDR custom detection rule that will identify compromised devices and establish a pattern of communication. The solution must meet the following requirements:
• Identify all the devices that have communicated during the past 14 days.
• Minimize how long it takes to identify the devices.
To what should you set the detection frequency for the rule?

  1. Every 12 hours
  2. Every 24 hours
  3. Every three hours
  4. Every hour

Answer(s): A



Page 30 of 79



Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

Anyah Vincent Ndubuisi commented on December 19, 2024
Microsoft SC 200 SOC, is awesomely good enough for every cybersecurity specialist. Well detailed for freshers also. From Anyah Vincent.Nigeria.
Anonymous
upvote

Vin commented on November 07, 2024
Good content
Anonymous
upvote

Lueng commented on October 21, 2024
Very professional people and accurate study content. I highly recommend.
HONG KONG
upvote

LA commented on October 18, 2024
Hi there, I have scheduled my EXAM and will share my experience if these questions are valid or not.
Anonymous
upvote

Vignesh commented on October 03, 2024
I'm writing next week, are the questions still valid?
CZECH REPUBLIC
upvote

Donjo commented on September 09, 2024
Anyone tried recently. like Sept?
Anonymous
upvote

Ma hari bahadur commented on July 12, 2024
Great passed
UNITED STATES
upvote

Tota commented on July 12, 2024
Nailed it totas
Anonymous
upvote

Heavy Guy commented on July 06, 2024
Just passed this exam.
UNITED STATES
upvote

Patrick commented on June 16, 2024
Very helpful
SWITZERLAND
upvote

Bhagwati commented on June 06, 2024
Exam dumps helped me to get 90% marks.
Anonymous
upvote

Nikhil Jagadale commented on May 10, 2024
Very helpful
INDIA
upvote

Karabo commented on April 11, 2024
Very helpful
SOUTH AFRICA
upvote

CyberThreat commented on March 12, 2024
Thank You for sharing this questions! Nice Job.
BRAZIL
upvote

Anwar commented on February 17, 2024
Thank you for your questions and the wonderful support. The PDF version really helped. Keep up the good work.
Italy
upvote

Balakrishna commented on February 17, 2024
Passed this exam today with a score of 864.
INDIA
upvote

Manish commented on February 17, 2024
Amazing Questions
INDIA
upvote

Kawah commented on February 17, 2024
I sat for my test today. I can confirm that there are about 6 new questions I didn't see in this dumps. The rest was all good.
UNITED STATES
upvote

Mohammed commented on February 17, 2024
I can say that this exam is valid and questions are same as in real exam. Passed my paper today after preparing for 1 week.
United Kingdom
upvote

John commented on January 27, 2024
is this up to date?
Anonymous
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Rebecca commented on October 08, 2023
Very useful material
SOUTH AFRICA
upvote

Rebecca commented on October 08, 2023
Very useful, the exact questions in exam
SOUTH AFRICA
upvote

Jane commented on October 08, 2023
Very useful
SOUTH AFRICA
upvote

bot commented on October 08, 2023
QUESTION: 99 You use Azure Sentinel. You need to use a built-in role to provide a security analyst with the ability to edit the queries of custom Azure Sentinel workbooks. The solution must use the principle of least privilege. Which role should you assign to the analyst? Answer is : Azure Sentinel Contributor (A) but it showing (C) Azure Sentinel Responder - WORNG
INDIA
upvote

bot commented on October 08, 2023
how many question will ask in exam
INDIA
upvote

Mark commented on July 25, 2023
Hi all, where can I find the updated questions
Anonymous
upvote

Yefferic commented on July 19, 2023
very usefull
Anonymous
upvote

Jason commented on July 05, 2023
Total Questions: 156 Exam questions 187 If I buy this dump - will I get 156 questions or 187?
AUSTRALIA
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Percy commented on June 06, 2023
Good dump to study
INDIA
upvote

Alejandro commented on May 30, 2023
This practice exam contained the exact questions and answers that I encountered in the exam. It felt like cheaing! LOL
UNITED KINGDOM
upvote

IRSHAD PASHA commented on May 30, 2023
these questions are absolutely the same what was asked in the exam
Anonymous
upvote

Mihai commented on February 15, 2023
Pass my exam. This question bank has real content from exam.
UNITED STATES
upvote