Free SC-200 Exam Braindumps (page: 41)

Page 41 of 79

You have a Microsoft Sentinel workspace.
You are investigating an incident that involves multiple alerts, events, and entities.
You need to create a bookmark for the investigation. The solution must minimize administrative effort.
Which settings should you use?

  1. Incidents
  2. Hunting
  3. Content hub
  4. Logs

Answer(s): A



HOTSPOT (Drag and Drop is not supported).
You have a Microsoft 365 E5 subscription that contains 200 Windows 10 devices enrolled in Microsoft Defender for Endpoint.
You need to ensure that users can access the devices by using a remote shell connection directly from the Microsoft 365 Defender portal. The solution must use the principle of least privilege.
What should you do in the Microsoft 365 Defender portal? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: Turn on Live Response -
Live response is a capability that gives you instantaneous access to a device by using a remote shell connection. This gives you the power to do in-depth investigative work and take immediate response actions.
Box: 2 -
Network assessment jobs allow you to choose network devices to be scanned regularly and added to the device inventory.


Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-machine-alerts?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-devices?view=o365-worldwide



You are investigating an incident in Azure Sentinel that contains more than 127 alerts.
You discover eight alerts in the incident that require further investigation.
You need to escalate the alerts to another Azure Sentinel administrator.
What should you do to provide the alerts to the administrator?

  1. Create a Microsoft incident creation rule
  2. Share the incident URL
  3. Create a scheduled query rule
  4. Assign the incident

Answer(s): D


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/investigate-cases



You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled.
You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1.
What should you do first?

  1. From Azure Security Center, add a workflow automation.
  2. On VM1, run the Get-MPThreatCatalog cmdlet.
  3. On VM1 trigger a PowerShell alert.
  4. From Azure Security Center, export the alerts to a Log Analytics workspace.

Answer(s): C


Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-alerts?view=o365-worldwide



Page 41 of 79



Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

Anyah Vincent Ndubuisi commented on December 19, 2024
Microsoft SC 200 SOC, is awesomely good enough for every cybersecurity specialist. Well detailed for freshers also. From Anyah Vincent.Nigeria.
Anonymous
upvote

Vin commented on November 07, 2024
Good content
Anonymous
upvote

Lueng commented on October 21, 2024
Very professional people and accurate study content. I highly recommend.
HONG KONG
upvote

LA commented on October 18, 2024
Hi there, I have scheduled my EXAM and will share my experience if these questions are valid or not.
Anonymous
upvote

Vignesh commented on October 03, 2024
I'm writing next week, are the questions still valid?
CZECH REPUBLIC
upvote

Donjo commented on September 09, 2024
Anyone tried recently. like Sept?
Anonymous
upvote

Ma hari bahadur commented on July 12, 2024
Great passed
UNITED STATES
upvote

Tota commented on July 12, 2024
Nailed it totas
Anonymous
upvote

Heavy Guy commented on July 06, 2024
Just passed this exam.
UNITED STATES
upvote

Patrick commented on June 16, 2024
Very helpful
SWITZERLAND
upvote

Bhagwati commented on June 06, 2024
Exam dumps helped me to get 90% marks.
Anonymous
upvote

Nikhil Jagadale commented on May 10, 2024
Very helpful
INDIA
upvote

Karabo commented on April 11, 2024
Very helpful
SOUTH AFRICA
upvote

CyberThreat commented on March 12, 2024
Thank You for sharing this questions! Nice Job.
BRAZIL
upvote

Anwar commented on February 17, 2024
Thank you for your questions and the wonderful support. The PDF version really helped. Keep up the good work.
Italy
upvote

Balakrishna commented on February 17, 2024
Passed this exam today with a score of 864.
INDIA
upvote

Manish commented on February 17, 2024
Amazing Questions
INDIA
upvote

Kawah commented on February 17, 2024
I sat for my test today. I can confirm that there are about 6 new questions I didn't see in this dumps. The rest was all good.
UNITED STATES
upvote

Mohammed commented on February 17, 2024
I can say that this exam is valid and questions are same as in real exam. Passed my paper today after preparing for 1 week.
United Kingdom
upvote

John commented on January 27, 2024
is this up to date?
Anonymous
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Rebecca commented on October 08, 2023
Very useful material
SOUTH AFRICA
upvote

Rebecca commented on October 08, 2023
Very useful, the exact questions in exam
SOUTH AFRICA
upvote

Jane commented on October 08, 2023
Very useful
SOUTH AFRICA
upvote

bot commented on October 08, 2023
QUESTION: 99 You use Azure Sentinel. You need to use a built-in role to provide a security analyst with the ability to edit the queries of custom Azure Sentinel workbooks. The solution must use the principle of least privilege. Which role should you assign to the analyst? Answer is : Azure Sentinel Contributor (A) but it showing (C) Azure Sentinel Responder - WORNG
INDIA
upvote

bot commented on October 08, 2023
how many question will ask in exam
INDIA
upvote

Mark commented on July 25, 2023
Hi all, where can I find the updated questions
Anonymous
upvote

Yefferic commented on July 19, 2023
very usefull
Anonymous
upvote

Jason commented on July 05, 2023
Total Questions: 156 Exam questions 187 If I buy this dump - will I get 156 questions or 187?
AUSTRALIA
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Percy commented on June 06, 2023
Good dump to study
INDIA
upvote

Alejandro commented on May 30, 2023
This practice exam contained the exact questions and answers that I encountered in the exam. It felt like cheaing! LOL
UNITED KINGDOM
upvote

IRSHAD PASHA commented on May 30, 2023
these questions are absolutely the same what was asked in the exam
Anonymous
upvote

Mihai commented on February 15, 2023
Pass my exam. This question bank has real content from exam.
UNITED STATES
upvote