Free SC-200 Exam Braindumps (page: 43)

Page 43 of 79

DRAG DROP (Drag and Drop is not supported).
You need to use an Azure Sentinel analytics rule to search for specific criteria in Amazon Web Services (AWS) logs and to generate incidents.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/detect-threats-custom



Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have Linux virtual machines on Amazon Web Services (AWS).
You deploy Azure Defender and enable auto-provisioning.
You need to monitor the virtual machines by using Azure Defender.
Solution: You manually install the Log Analytics agent on the virtual machines.
Does this meet the goal?

  1. Yes
  2. No

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-machines?pivots=azure-arc



You have a Microsoft 365 subscription that has Microsoft 365 Defender enabled.
You need to identify all the changes made to sensitivity labels during the past seven days.
What should you use?

  1. the Incidents blade of the Microsoft 365 Defender portal
  2. the Alerts settings on the Data Loss Prevention blade of the Microsoft 365 compliance center
  3. Activity explorer in the Microsoft 365 compliance center
  4. the Explorer settings on the Email & collaboration blade of the Microsoft 365 Defender portal

Answer(s): C

Explanation:

Labeling activities are available in Activity explorer.
For example:
Sensitivity label applied -
This event is generated each time an unlabeled document is labeled or an email is sent with a sensitivity label.
It is captured at the time of save in Office native applications and web applications.
It is captured at the time of occurrence in Azure Information protection add-ins.
Upgrade and downgrade labels actions can also be monitored via the Label event type field and filter.


Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/data-classification-activity-explorer-available-events?view=o365-worldwide



You have the following environment:
Azure Sentinel -
✑ A Microsoft 365 subscription
✑ Microsoft Defender for Identity
✑ An Azure Active Directory (Azure AD) tenant
You configure Azure Sentinel to collect security logs from all the Active Directory member servers and domain controllers.
You deploy Microsoft Defender for Identity by using standalone sensors.
You need to ensure that you can detect when sensitive groups are modified in Active Directory.
Which two actions should you perform? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.

  1. Configure the Advanced Audit Policy Configuration settings for the domain controllers.
  2. Modify the permissions of the Domain Controllers organizational unit (OU).
  3. Configure auditing in the Microsoft 365 compliance center.
  4. Configure Windows Event Forwarding on the domain controllers.

Answer(s): A,D


Reference:

https://docs.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection https://docs.microsoft.com/en-us/defender-for-identity/configure-event-collection



Page 43 of 79



Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

Anyah Vincent Ndubuisi commented on December 19, 2024
Microsoft SC 200 SOC, is awesomely good enough for every cybersecurity specialist. Well detailed for freshers also. From Anyah Vincent.Nigeria.
Anonymous
upvote

Vin commented on November 07, 2024
Good content
Anonymous
upvote

Lueng commented on October 21, 2024
Very professional people and accurate study content. I highly recommend.
HONG KONG
upvote

LA commented on October 18, 2024
Hi there, I have scheduled my EXAM and will share my experience if these questions are valid or not.
Anonymous
upvote

Vignesh commented on October 03, 2024
I'm writing next week, are the questions still valid?
CZECH REPUBLIC
upvote

Donjo commented on September 09, 2024
Anyone tried recently. like Sept?
Anonymous
upvote

Ma hari bahadur commented on July 12, 2024
Great passed
UNITED STATES
upvote

Tota commented on July 12, 2024
Nailed it totas
Anonymous
upvote

Heavy Guy commented on July 06, 2024
Just passed this exam.
UNITED STATES
upvote

Patrick commented on June 16, 2024
Very helpful
SWITZERLAND
upvote

Bhagwati commented on June 06, 2024
Exam dumps helped me to get 90% marks.
Anonymous
upvote

Nikhil Jagadale commented on May 10, 2024
Very helpful
INDIA
upvote

Karabo commented on April 11, 2024
Very helpful
SOUTH AFRICA
upvote

CyberThreat commented on March 12, 2024
Thank You for sharing this questions! Nice Job.
BRAZIL
upvote

Anwar commented on February 17, 2024
Thank you for your questions and the wonderful support. The PDF version really helped. Keep up the good work.
Italy
upvote

Balakrishna commented on February 17, 2024
Passed this exam today with a score of 864.
INDIA
upvote

Manish commented on February 17, 2024
Amazing Questions
INDIA
upvote

Kawah commented on February 17, 2024
I sat for my test today. I can confirm that there are about 6 new questions I didn't see in this dumps. The rest was all good.
UNITED STATES
upvote

Mohammed commented on February 17, 2024
I can say that this exam is valid and questions are same as in real exam. Passed my paper today after preparing for 1 week.
United Kingdom
upvote

John commented on January 27, 2024
is this up to date?
Anonymous
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Rebecca commented on October 08, 2023
Very useful material
SOUTH AFRICA
upvote

Rebecca commented on October 08, 2023
Very useful, the exact questions in exam
SOUTH AFRICA
upvote

Jane commented on October 08, 2023
Very useful
SOUTH AFRICA
upvote

bot commented on October 08, 2023
QUESTION: 99 You use Azure Sentinel. You need to use a built-in role to provide a security analyst with the ability to edit the queries of custom Azure Sentinel workbooks. The solution must use the principle of least privilege. Which role should you assign to the analyst? Answer is : Azure Sentinel Contributor (A) but it showing (C) Azure Sentinel Responder - WORNG
INDIA
upvote

bot commented on October 08, 2023
how many question will ask in exam
INDIA
upvote

Mark commented on July 25, 2023
Hi all, where can I find the updated questions
Anonymous
upvote

Yefferic commented on July 19, 2023
very usefull
Anonymous
upvote

Jason commented on July 05, 2023
Total Questions: 156 Exam questions 187 If I buy this dump - will I get 156 questions or 187?
AUSTRALIA
upvote

Brijesh kr commented on June 29, 2023
awesome contents
INDIA
upvote

Percy commented on June 06, 2023
Good dump to study
INDIA
upvote

Alejandro commented on May 30, 2023
This practice exam contained the exact questions and answers that I encountered in the exam. It felt like cheaing! LOL
UNITED KINGDOM
upvote

IRSHAD PASHA commented on May 30, 2023
these questions are absolutely the same what was asked in the exam
Anonymous
upvote

Mihai commented on February 15, 2023
Pass my exam. This question bank has real content from exam.
UNITED STATES
upvote