Microsoft SC-200 Exam Actual Questions
Microsoft Security Operations Analyst (Page 11 )

Updated On: 7-Aug-2026
View Related Case Study

You need to deploy the native cloud connector to Account 1 to meet the Microsoft Defender for Cloud requirements.
What should you do in Account1 first?

  1. Create an AWS user for Defender for Cloud.
  2. Configure AWS Security Hub.
  3. Deploy the AWS Systems Manager (SSM) agent.
  4. Create an Access control (IAM) role for Defender for Cloud.

Answer(s): B



View Related Case Study

HOTSPOT (Drag and Drop is not supported)
You need to implement Microsoft Defender for Cloud to meet the Microsoft Defender for Cloud requirements and the business requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



View Related Case Study

HOTSPOT (Drag and Drop is not supported)
You need to recommend remediation actions for the Microsoft Defender for Cloud alerts for Fabrikam.
What should you recommend for each threat? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/key-vault/general/security-features https://docs.microsoft.com/en-us/azure/key-vault/general/secure-your-key-vault



View Related Case Study

You need to recommend a solution to meet the technical requirements for the Azure virtual machines.
What should you include in the recommendation?

  1. just-in-time (JIT) VM access
  2. Microsoft Defender for Cloud
  3. Azure Firewall
  4. Azure Application Gateway

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/azure/security-center/azure-defender



View Related Case Study

You need to implement the Defender for Cloud requirements.
What should you configure for Server2?

  1. the Microsoft Antimalware extension
  2. the Azure Automanage machine configuration extension for Windows
  3. an Azure resource lock
  4. an Azure resource tag

Answer(s): D

Explanation:

Server2 must be excluded from agentless scanning.
Exclude machines from scanning Agentless scanning applies to all of the eligible machines in the subscription. To prevent specific machines from being scanned, you can exclude machines from agentless scanning based on your pre-existing environment tags.
When Defender for Cloud performs the continuous discovery for machines, excluded machines are skipped.
To configure machines for exclusion:
1. From Defender for Cloud's menu, open Environment settings. 2. Select the relevant subscription or multicloud connector. 3. For either the Defender Cloud Security Posture Management (CSPM) or Defender for Servers P2 plan, select Settings. 4. For agentless scanning, select Edit configuration. 5. Enter the tag name and value that applies to the machines that you want to exempt. You can enter multiple tag:value pairs.

6. Select Save to apply the changes.


Reference:

https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms



View Related Case Study

You need to implement the Defender for Cloud requirements.
Which subscription-level role should you assign to Group1?

  1. Security Assessment Contributor
  2. Contributor
  3. Security Admin
  4. Owner

Answer(s): D



HOTSPOT (Drag and Drop is not supported)
You have an Azure subscription that has Microsoft Defender for Cloud enabled for all supported resource types.
You create an Azure logic app named LA1.
You plan to use LA1 to automatically remediate security risks detected in Defender for Cloud.
You need to test LA1 in Security Center.
What should you do? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: When a Microsoft Defender for Cloud Recommendation is created or triggered When a Microsoft Defender for Cloud Recommendation is created or triggered - If your logic app relies on a recommendation that gets deprecated or replaced, your automation will stop working and you'll need to update the trigger. (also see step 6 below)
Incorrect: * When a Defender for Cloud Alert is created or triggered You can customize the trigger so that it relates only to alerts with the severity levels that interest you.
* When a response to a Defender for Cloud alert is triggered.
Note: If you are using the legacy trigger "When a response to a Microsoft Defender for Cloud alert is triggered", your logic apps will not be launched by the Workflow Automation feature. Instead, use either of the triggers mentioned above [rather in step 6 below].
Box 2: Workflow automation Create a logic app and define when it should automatically run 1. From Defender for Cloud's sidebar, select Workflow automation.
From this page you can create new automation rules, enable, disable, or delete existing ones.
2. To define a new workflow, select Add workflow automation. The options pane for your new automation opens.
Here you can enter: A name and description for the automation. The triggers that will initiate this automatic workflow. For example, you might want your Logic App to run when a security alert that contains "SQL" is generated. The Logic App that will run when your trigger conditions are met.
3. From the Actions section, select visit the Logic Apps page to begin the Logic App creation process.
4. Select (+) Add.
5. Fill out all required fields and select Review + Create.
The message Deployment is in progress appears. Wait for the deployment complete notification to appear and select Go to resource from the notification.
6. Review the information you entered and select Create.
The logic app designer supports the following Defender for Cloud triggers:
* When a Microsoft Defender for Cloud Recommendation is created or triggered - If your logic app relies on a recommendation that gets deprecated or replaced, your automation will stop working and you'll need to update the trigger. To track changes to recommendations, use the release notes.
* When a Defender for Cloud Alert is created or triggered - You can customize the trigger so that it relates only to alerts with the severity levels that interest you.
* When a Defender for Cloud regulatory compliance assessment is created or triggered - Trigger automations based on updates to regulatory compliance assessments.
7. Etc.


Reference:

https://docs.microsoft.com/en-us/azure/security-center/workflow-automation#create-a-logic-app-and-define-when-it-should-automatically-run



You have an Azure subscription that uses Microsoft Defender for Cloud.
You have 100 virtual machines in a resource group named RG1.
You assign the Security Admin roles to a new user named SecAdmin1.
You need to ensure that SecAdmin1 can apply quick fixes to the virtual machines by using Microsoft Defender for Cloud. The solution must use the principle of least privilege.
Which role should you assign to SecAdmin1?

  1. the Security Reader role for the subscription
  2. the Contributor for the subscription
  3. the Contributor role for RG1
  4. the Owner role for RG1

Answer(s): C



Viewing page 11 of 61
Viewing questions 81 - 88 out of 478 questions


Post your Comments and Discuss Microsoft SC-200 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!