Free SC-200 Exam Braindumps (page: 16)

Page 15 of 79

You create an Azure subscription named sub1.
In sub1, you create a Log Analytics workspace named workspace1.
You enable Azure Security Center and configure Security Center to use workspace1.
You need to collect security event logs from the Azure virtual machines that report to workspace1.
What should you do?

  1. From Security Center, enable data collection
  2. In sub1, register a provider.
  3. From Security Center, create a Workflow automation.
  4. In workspace1, create a workbook.

Answer(s): A


Reference:

https://docs.microsoft.com/en-us/azure/security-center/security-center-enable-data-collection



DRAG DROP (Drag and Drop is not supported).
You open the Cloud App Security portal as shown in the following exhibit.
Your environment does NOT have Microsoft Defender for Endpoint enabled.
You need to remediate the risk for the Launchpad app.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/cloud-app-security/governance-discovery



You have a playbook in Azure Sentinel.
When you trigger the playbook, it sends an email to a distribution group.
You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
What should you do?

  1. Add a parameter and modify the trigger.
  2. Add a custom data connector and modify the trigger.
  3. Add a condition and modify the action.
  4. Add an alert and modify the action.

Answer(s): A


Reference:

https://azsec.azurewebsites.net/2020/01/19/notify-azure-sentinel-alert-to-your-email-automatically/



HOTSPOT (Drag and Drop is not supported).
You need to create the analytics rule to meet the Azure Sentinel requirements.
What should you do? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom#set-automated-responses-and-create-the-rule https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook






Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

SC-200 Discussions & Posts