Free SC-200 Exam Braindumps (page: 21)

Page 20 of 79

You have an Azure subscription.
You need to stream the Microsoft Graph activity logs to a third-party security information and event management (SIEM) tool. The solution must minimize administrative effort.
To where should you stream the logs?

  1. an Azure Event Hubs namespace
  2. an Azure Storage account
  3. an Azure Event Grid namespace
  4. a Log Analytics workspace

Answer(s): A



You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains 1,000 Windows devices.
You have a PowerShell script named Script1.ps1 that is signed digitally.
You need to ensure that you can run Script1.ps1 in a live response session on one of the devices.
What should you do first from the live response session?

  1. Run the library command.
  2. Upload Script1.ps1 to the library.
  3. Run the putfile command.
  4. Modify the PowerShell execution policy of the device.

Answer(s): B



DRAG DROP (Drag and Drop is not supported).
You have resources in Azure and Google cloud.
You need to ingest Google Cloud Platform (GCP) data into Azure Defender.
In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/security-center/quickstart-onboard-gcp



You are investigating a potential attack that deploys a new ransomware strain.
You have three custom device groups. The groups contain devices that store highly sensitive information.
You plan to perform automated actions on all devices.
You need to be able to temporarily group the machines to perform actions on the devices.
Which three actions should you perform? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.

  1. Assign a tag to the device group.
  2. Add the device users to the admin role.
  3. Add a tag to the machines.
  4. Create a new device group that has a rank of 1.
  5. Create a new admin role.
  6. Create a new device group that has a rank of 4.

Answer(s): A,C,D


Reference:

https://docs.microsoft.com/en-us/learn/modules/deploy-microsoft-defender-for-endpoints-environment/4-manage-access






Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

SC-200 Discussions & Posts