Free SC-200 Exam Braindumps (page: 39)

Page 38 of 79

You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
What should you use?

  1. notebooks in Azure Sentinel
  2. Microsoft Cloud App Security
  3. Azure Monitor
  4. hunting queries in Azure Sentinel

Answer(s): A


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/notebooks



A security administrator receives email alerts from Azure Defender for activities such as potential malware uploaded to a storage account and potential successful brute force attacks.
The security administrator does NOT receive email alerts for activities such as antimalware action failed and suspicious network activity. The alerts appear in
Azure Security Center.
You need to ensure that the security administrator receives email alerts for all the activities.
What should you configure in the Security Center settings?

  1. the severity level of email notifications
  2. a cloud connector
  3. the Azure Defender plans
  4. the integration settings for Threat detection

Answer(s): A


Reference:

https://techcommunity.microsoft.com/t5/microsoft-365-defender/get-email-notifications-on-new-incidents-from-microsoft-365/ba-p/2012518



You have a Microsoft 365 subscription that contains 1,000 Windows 10 devices. The devices have Microsoft Office 365 installed.
You need to mitigate the following device threats:
✑ Microsoft Excel macros that download scripts from untrusted websites
✑ Users that open executable attachments in Microsoft Outlook
✑ Outlook rules and forms exploits
What should you use?

  1. Microsoft Defender Antivirus
  2. attack surface reduction rules in Microsoft Defender for Endpoint
  3. Windows Defender Firewall
  4. adaptive application control in Azure Defender

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/overview-attack-surface-reduction?view=o365-worldwide



You plan to create a custom Azure Sentinel query that will provide a visual representation of the security alerts generated by Azure Security Center.
You need to create a query that will be used to display a bar graph.
What should you include in the query?

  1. extend
  2. bin
  3. count
  4. workspace

Answer(s): C


Reference:

https://docs.microsoft.com/en-us/azure/azure-monitor/visualize/workbooks-chart-visualizations






Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

SC-200 Discussions & Posts