Free SC-200 Exam Braindumps (page: 40)

Page 39 of 79

DRAG DROP (Drag and Drop is not supported).
You have an Azure Functions app that generates thousands of alerts in Azure Security Center each day for normal activity.
You need to hide the alerts automatically in Security Center.
Which three actions should you perform in sequence in Security Center? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://techcommunity.microsoft.com/t5/azure-security-center/suppression-rules-for-azure-security-center-alerts-are-now/ba-p/1404920



You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains the devices shown in the following table.



You initiate a live response session on each device.
You need to collect a Defender for Endpoint investigation package from each device.
On which devices can you collect the package by running advanced live response commands from the command-line interface (CLI)?

  1. Device1 and Device2 only
  2. Device1, Device2, and Device3 only
  3. Device3 and Device4 only
  4. Device1, Device2, Device3, and Device4

Answer(s): B



You have a third-party security information and event management (SIEM) solution.
You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in near real time.
What should you do to route events to the SIEM solution?

  1. Create an Azure Sentinel workspace that has a Security Events connector.
  2. Configure the Diagnostics settings in Azure AD to stream to an event hub.
  3. Create an Azure Sentinel workspace that has an Azure Active Directory connector.
  4. Configure the Diagnostics settings in Azure AD to archive to a storage account.

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/overview-monitoring



You use Azure Sentinel.
You need to receive an alert in near real-time whenever Azure Storage account keys are enumerated.
Which two actions should you perform? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.

  1. Create a livestream
  2. Add a data connector
  3. Create an analytics rule
  4. Create a hunting query.
  5. Create a bookmark.

Answer(s): A,D


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/livestream






Post your Comments and Discuss Microsoft SC-200 exam with other Community members:

SC-200 Discussions & Posts