Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Microsoft Certified: Security Operations Analyst Associate SC-200 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SC-200 Premium Access

View all detail and faqs for the SC-200 exam


751 Students Passed

87% Average Score

91% Same Questions
Viewing page 13 out of 13 pages
Viewing questions 121-130 out of questions
Questions # 121:

You need to implement the Defender for Cloud requirements.

Which subscription-level role should you assign to Group1?

Options:

A.

Security Admin

B.

Owner

C.

Security Assessment Contributor

D.

Contributor

Questions # 122:

You have the resources shown in the following table.

Question # 122

You need to prevent duplicate events from occurring in SW1.

What should you use for each action? To answer, drag the appropriate resources to the correct actions. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 122

Options:

Questions # 123:

You have a Microsoft 365 E5 subscription that contains two users named Userl and User2 and From the Copilot for Security portal, User1 starts a session and creates the following prompts:

• Prompt1: Provides access to the Entra plugin

• Prompt2: Provides access to the Intune plugin

• Prompt3: Provides access to the Entra plugin

User1 shares the session with User2.

User2 does NOT have access to Microsoft Intune.

For which prompts can User2 view results during the shared session?

Options:

A.

Prompt1 only

B.

Prompt1 and Prompt2 only

C.

Prompt3 only

D.

Prompt1 and Prompt3 only

E.

Prompt1, Prompt2, and Prompt3

Questions # 124:

You plan to connect an external solution that will send Common Event Format (CEF) messages to Azure Sentinel.

You need to deploy the log forwarder.

Which three actions shou ld you perform in sequence? To answer, move the appropriate actions form the list of actions to the answer area and arrange them in the correct order.

Question # 124

Options:

Questions # 125:

You create a hunting query in Azure Sentinel.

You need to receive a notification in the Azure portal as soon as the hunting query detects a match on the query. The solution must minimize effort.

What should you use?

Options:

A.

a playbook

B.

a notebook

C.

a livestream

D.

a bookmark

Questions # 126:

No te: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are configuring Azure Sentinel.

You need to create an incident in Azure S entinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.

Solution: You create a hunting bookmark.

Does this meet the goal?

Options:

A.

Yes

B.

No

Questions # 127:

You have a Microsoft Sentinel workspace that has user and Entity Behavior Analytics (UEBA) enabled for Signin Logs.

You need to ensure that failed interactive sign-ins are detected.

The solution must minimize administrative effort.

What should you use?

Options:

A.

a scheduled alert query

B.

a UEBA activity template

C.

the Activity Log data connector

D.

a hunting query

Questions # 128:

You have a Microsoft 365 E5 subscription that uses Microsoft Copilot for Security.

You start a Copilot for Security session and enter five prompts that each provide responses.

You need to create a promptbook that will use the prompts but will NOT contain the responses. The solution must minimize administrative effort.

What should you do?

Options:

A.

Enter a new prompt that has the following input: Create a promptbook from my session prompts.

B.

Select each prompt, and then select Create promptbook.

C.

Share the session, and then select Create promptbook.

D.

Create a new promptbook and include each prompt.

Questions # 129:

You have a Microsoft 365 subscription that uses Microsoft Defender XDR.

You have a query that contains the following statements.

Question # 129

You need to configure a custom detection rule that will use the query. The solution must minimize how long it takes to be notified about events that match the query.

Which frequency should you select for the rule?

Options:

A.

Continuous (NRT)

B.

Every hour

C.

Every 12 hours

D.

Every 3 hours

Questions # 130:

You have a Microsoft 365 E5 subscription.

You need to search the Microsoft Purview audit log by using PowerShell on a Windows device.

What should you do first?

Options:

A.

Modify the TrustedHosts list

B.

Install the Microsoft Exchange Online PowerShell module.

C.

Install the Microsoft Graph PowerShell module.

D.

Enable PowerShell remoting.

Viewing page 13 out of 13 pages
Viewing questions 121-130 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.