Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Microsoft Certified: Security Operations Analyst Associate SC-200 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SC-200 Premium Access

View all detail and faqs for the SC-200 exam


751 Students Passed

87% Average Score

91% Same Questions
Viewing page 8 out of 12 pages
Viewing questions 71-80 out of questions
Questions # 71:

You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1.

You create a hunting query that detects a new attack vector. The attack vector maps to a tactic listed in the MITRE ATT&CK database.

You need to ensure that an incident is created in WS1 when the new attack vector is detected.

What should you configure?

Options:

A.

a Fusion rule

B.

a query bookmark

C.

a scheduled query rule

D.

a hunting livestream session

Questions # 72:

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 1 and contains a macOS device named Device1.

You need to investigate a Defender for Endpoint agent alert on Device1. The solution must meet the following requirements:

• Identify all the active network connections on Device1.

• Identify all the running processes on Device1.

• Retrieve the login history of Device1.

• Minimize administrative effort.

What should you do first from the Microsoft Defender portal?

Options:

A.

From Advanced features in Endpoints, disable Authenticated telemetry.

B.

From Advanced features in Endpoints, enable Live Response unsigned script execution.

C.

From Devices, click Collect investigation package for Device 1.

D.

From Devices, initiate a live response session on Device1.

Questions # 73:

Your company stores the data of every project in a different Azure subscription. All the subscriptions use the same Microsoft Entra tenant.

Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription.

You deploy Microsoft Sentinel to a new Azure subscription.

You need to perform hunting queries in Microsoft Sentinel to search across all the Log Analytics workspaces of all the subscriptions.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Create a query that uses the resource expression and the alias operator.

B.

Use the alias statement.

C.

Add the Microsoft Sentinel solution to each workspace.

D.

Create a query that uses the workspace expression and the union operator.

E.

Add the Security Events connector to the Microsoft Sentinel workspace.

Questions # 74:

You have a Microsoft 365 subscription that contains three users named User1. User2 and User3 and the resources shown in the following table.

Question # 74

You have a Microsoft Defender XDR detection rule named Rule1 that has the following configurations:

• Scope: DevGroup1

• File hash: File1.exe

• Actions

o Devices: Collect investigation package

o User: Mark as compromised o Files: Block

Each user attempts to run File1.exe on their device.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 74

Options:

Questions # 75:

You are configuring Azure Sentinel.

You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.

Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Enable Entity behavior analytics.

B.

Associate a playbook to the analytics rule that triggered the incident.

C.

Enable the Fusion rule.

D.

Add a playbook.

E.

Create a workbook.

Questions # 76:

You have an Azure Functions app that generates thousands of alerts in Azure Security Center each day for normal activity.

You need to hide the alerts automatically in Security Center.

Which three actions should you perform in sequence in Security Center? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Question # 76

Options:

Questions # 77:

You haw the resources shown in the following Table.

Question # 77

You have an Azure subscription that uses Microsoft Defender for Cloud.

You need to enable Microsoft Defender lot Servers on each resource.

Which resources will require the installation of the Azure Arc agent?

Options:

A.

Server 3 only

B.

Server1 and 5erver4 only

C.

Server 1. Server2. arid Server4 only

D.

Server 1, Servec2, Server3. and Seiver4

Questions # 78:

Your on-premises network contains an Active Directory Domain Services (AD DS) forest.

You have a Microsoft Entra tenant that uses Microsoft Defender for Identity. The AD DS forest syncs with the tenant

You need to create a hunting query that will identify LDAP simple binds to the AD DS domain controllers.

Which table should you query?

Options:

A.

AADServicePrincipalRiskEventi

B.

IdentityLOgonEvents

C.

AADDomainServicesAccountLogon

D.

Signinlogs

Questions # 79:

You have an Azure subscription that contains 50 virtual machines.

You plan to deploy Microsoft [Defender for Cloud.

You need to enable agentless scanning for 40 virtual machines. The solution must create disk snapshots of the virtual machines and perform out-of-band analysis of the snapshots.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 79

Options:

Questions # 80:

You have four Azure subscriptions. One of the subscriptions contains a Microsoft Sentinel workspace.

You need to deploy Microsoft Sentinel data connectors to collect data from the subscriptions by using Azure Policy. The solution must ensure that the policy will apply to new and existing resources in the subscriptions.

Which type of connectors should you provision, and what should you use to ensure that all the resources are monitored? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 80

Options:

Viewing page 8 out of 12 pages
Viewing questions 71-80 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.