Pass the Microsoft Microsoft Certified: Security Operations Analyst Associate SC-200 Questions and answers with CertsForce

Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions
Questions # 1:

You need to ensure that the Group1 members can meet the Microsoft Sentinel requirements.

Which role should you assign to Group1?

Options:

A.

Microsoft Sentinel Automation Contributor


B.

Logic App Contributor


C.

Automation Operator


D.

Microsoft Sentinel Playbook Operator


Expert Solution
Questions # 2:

You need to implement the Microsoft Sentinel NRT rule for monitoring the designated break glass account. The solution must meet the Microsoft Sentinel requirements.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 2


Expert Solution
Questions # 3:

You need to implement the ASIM query for DNS requests. The solution must meet the Microsoft Sentinel requirements. How should you configure the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 3


Expert Solution
Questions # 4:

You need to implement the Defender for Cloud requirements.

What should you configure for Server2?

Options:

A.

the Microsoft Antimalware extension


B.

an Azure resource lock


C.

an Azure resource tag


D.

the Azure Automanage machine configuration extension for Windows


Expert Solution
Questions # 5:

You need to implement the query for Workbook1 and Webapp1. The solution must meet the Microsoft Sentinel requirements. How should you configure the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 5


Expert Solution
Questions # 6:

You need to implement the scheduled rule for incident generation based on rulequery1.

What should you configure first?

Options:

A.

entity mapping


B.

custom details


C.

event grouping


D.

alert details


Expert Solution
Questions # 7:

You need to ensure that the configuration of HuntingQuery1 meets the Microsoft Sentinel requirements.

What should you do?

Options:

A.

Add HuntingQuery1 to a livestream.


B.

Create a watch list.


C.

Create an Azure Automation rule.


D.

Add HuntingQuery1 to favorites.


Expert Solution
Questions # 8:

You need to implement the Defender for Cloud requirements.

Which subscription-level role should you assign to Group1?

Options:

A.

Security Admin


B.

Owner


C.

Security Assessment Contributor


D.

Contributor


Expert Solution
Questions # 9:

You need to configure event monitoring for Server1. The solution must meet the Microsoft Sentinel requirements. What should you create first?

Options:

A.

a Microsoft Sentinel automation rule


B.

a Microsoft Sentinel scheduled query rule


C.

a Data Collection Rule (DCR)


D.

an Azure Event Grid topic


Expert Solution
Questions # 10:

You need to ensure that the processing of incidents generated by rulequery1 meets the Microsoft Sentinel requirements.

What should you create first?

Options:

A.

a playbook with an incident trigger


B.

a playbook with an entity trigger


C.

an Azure Automation rule


D.

a playbook with an alert trigger


Expert Solution
Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions