Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Microsoft Microsoft Certified: Security Operations Analyst Associate SC-200 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

You need to meet the Microsoft Sentinel requirements for App1. What should you configure for App1?

Options:

A.

an API connection


B.

a trigger


C.

an connector


D.

authorization


Expert Solution
Questions # 32:

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. All endpoint devices are onboarded to Microsoft Defender for Endpoint.

You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace 1. All Microsoft Defender XDR events are ingested into Workspace1.

You have a Microsoft Entra tenant.

You create a KQL query named query1 that searches device logs for a known vulnerability.

You need to ensure that query1 runs every hour. The solution must minimize administrative effort.

What should you configure?

Options:

A.

an automation rule


B.

automated investigation and response (AIR)


C.

a watchlist


D.

a custom detection rule


Expert Solution
Questions # 33:

You have a Microsoft 365 subscription that uses Microsoft Defender XDR.

You discover that when Microsoft Defender for Endpoint generates alerts for a commonly used executable file, it causes alert fatigue. You need to tune the alerts.

Which two actions can an alert tuning rule perform for the alerts?

Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Options:

A.

delete


B.

hide


C.

resolve


D.

merge


E.

assign


Expert Solution
Questions # 34:

You have a Microsoft 365 subscription that uses Microsoft Defender XDR.

You plan to investigate suspicious activity in the subscription by using Microsoft Graph activity logs.

You need to search for requests to delete resources from the subscription and identify the users that initiated the requests.

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 34


Expert Solution
Questions # 35:

You have the resources shown in the following table.

Question # 35

You have an Azure subscription that uses Mictosoft Defender for Cloud.

You need to use Defender for Cloud to protect VM1 and Server1. The solution must meet the following requirements:

• Support Advanced Threat Protection and vulnerability assessment

• Register each SQL Server 2022 instance as a SQL virtual machine.

• Minimize implementation and administrative effort

What should you deploy to each server? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 35


Expert Solution
Questions # 36:

You need to complete the query for failed sign-ins to meet the technical requirements.

Where can you find the column name to complete the where clause?

Options:

A.

Security alerts in Azure Security Center


B.

Activity log in Azure


C.

Azure Advisor


D.

the query windows of the Log Analytics workspace


Expert Solution
Questions # 37:

You are responsible for responding to Azure Defender for Key Vault alerts.

During an investigation of an alert, you discover unauthorized atte mpts to access a key vault from a Tor exit node.

What should you configure to mitigate the threat?

Options:

A.

Key Vault firewalls and virtual networks


B.

Azure Active Directory (Azure AD) permissions


C.

role-based access control (RBAC) for the key vault


D.

the access policy settings of the key vault


Expert Solution
Questions # 38:

You have a Microsoft 365 B5 subscription that contains a user named User1. The subscription uses Microsoft 365 Copilot for Security. Copilot for Security uses the Sentinel plugin. User1 is assigned the Copilot Contributor role.

During an investigation, User1 submits a prompt and receives a notification that Copilot for Security cannot respond to requests because the security compute unit (SCU) usage is nearing the provisioned capacity limit.

You need to ensure that User1 can use Copilot for Security to generate a successful response.

What should User1 do?

Options:

A.

Open a second Copilot for Security session and submit the prompt.


B.

Wait one hour and resubmit the prompt.


C.

Run the Microsoft Sentinel Optimization Workbook.


D.

Update the provisioned SCUs.


Expert Solution
Questions # 39:

You need to recommend a solution to meet the technical requirements for the Azure virtual machines. What should you include in the recommendation?

Options:

A.

just-in-time (JIT) access


B.

Azure Defender


C.

Azure Firewall


D.

Azure Application Gateway


Expert Solution
Questions # 40:

The issue for which team can be resolved by using Microsoft Defender for Endpoint?

Options:

A.

executive


B.

sales


C.

marketing


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions