Microsoft SC-200 Exam Info and Free Practice Test VCE4Plus [Q56-Q74]

Share

Microsoft SC-200 Exam Info and Free Practice Test | VCE4Plus

Pass Microsoft SC-200 Premium Files Test Engine pdf - Free Dumps Collection


Skills measured

  • Mitigate threats using Azure Defender (25-30%)
  • The content of this exam was updated on July 23, 2021. Please download the exam skills outline below to see what changed.
  • Mitigate threats using Azure Sentinel (40-45%)
  • Mitigate threats using Microsoft 365 Defender (25-30%)

How to Register For Exam SC-200: Microsoft Security Operations Analyst?

Exam Register Link: https://examregistration.microsoft.com/?locale=en-us&examcode=SC-200&examname=Exam%20SC-200:%20Microsoft%20Security%20Operations%20Analyst&returnToLearningUrl=https%3A%2F%2Fdocs.microsoft.com%2Flearn%2Fcertifications%2Fexams%2Fsc-200

 

NEW QUESTION 56
You have the following advanced hunting query in Microsoft 365 Defender.

You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Add DeviceIdand ReportIdto the output of the query.
  • B. Add | orderby Timestamp to the query.
  • C. Create a detection rule.
  • D. Replace DeviceProcessEventswith DeviceNetworkEvents.
  • E. Create a suppression rule.

Answer: A,C

Explanation:
Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/custom-detection- rules

 

NEW QUESTION 57
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring Microsoft Defender for Identity integration with Active Directory.
From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit.
Solution: From Azure Identity Protection, you configure the sign-in risk policy.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/defender-for-identity/manage-sensitive-honeytoken-accounts

 

NEW QUESTION 58
The issue for which team can be resolved by using Microsoft Defender for Office 365?

  • A. marketing
  • B. security
  • C. executive
  • D. sales

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/atp-for-spo-odb-and-teams?
view=o365-worldwide

 

NEW QUESTION 59
You have the following advanced hunting query in Microsoft 365 Defender.

You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Add DeviceId and ReportId to the output of the query.
  • B. Create a detection rule.
  • C. Replace DeviceProcessEvents with DeviceNetworkEvents.
  • D. Create a suppression rule.
  • E. Add | order by Timestamp to the query.

Answer: A,B

Explanation:
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/custom-detection- rules

 

NEW QUESTION 60
Your company uses Microsoft Defender for Endpoint.
The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company's accounting team.
You need to hide false positive in the Alerts queue, while maintaining the existing security posture.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Create a suppression rule scoped to a device group.
  • B. Create a suppression rule scoped to any device.
  • C. Resolve the alert automatically.
  • D. Hide the alert.
  • E. Generate the alert.

Answer: B,D,E

Explanation:
Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/manage-alerts

 

NEW QUESTION 61
You have resources in Azure and Google cloud.
You need to ingest Google Cloud Platform (GCP) data into Azure Defender.
In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/security-center/quickstart-onboard-gcp

 

NEW QUESTION 62
HOTSPOT
You use Azure Sentinel to monitor irregular Azure activity.
You create custom analytics rules to detect threats as shown in the following exhibit.

You do NOT define any incident settings as part of the rule definition.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:

Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

 

NEW QUESTION 63
You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?

  • A. Add a hunting bookmark.
  • B. Add data connectors
  • C. Disable, and then enable the rule.
  • D. Create a new machine learning analytics rule.

Answer: B

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/connect-data-sources

 

NEW QUESTION 64
You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
What should you use?

  • A. Azure Monitor
  • B. notebooks in Azure Sentinel
  • C. Microsoft Cloud App Security
  • D. hunting queries in Azure Sentinel

Answer: B

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/notebooks

 

NEW QUESTION 65
Your company uses Azure Sentinel.
A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?

  • A. Azure Sentinel Responder
  • B. Azure Sentinel Reader
  • C. Azure Sentinel Contributor
  • D. Logic App Contributor

Answer: A

 

NEW QUESTION 66
You need to configure Microsoft Cloud App Security to generate alerts and trigger remediation actions in response to external sharing of confidential files.
Which two actions should you perform in the Cloud App Security portal? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Select Investigate files, and then filter File Type to Document.
  • B. From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings
  • C. Select Investigate files, and then filter App to Office 365.
  • D. Select Investigate files, and then select New policy from search
  • E. From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant
  • F. From Settings, select Information Protection, select Files, and then enable file monitoring.

Answer: B,F

Explanation:
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/tutorial-dlp
https://docs.microsoft.com/en-us/cloud-app-security/azip-integration

 

NEW QUESTION 67
You need to create the test rule to meet the Azure Sentinel requirements.
What should you do when you create the rule?

  • A. From Set rule logic, turn off suppression.
  • B. From Analytics rule details, configure the tactics.
  • C. From Set rule logic, map the entities.
  • D. From Analytics rule details, configure the severity.

Answer: C

Explanation:
Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

 

NEW QUESTION 68
You are informed of an increase in malicious email being received by users.
You need to create an advanced hunting query in Microsoft 365 Defender to identify whether the accounts of the email recipients were compromised. The query must return the most recent 20 sign-ins performed by the recipients within an hour of receiving the known malicious email.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-emails-devices?view=o365-worldwide

 

NEW QUESTION 69
You use Azure Sentinel to monitor irregular Azure activity.
You create custom analytics rules to detect threats as shown in the following exhibit.

You do NOT define any incident settings as part of the rule definition.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application, email Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

 

NEW QUESTION 70
Your company uses Microsoft Defender for Endpoint.
The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company's accounting team.
You need to hide false positive in the Alerts queue, while maintaining the existing security posture. Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Create a suppression rule scoped to a device group.
  • B. Create a suppression rule scoped to any device.
  • C. Resolve the alert automatically.
  • D. Hide the alert.
  • E. Generate the alert.

Answer: B,D,E

Explanation:
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/manage-alerts

 

NEW QUESTION 71
You have an Azure Sentinel deployment.
You need to query for all suspicious credential access activities.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - From Azure Sentinel, select Hunting.
2 - Filter by tactics.
3 - Select Run All Queries.

 

NEW QUESTION 72
You have a playbook in Azure Sentinel.
When you trigger the playbook, it sends an email to a distribution group.
You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
What should you do?

  • A. Add a parameter and modify the action.
  • B. Add a parameter and modify the trigger.
  • C. Add a condition and modify the action.
  • D. Add a custom data connector and modify the trigger.

Answer: A

Explanation:
Reference:
https://azsec.azurewebsites.net/2020/01/19/notify-azure-sentinel-alert-to-your-email-automatically/

 

NEW QUESTION 73
You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
You deploy Azure Sentinel.
You need to use the existing logic app as a playbook in Azure Sentinel.
What should you do first?

  • A. Add a data connector to Azure Sentinel.
  • B. Configure a custom Threat Intelligence connector in Azure Sentinel.
  • C. And a new scheduled query rule.
  • D. Modify the trigger in the logic app.

Answer: A

Explanation:
Section: [none]

 

NEW QUESTION 74
......


Schedule exam

Languages: English, Japanese, Chinese (Simplified), Korean, French, German, Spanish, Portuguese (Brazil), Russian, Arabic (Saudi Arabia), Chinese (Traditional), Italian

Retirement date: none

This exam measures your ability to accomplish the following technical tasks: mitigate threats using Microsoft 365 Defender; mitigate threats using Azure Defender; and mitigate threats using Azure Sentinel.

 

Updated Official licence for SC-200 Certified by SC-200 Dumps PDF: https://www.vce4plus.com/Microsoft/SC-200-valid-vce-dumps.html

New 2022 Realistic SC-200 Dumps Test Engine Exam Questions in here: https://drive.google.com/open?id=1Ehgsh59JYPOP-8KI6fOKbzb7xbOdoZsX