SC-200 Exam Dumps Pass with Updated Mar-2022 Tests Dumps SC-200 exam questions for practice in 2022 Updated 110 Questions Skills measured The content of this exam was updated on July 23, 2021. Please download the exam skills outline below to see what changed.Mitigate threats using Azure Sentinel (40-45%)Mitigate threats using Microsoft 365 Defender (25-30%)Mitigate threats using Azure Defender (25-30%) [...]

SC-200 Exam Dumps Pass with Updated Mar-2022 Tests Dumps [Q11-Q30]

Share

SC-200 Exam Dumps Pass with Updated Mar-2022 Tests Dumps

SC-200 exam questions for practice in 2022 Updated 110 Questions


Skills measured

  • The content of this exam was updated on July 23, 2021. Please download the exam skills outline below to see what changed.
  • Mitigate threats using Azure Sentinel (40-45%)
  • Mitigate threats using Microsoft 365 Defender (25-30%)
  • Mitigate threats using Azure Defender (25-30%)

 

NEW QUESTION 11
You need to use an Azure Sentinel analytics rule to search for specific criteria in Amazon Web Services (AWS) logs and to generate incidents.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Add the Azure Web Services connector.
2 - From Analytics in Azure Sentinel, create a custom......
3 - Set the alert logic.
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/detect-threats-custom

 

NEW QUESTION 12
You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector.
While creating a new rule from a template in the connector, you decide to generate a new alert for every event. You create the following rule query.

By which two components can you group alerts into incidents? Each correct answer presents a complete
solution.
NOTE: Each correct selection is worth one point.

  • A. resource group
  • B. user
  • C. computer
  • D. IP address

Answer: B,C

 

NEW QUESTION 13
You are informed of an increase in malicious email being received by users.
You need to create an advanced hunting query in Microsoft 365 Defender to identify whether the accounts of the email recipients were compromised. The query must return the most recent 20 sign-ins performed by the recipients within an hour of receiving the known malicious email.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-emails-devices?view=o365-worldwide

 

NEW QUESTION 14
HOTSPOT
You manage the security posture of an Azure subscription that contains two virtual machines name vm1 and vm2.
The secure score in Azure Security Center is shown in the Security Center exhibit. (Click the Security Center tab.)

Azure Policy assignments are configured as shown in the Policies exhibit. (Click the Policies tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:

Section: [none]
Explanation/Reference:
https://techcommunity.microsoft.com/t5/azure-security-center/security-control-restrict-unauthorized-network- access/ba-p/1593833
https://techcommunity.microsoft.com/t5/azure-security-center/security-control-secure-management-ports/ba- p/1505770

 

NEW QUESTION 15
You need to create the test rule to meet the Azure Sentinel requirements.
What should you do when you create the rule?

  • A. From Set rule logic, turn off suppression.
  • B. From Analytics rule details, configure the severity.
  • C. From Analytics rule details, configure the tactics.
  • D. From Set rule logic, map the entities.

Answer: D

Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom Mitigate threats using Azure Sentinel Question Set 2

 

NEW QUESTION 16
You have an Azure Functions app that generates thousands of alerts in Azure Security Center each day for normal activity.
You need to hide the alerts automatically in Security Center.
Which three actions should you perform in sequence in Security Center? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

1 - Select Security policy.
2 - Select Suppression rules, and then.....
3 - Select Azure resource as the entity type and specify the ID.
Reference:
https://techcommunity.microsoft.com/t5/azure-security-center/suppression-rules-for-azure-security-center-alerts-are-now/ba-p/1404920

 

NEW QUESTION 17
You have an Azure subscription that contains a Log Analytics workspace.
You need to enable just-in-time (JIT) VM access and network detections for Azure resources.
Where should you enable Azure Defender?

  • A. at the subscription level
  • B. at the workspace level
  • C. at the resource level

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/security-center/enable-azure-defender

 

NEW QUESTION 18
You have an Azure Sentinel deployment.
You need to query for all suspicious credential access activities.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:
Explanation

 

NEW QUESTION 19
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.
You have Microsoft SharePoint Online sites that contain sensitive documents. The documents contain customer account numbers that each consists of 32 alphanumeric characters.
You need to create a data loss prevention (DLP) policy to protect the sensitive documents. What should you use to detect which documents are sensitive?

  • A. a hunting query in Microsoft 365 Defender
  • B. RegEx pattern matching
  • C. SharePoint search
  • D. Azure Information Protection

Answer: D

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/information-protection/what-is-information-protection

 

NEW QUESTION 20
Your company deploys the following services:
* Microsoft Defender for Identity
* Microsoft Defender for Endpoint
* Microsoft Defender for Office 365
You need to provide a security analyst with the ability to use the Microsoft 365 security center. The analyst must be able to approve and reject pending actions generated by Microsoft Defender for Endpoint. The solution must use the principle of least privilege.
Which two roles should assign to the analyst? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. the Compliance Data Administrator in Azure Active Directory (Azure AD)
  • B. the Active remediation actions role in Microsoft Defender for Endpoint
  • C. the Security Administrator role in Azure Active Directory (Azure AD)
  • D. the Security Reader role in Azure Active Directory (Azure AD)

Answer: B,D

Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide

 

NEW QUESTION 21
You need to create the test rule to meet the Azure Sentinel requirements.
What should you do when you create the rule?

  • A. From Set rule logic, turn off suppression.
  • B. From Analytics rule details, configure the severity.
  • C. From Analytics rule details, configure the tactics.
  • D. From Set rule logic, map the entities.

Answer: D

Explanation:
Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

 

NEW QUESTION 22
You need to create a query for a workbook. The query must meet the following requirements:
List all incidents by incident number.
Only include the most recent log for each incident.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://www.drware.com/whats-new-soc-operational-metrics-now-available-in-sentinel/

 

NEW QUESTION 23
You need to assign a role-based access control (RBAC) role to admin1 to meet the Azure Sentinel requirements and the business requirements.
Which role should you assign?

  • A. Logic App Contributor
  • B. Automation Operator
  • C. Automation Runbook Operator
  • D. Azure Sentinel Contributor

Answer: D

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/roles

 

NEW QUESTION 24
You have a custom analytics rule to detect threats in Azure Sentinel.
You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED.
What is a possible cause of the issue?

  • A. The number of alerts exceeded 10,000 within two minutes.
  • B. There are connectivity issues between the data sources and Log Analytics.
  • C. Permissions to one of the data sources of the rule query were modified.
  • D. The rule query takes too long to run and times out.

Answer: C

Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

 

NEW QUESTION 25
Your company uses Azure Sentinel.
A new security analyst reports that she cannot assign and resolve incidents in Azure Sentinel.
You need to ensure that the analyst can assign and resolve incidents. The solution must use the principle of least privilege.
Which role should you assign to the analyst?

  • A. Azure Sentinel Responder
  • B. Logic App Contributor
  • C. Azure Sentinel Contributor
  • D. Azure Sentinel Reader

Answer: A

Explanation:
Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sentinel/roles

 

NEW QUESTION 26
You need to configure DC1 to meet the business requirements.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation
Text Description automatically generated with medium confidence

Step 1: log in to https://portal.atp.azure.com as a global admin
Step 2: Create the instance
Step 3. Connect the instance to Active Directory
Step 4. Download and install the sensor.
Reference:
https://docs.microsoft.com/en-us/defender-for-identity/install-step1
https://docs.microsoft.com/en-us/defender-for-identity/install-step4

 

NEW QUESTION 27
Your company uses Azure Security Center and Azure Defender.
The security operations team at the company informs you that it does NOT receive email notifications for security alerts.
What should you configure in Security Center to enable the email notifications?

  • A. Pricing & settings
  • B. Security solutions
  • C. Security policy
  • D. Security alerts
  • E. Azure Defender

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/security-center/security-center-provide-security-contact-details

 

NEW QUESTION 28
You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants

 

NEW QUESTION 29
You are investigating a potential attack that deploys a new ransomware strain.
You plan to perform automated actions on a group of highly valuable machines that contain sensitive information.
You have three custom device groups.
You need to be able to temporarily group the machines to perform actions on the devices. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A. Add a tag to the device group.
  • B. Add a tag to the machines.
  • C. Create a new device group that has a rank of 4.
  • D. Create a new admin role.
  • E. Add the device users to the admin role.
  • F. Create a new device group that has a rank of 1.

Answer: A,B,F

Explanation:
Explanation
https://docs.microsoft.com/en-us/learn/modules/deploy-microsoft-defender-for-endpoints-environment/4-manage

 

NEW QUESTION 30
......


Schedule exam

Languages: English, Japanese, Chinese (Simplified), Korean, French, German, Spanish, Portuguese (Brazil), Russian, Arabic (Saudi Arabia), Chinese (Traditional), Italian

Retirement date: none

This exam measures your ability to accomplish the following technical tasks: mitigate threats using Microsoft 365 Defender; mitigate threats using Azure Defender; and mitigate threats using Azure Sentinel.

 

Authentic SC-200 Dumps With 100% Passing Rate Practice Tests Dumps: https://www.guidetorrent.com/SC-200-pdf-free-download.html

Updated Premium SC-200 Exam Engine pdf: https://drive.google.com/open?id=1sG4ymySm5FXBoTSz1ooOOWygvuXk_Eao