Free SC-200 Exam Braindumps

Pass your Microsoft Security Operations Analyst exam with these free Questions and Answers

Page 7 of 40
QUESTION 26

- (Exam Topic 3)
You have a Microsoft Sentinel workspace that contains an Azure AD data connector. You need to associate a bookmark with an Azure AD-related incident.
What should you do? To answer, drag the appropriate blades to the correct tasks. Each blade may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content
NOTE: Each correct selection is worth one point.
SC-200 dumps exhibit
Solution:
You can use the Logs blade or incident blade to create a bookmark of an Azure AD-related incident. Once the bookmark is created, you can associate it with the incident by using the incident blade. This allows you to quickly and easily access important information related to the incident in the future.

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

QUESTION 27

- (Exam Topic 3)
You are investigating an incident by using Microsoft 365 Defender.
You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop. CEOLaptop, and COOLaptop.
How should you complete the query? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point
SC-200 dumps exhibit
Solution:
SC-200 dumps exhibit

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

QUESTION 28

- (Exam Topic 1)
You need to recommend a solution to meet the technical requirements for the Azure virtual machines. What should you include in the recommendation?

  1. A. just-in-time (JIT) access
  2. B. Azure Defender
  3. C. Azure Firewall
  4. D. Azure Application Gateway

Correct Answer: B
Reference:
https://docs.microsoft.com/en-us/azure/security-center/azure-defender

QUESTION 29

- (Exam Topic 3)
You use Azure Defender.
You have an Azure Storage account that contains sensitive information.
You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address. Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  1. A. From Azure Security Center, enable workflow automation.
  2. B. Create an Azure logic appthat has a manual trigger
  3. C. Create an Azure logic app that has an Azure Security Center alert trigger.
  4. D. Create an Azure logic appthat has an HTTP trigger.
  5. E. From Azure Active Directory (Azure AD), add an app registration.

Correct Answer: AC
Reference:
https://docs.microsoft.com/en-us/azure/storage/common/azure-defender-storage-configure?tabs=azure-security-c https://docs.microsoft.com/en-us/azure/security-center/workflow-automation

QUESTION 30

- (Exam Topic 3)
You have a playbook in Azure Sentinel.
When you trigger the playbook, it sends an email to a distribution group.
You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
What should you do?

  1. A. Add a parameter and modify the trigger.
  2. B. Add a custom data connector and modify the trigger.
  3. C. Add a condition and modify the action.
  4. D. Add a parameter and modify the action.

Correct Answer: D
Reference:
https://azsec.azurewebsites.net/2020/01/19/notify-azure-sentinel-alert-to-your-email-automatically/

Page 7 of 40

Post your Comments and Discuss Microsoft SC-200 exam with other Community members: