SC-100 Exam Question 46

A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription.
All the on-premises servers in the perimeter network are prevented from connecting directly to the internet.
The customer recently recovered from a ransomware attack.
The customer plans to deploy Microsoft Sentinel.
You need to recommend configurations to meet the following requirements:
* Ensure that the security operations team can access the security logs and the operation logs.
* Ensure that the IT operations team can access only the operations logs, including the event logs of the servers in the perimeter network.
Which two configurations can you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
  • SC-100 Exam Question 47

    A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription.
    All the on-premises servers in the perimeter network are prevented from connecting directly to the internet.
    The customer recently recovered from a ransomware attack.
    The customer plans to deploy Microsoft Sentinel.
    You need to recommend configurations to meet the following requirements:
    * Ensure that the security operations team can access the security logs and the operation logs.
    * Ensure that the IT operations team can access only the operations logs, including the event logs of the servers in the perimeter network.
    Which two configurations can you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
  • SC-100 Exam Question 48

    You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
    The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
    You need to recommend a solution to ensure that only authorized applications can run on the virtual machines.
    If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
    Which security control should you recommend?
  • SC-100 Exam Question 49

    You receive a security alert in Microsoft Defender for Cloud as shown in the exhibit. (Click the Exhibit tab.)

    After remediating the threat which policy definition should you assign to prevent the threat from reoccurring?
  • SC-100 Exam Question 50

    Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel. You plan to integrate Microsoft Sentinel with Splunk.
    You need to recommend a solution to send security events from Microsoft Sentinel to Splunk. What should you include in the recommendation?