SC-200 Exam Question 16

You have the following advanced hunting query in Microsoft 365 Defender.

You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 17

    The issue for which team can be resolved by using Microsoft Defender for Office 365?
  • SC-200 Exam Question 18

    Your company uses Azure Sentinel.
    A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?
  • SC-200 Exam Question 19

    You receive an alert from Azure Defender for Key Vault.
    You discover that the alert is generated from multiple suspicious IP addresses.
    You need to reduce the potential of Key Vault secrets being leaked while you investigate the issue. The solution must be implemented as soon as possible and must minimize the impact on legitimate users.
    What should you do first?
  • SC-200 Exam Question 20

    You plan to create a custom Azure Sentinel query that will track anomalous Azure Active Directory (Azure AD) sign-in activity and present the activity as a time chart aggregated by day.
    You need to create a query that will be used to display the time chart.
    What should you include in the query?