SC-200 Exam Question 66

You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?
  • SC-200 Exam Question 67

    HOTSPOT
    You have a Microsoft 365 E5 subscription.
    You plan to perform cross-domain investigations by using Microsoft 365 Defender.
    You need to create an advanced hunting query to identify devices affected by a malicious email attachment.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.
    Hot Area:

    SC-200 Exam Question 68

    You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
    You deploy Azure Sentinel.
    You need to use the existing logic app as a playbook in Azure Sentinel.
    What should you do first?
  • SC-200 Exam Question 69

    You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
    What should you use?
  • SC-200 Exam Question 70

    You have a custom analytics rule to detect threats in Azure Sentinel.
    You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED.
    What is a possible cause of the issue?