SC-200 Exam Question 11

You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.
Which anomaly detection policy should you use?
  • SC-200 Exam Question 12

    You need to implement the Azure Information Protection requirements.
    What should you configure first?
  • SC-200 Exam Question 13

    The issue for which team can be resolved by using Microsoft Defender for Office 365?
  • SC-200 Exam Question 14

    You need to configure the Azure Sentinel integration to meet the Azure Sentinel requirements.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 15

    You have a playbook in Azure Sentinel.
    When you trigger the playbook, it sends an email to a distribution group.
    You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
    What should you do?