SC-200 Exam Question 51

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring Microsoft Defender for Identity integration with Active Directory.
From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit.
Solution: You add each account as a Sensitive account.
Does this meet the goal?
  • SC-200 Exam Question 52

    You receive an alert from Azure Defender for Key Vault.
    You discover that the alert is generated from multiple suspicious IP addresses.
    You need to reduce the potential of Key Vault secrets being leaked while you investigate the issue. The solution must be implemented as soon as possible and must minimize the impact on legitimate users.
    What should you do first?
  • SC-200 Exam Question 53

    You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
    You deploy Azure Sentinel.
    You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
  • SC-200 Exam Question 54

    You have an Azure subscription that contains an Microsoft Sentinel workspace.
    You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:
    * Identifies an anomalous number of changes to the rules of a network security group (NSG) made by the same security principal
    * Automatically associates the security principal with an Microsoft Sentinel entity How should you complete the query? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 55

    You have a Microsoft 365 E5 subscription that uses Microsoft SharePoint Online.
    You delete users from the subscription.
    You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.
    What should you use?