SC-200 Exam Question 11

You have an Azure Sentinel workspace.
You need to test a playbook manually in the Azure portal. From where can you run the test in Azure Sentinel?
  • SC-200 Exam Question 12

    You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector.
    While creating a new rule from a template in the connector, you decide to generate a new alert for every event. You create the following rule query.

    By which two components can you group alerts into incidents? Each correct answer presents a complete solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 13

    Your company uses line-of-business apps that contain Microsoft Office VBA macros.
    You plan to enable protection against downloading and running additional payloads from the Office VBA macros as additional child processes.
    You need to identify which Office VBA macros might be affected.
    Which two commands can you run to achieve the goal? Each correct answer presents a complete solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 14

    You have an Azure subscription linked to an Azure Active Directory (Azure AD) tenant. The tenant contains two users named User1 and User2.
    You plan to deploy Azure Defender.
    You need to enable User1 and User2 to perform tasks at the subscription level as shown in the following table.

    The solution must use the principle of least privilege.
    Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

    SC-200 Exam Question 15

    You need to configure DC1 to meet the business requirements.
    Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.