SC-200 Exam Question 6

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring Azure Sentinel.
You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.
Solution: You create a Microsoft incident creation rule for a data connector.
Does this meet the goal?
  • SC-200 Exam Question 7

    You have a Microsoft 365 E5 subscription that uses Microsoft SharePoint Online.
    You delete users from the subscription.
    You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.
    What should you use?
  • SC-200 Exam Question 8

    Your company deploys Azure Sentinel.
    You plan to delegate the administration of Azure Sentinel to various groups.
    You need to delegate the following tasks:
    Create and run playbooks
    Create workbooks and analytic rules.
    The solution must use the principle of least privilege.
    Which role should you assign for each task? To answer, drag the appropriate roles to the correct tasks. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 9

    You are informed of an increase in malicious email being received by users.
    You need to create an advanced hunting query in Microsoft 365 Defender to identify whether the accounts of the email recipients were compromised. The query must return the most recent 20 sign-ins performed by the recipients within an hour of receiving the known malicious email.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 10

    You have two Azure subscriptions that use Microsoft Defender for Cloud.
    You need to ensure that specific Defender for Cloud security alerts are suppressed at the root management group level. The solution must minimize administrative effort.
    What should you do in the Azure portal?