SC-200 Exam Question 16

You have an Azure subscription that uses Microsoft Sentinel.
You need to create a custom report that will visualise sign-in information over time.
What should you create first?
  • SC-200 Exam Question 17

    You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
    What should you include in the solution? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 18

    Your company stores the data for every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant.
    Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription.
    You deploy Azure Sentinel to a new Azure subscription.
    You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 19

    You have an Azure subscription that contains an Microsoft Sentinel workspace.
    You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:
    * Identifies an anomalous number of changes to the rules of a network security group (NSG) made by the same security principal
    * Automatically associates the security principal with an Microsoft Sentinel entity How should you complete the query? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 20

    You have an Azure subscription. The subscription contains 10 virtual machines that are onboarded to Microsoft Defender for Cloud.
    You need to ensure that when Defender for Cloud detects digital currency mining behavior on a virtual machine, you receive an email notification. The solution must generate a test email.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.