SC-200 Exam Question 21

You need to remediate active attacks to meet the technical requirements.
What should you include in the solution?
  • SC-200 Exam Question 22

    You have a custom analytics rule to detect threats in Azure Sentinel.
    You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED.
    What is a possible cause of the issue?
  • SC-200 Exam Question 23

    You have a Microsoft Sentinel workspace named Workspace1.
    You need to exclude a built-in, source-specific Advanced Security information Model (ASIM) parse from a built-in unified ASIM parser.
    What should you create in Workspace1?
  • SC-200 Exam Question 24

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have Linux virtual machines on Amazon Web Services (AWS).
    You deploy Azure Defender and enable auto-provisioning.
    You need to monitor the virtual machines by using Azure Defender.
    Solution: You enable Azure Arc and onboard the virtual machines to Azure Arc.
    Does this meet the goal?
  • SC-200 Exam Question 25

    You have a suppression rule in Azure Security Center for 10 virtual machines that are used for testing. The virtual machines run Windows Server.
    You are troubleshooting an issue on the virtual machines.
    In Security Center, you need to view the alerts generated by the virtual machines during the last five days.
    What should you do?