SC-200 Exam Question 1

Your company uses line-of-business apps that contain Microsoft Office VBA macros.
You plan to enable protection against downloading and running additional payloads from the Office VBA macros as additional child processes.
You need to identify which Office VBA macros might be affected.
Which two commands can you run to achieve the goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 2

    You have a playbook in Azure Sentinel.
    When you trigger the playbook, it sends an email to a distribution group.
    You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
    What should you do?
  • SC-200 Exam Question 3

    You have a Microsoft Sentinel workspace named workspace1 and an Azure virtual machine named VM1.
    You receive an alert for suspicious use of PowerShell on VM1.
    You need to investigate the incident, identify which event triggered the alert, and identify whether the following actions occurred on VM1 after the alert:
    The modification of local group memberships
    The purging of event logs
    Which three actions should you perform in sequence in the Azure portal? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 4

    You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector.
    While creating a new rule from a template in the connector, you decide to generate a new alert for every event. You create the following rule query.

    By which two components can you group alerts into incidents? Each correct answer presents a complete solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 5

    You need to configure the Microsoft Sentinel integration to meet the Microsoft Sentinel requirements. What should you do? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.