SC-200 Exam Question 41

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have Linux virtual machines on Amazon Web Services (AWS).
You deploy Azure Defender and enable auto-provisioning.
You need to monitor the virtual machines by using Azure Defender.
Solution: You manually install the Log Analytics agent on the virtual machines.
Does this meet the goal?
  • SC-200 Exam Question 42

    You need to remediate active attacks to meet the technical requirements.
    What should you include in the solution?
  • SC-200 Exam Question 43

    You are configuring Azure Sentinel.
    You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.
    Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 44

    You have a Microsoft Sentinel workspace that has User and Entity Behavior Analytics (UEBA) enabled.
    You need to identify all the log entries that relate to security-sensitive user actions performed on a server named Server1. The solution must meet the following requirements:
    * Only include security-sensitive actions by users that are NOT members of the IT department.
    * Minimize the number of false positives.
    How should you complete the query? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 45

    You have a Microsoft Sentinel workspace named sws1.
    You need to create a hunting query to identify users that list storage keys of multiple Azure Storage accounts. The solution must exclude users that list storage keys for a single storage account.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.