SC-200 Exam Question 1

You have an Azure subscription that uses Microsoft Defender for Endpoint.
You need to ensure that you can allow or block a user-specified range of IP addresses and URLs.
What should you enable first in the advanced features from the Endpoints Settings in the Microsoft 365 Defender portal?
  • SC-200 Exam Question 2

    Your company uses Azure Sentinel to manage alerts from more than 10,000 IoT devices.
    A security manager at the company reports that tracking security threats is increasingly difficult due to the large number of incidents.
    You need to recommend a solution to provide a custom visualization to simplify the investigation of threats and to infer threats by using machine learning.
    What should you include in the recommendation?
  • SC-200 Exam Question 3

    You have an Azure subscription that contains an Azure logic app named app1 and a Microsoft Sentinel workspace that has an Azure AD connector. You need to ensure that app1 launches when Microsoft Sentinel detects an Azure AD-generated alert. What should you create first?
  • SC-200 Exam Question 4

    You need to create a query for a workbook. The query must meet the following requirements:
    List all incidents by incident number.
    Only include the most recent log for each incident.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 5

    The issue for which team can be resolved by using Microsoft Defender for Endpoint?