SC-200 Exam Question 16

You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 17

You receive a security bulletin about a potential attack that uses an image file.
You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent the attack.
Which indicator type should you use?
  • SC-200 Exam Question 18

    Your company deploys Azure Sentinel.
    You plan to delegate the administration of Azure Sentinel to various groups.
    You need to delegate the following tasks:
    Create and run playbooks
    Create workbooks and analytic rules.
    The solution must use the principle of least privilege.
    Which role should you assign for each task? To answer, drag the appropriate roles to the correct tasks. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 19

    You have the following environment:
    Azure Sentinel
    A Microsoft 365 subscription
    Microsoft Defender for Identity
    An Azure Active Directory (Azure AD) tenant
    You configure Azure Sentinel to collect security logs from all the Active Directory member servers and domain controllers.
    You deploy Microsoft Defender for Identity by using standalone sensors.
    You need to ensure that you can detect when sensitive groups are modified in Active Directory.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 20

    You need to restrict cloud apps running on CUENT1 to meet the Microsoft Defender for Endpoint requirements. Which two configurations should you modify? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.