SC-200 Exam Question 31

You have resources in Azure and Google cloud.
You need to ingest Google Cloud Platform (GCP) data into Azure Defender.
In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

SC-200 Exam Question 32

You have a Microsoft 365 subscription that uses Microsoft 365 Defender and contains a user named User1.
You are notified that the account of User1 is compromised.
You need to review the alerts triggered on the devices to which User1 signed in.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 33

You have a Microsoft Sentinel workspace named workspace1 that contains custom Kusto queries.
You need to create a Python-based Jupyter notebook that will create visuals. The visuals will display the results of the queries and be pinned to a dashboard. The solution must minimize development effort.
What should you use to create the visuals?
  • SC-200 Exam Question 34

    You have the resources shown in the following table.

    You need to prevent duplicate events from occurring in SW1.
    What should you use for each action? To answer, drag the appropriate resources to the correct actions. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 35

    You have an Azure subscription that uses Microsoft Sentinel.
    You detect a new threat by using a hunting query.
    You need to ensure that Microsoft Sentinel automatically detects the threat. The solution must minimize administrative effort.
    What should you do?