SC-200 Exam Question 41

You have a Microsoft Sentinel workspace named workspace1 that contains custom Kusto queries.
You need to create a Python-based Jupyter notebook that will create visuals. The visuals will display the results of the queries and be pinned to a dashboard. The solution must minimize development effort.
What should you use to create the visuals?
  • SC-200 Exam Question 42

    You have a third-party security information and event management (SIEM) solution.
    You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in near real time.
    What should you do to route events to the SIEM solution?
  • SC-200 Exam Question 43

    You have resources in Azure and Google cloud.
    You need to ingest Google Cloud Platform (GCP) data into Azure Defender.
    In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 44

    You have the following environment:
    Azure Sentinel
    A Microsoft 365 subscription
    Microsoft Defender for Identity
    An Azure Active Directory (Azure AD) tenant
    You configure Azure Sentinel to collect security logs from all the Active Directory member servers and domain controllers.
    You deploy Microsoft Defender for Identity by using standalone sensors.
    You need to ensure that you can detect when sensitive groups are modified in Active Directory.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 45

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You are configuring Microsoft Defender for Identity integration with Active Directory.
    From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit.
    Solution: You add the accounts to an Active Directory group and add the group as a Sensitive group.
    Does this meet the goal?