SC-200 Exam Question 46

You need to ensure that you can run hunting queries to meet the Microsoft Sentinel requirements. Which type of workspace should you create?
  • SC-200 Exam Question 47

    You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
    You deploy Azure Sentinel.
    You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
  • SC-200 Exam Question 48

    You have an Azure subscription.
    You need to delegate permissions to meet the following requirements:
    Enable and disable Azure Defender.
    Apply security recommendations to resource.
    The solution must use the principle of least privilege.
    Which Azure Security Center role should you use for each requirement? To answer, drag the appropriate roles to the correct requirements. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 49

    You have a Microsoft 365 tenant that uses Microsoft Exchange Online and Microsoft Defender for Office 365.
    What should you use to identify whether zero-hour auto purge (ZAP) moved an email message from the mailbox of a user?
  • SC-200 Exam Question 50

    You have a Microsoft 365 E5 subscription that contains 200 Windows 10 devices enrolled in Microsoft Defender for Endpoint.
    You need to ensure that users can access the devices by using a remote shell connection directly from the Microsoft 365 Defender portal. The solution must use the principle of least privilege.
    What should you do in the Microsoft 365 Defender portal? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.