SC-200 Exam Question 36

You have a Microsoft Sentinel workspace.
You have a query named Query1 as shown in the following exhibit.

You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1. What should you do first?
  • SC-200 Exam Question 37

    You have an Azure subscription that uses Microsoft Sentinel.
    You detect a new threat by using a hunting query.
    You need to ensure that Microsoft Sentinel automatically detects the threat. The solution must minimize administrative effort.
    What should you do?
  • SC-200 Exam Question 38

    You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.
    Which anomaly detection policy should you use?
  • SC-200 Exam Question 39

    You create a new Azure subscription and start collecting logs for Azure Monitor.
    You need to configure Azure Security Center to detect possible threats related to sign-ins from suspicious IP addresses to Azure virtual machines. The solution must validate the configuration.
    Which three actions should you perform in a sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.

    SC-200 Exam Question 40

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You are configuring Azure Sentinel.
    You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.
    Solution: You create a hunting bookmark.
    Does this meet the goal?