SC-200 Exam Question 51

You have a Microsoft subscription that has Microsoft Defender for Cloud enabled You configure the Azure logic apps shown in the following table.

You need to configure an automatic action that will run if a Suspicious process executed alert is triggered. The solution must minimize administrative effort.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

SC-200 Exam Question 52

You use Microsoft Sentinel.
You need to receive an alert in near real-time whenever Azure Storage account keys are enumerated. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point
  • SC-200 Exam Question 53

    You have an Azure subscription. The subscription contains 10 virtual machines that are onboarded to Microsoft Defender for Cloud.
    You need to ensure that when Defender for Cloud detects digital currency mining behavior on a virtual machine, you receive an email notification. The solution must generate a test email.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 54

    You have a Microsoft 365 subscription that uses Microsoft 365 Defender and contains a user named User1.
    You are notified that the account of User1 is compromised.
    You need to review the alerts triggered on the devices to which User1 signed in.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 55

    Your company deploys the following services:
    * Microsoft Defender for Identity
    * Microsoft Defender for Endpoint
    * Microsoft Defender for Office 365
    You need to provide a security analyst with the ability to use the Microsoft 365 security center. The analyst must be able to approve and reject pending actions generated by Microsoft Defender for Endpoint. The solution must use the principle of least privilege.
    Which two roles should assign to the analyst? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.