SC-200 Exam Question 56

You have an Azure subscription that uses Microsoft Defender for Cloud.
You have a GitHub account named Account1 that contains 10 repositories.
You need to ensure that Defender for Cloud can assess the repositories in Account1.
What should you do first in the Microsoft Defender for Cloud portal?
  • SC-200 Exam Question 57

    You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled.
    You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1.
    What should you do first?
  • SC-200 Exam Question 58

    You have a Microsoft 365 E5 subscription that contains 200 Windows 10 devices enrolled in Microsoft Defender for Endpoint.
    You need to ensure that users can access the devices by using a remote shell connection directly from the Microsoft 365 Defender portal. The solution must use the principle of least privilege.
    What should you do in the Microsoft 365 Defender portal? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 59

    You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1.
    You enable agentless scanning.
    You need to prevent Server1 from being scanned. The solution must minimize administrative effort.
    What should you do?
  • SC-200 Exam Question 60

    You have a Microsoft Sentinel workspace that has user and Entity Behavior Analytics (UEBA) enabled for Signin Logs.
    You need to ensure that failed interactive sign-ins are detected.
    The solution must minimize administrative effort.
    What should you use?