SC-200 Exam Question 91

You have the resources shown in the following table.

You need to prevent duplicate events from occurring in SW1.
What should you use for each action? To answer, drag the appropriate resources to the correct actions. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 92

You have a Microsoft 365 E5 subscription that contains 100 Linux devices. The devices are onboarded to Microsoft Defender 365. You need to initiate the collection of investigation packages from the devices by using the Microsoft 365 Defender portal. Which response action should you use?
  • SC-200 Exam Question 93

    You have 50 on-premises servers.
    You have an Azure subscription that uses Microsoft Defender for Cloud. The Defender for Cloud deployment has Microsoft Defender for Servers and automatic provisioning enabled.
    You need to configure Defender for Cloud to support the on-premises servers. The solution must meet the following requirements:
    * Provide threat and vulnerability management.
    * Support data collection rules.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 94

    You create a new Azure subscription and start collecting logs for Azure Monitor.
    You need to validate that Microsoft Defender for Cloud will trigger an alert when a malicious file is present on an Azure virtual machine running Windows Server.
    Which three actions should you perform in a sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.
    NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.

    SC-200 Exam Question 95

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender 36S.
    Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD.
    You need to identify the 100 most recent sign-in attempts recorded on devices and AD DS domain controllers.
    How should you complete The KQL query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.