SC-200 Exam Question 1

You need to use an Azure Resource Manager template to create a workflow automation that will trigger an automatic remediation when specific security alerts are received by Azure Security Center.
How should you complete the portion of the template that will provision the required Azure resources? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 2

You are configuring Azure Sentinel.
You need to send a Microsoft Teams message to a channel whenever a sign-in from a suspicious IP address is detected.
Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 3

    You plan to connect an external solution that will send Common Event Format (CEF) messages to Azure Sentinel.
    You need to deploy the log forwarder.
    Which three actions should you perform in sequence? To answer, move the appropriate actions form the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 4

    You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.
    What should you include in the solution? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 5

    You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.
    What should you recommend for each threat? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.