SC-200 Exam Question 41

You need to use an Azure Sentinel analytics rule to search for specific criteria in Amazon Web Services (AWS) logs and to generate incidents.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
a Microsoft 365 E5

SC-200 Exam Question 42

You have an Azure subscription that contains an Azure logic app named app1 and a Microsoft Sentinel workspace that has an Azure AD connector. You need to ensure that app1 launches when Microsoft Sentinel detects an Azure AD-generated alert. What should you create first?
  • SC-200 Exam Question 43

    You have an Azure subscription that has Azure Defender enabled for all supported resource types.
    You create an Azure logic app named LA1.
    You plan to use LA1 to automatically remediate security risks detected in Defenders for Cloud.
    You need to test LA1 in Defender for Cloud.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 44

    You need to modify the anomaly detection policy settings to meet the Microsoft Defender for Cloud Apps requirements and resolve the reported problem.
    Which policy should you modify?
  • SC-200 Exam Question 45

    Your company uses Azure Sentinel.
    A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?