SC-200 Exam Question 46

You create an Azure subscription named sub1.
In sub1, you create a Log Analytics workspace named workspace1.
You enable Azure Security Center and configure Security Center to use workspace1.
You need to ensure that Security Center processes events from the Azure virtual machines that report to workspace1.
What should you do?
  • SC-200 Exam Question 47

    You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1.
    You enable agentless scanning.
    You need to prevent Server1 from being scanned. The solution must minimize administrative effort.
    What should you do?
  • SC-200 Exam Question 48

    You have a Microsoft Sentinel workspace.
    You have a query named Query1 as shown in the following exhibit.

    You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1. What should you do first?
  • SC-200 Exam Question 49

    You have a playbook in Azure Sentinel.
    When you trigger the playbook, it sends an email to a distribution group.
    You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
    What should you do?
  • SC-200 Exam Question 50

    You are informed of a new common vulnerabilities and exposures (CVE) vulnerability that affects your environment.
    You need to use the Microsoft Defender portal to request remediation from the team responsible for the affected systems if there is a documented active exploit available.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.