SC-200 Exam Question 56

You have 500 on-premises Windows 11 devices that use Microsoft Defender for Endpoint You enable Network device discovery.
You need to create a hunting query that will identify discovered network devices and return the identity of the onboarded device that discovered each network device.
Which built-in function should you use?
  • SC-200 Exam Question 57

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have Linux virtual machines on Amazon Web Services (AWS).
    You deploy Azure Defender and enable auto-provisioning.
    You need to monitor the virtual machines by using Azure Defender.
    Solution: You manually install the Log Analytics agent on the virtual machines.
    Does this meet the goal?
  • SC-200 Exam Question 58

    You have a Microsoft 365 E5 subscription that is linked to a Microsoft Entra tenant named contoso.com.
    You need to query Microsoft Graph activity logs to identify changes to the roles in contoso.com.
    How should you complete the KQL query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 59

    A company wants to analyze by using Microsoft 365 Apps.
    You need to describe the connected experiences the company can use.
    Which connected experiences should you describe? To answer, drag the appropriate connected experiences to the correct description. Each connected experience may be used once, more than once, or not at all. You may need to drag the split between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 60

    You are investigating an incident by using Microsoft 365 Defender.
    You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop. CEOLaptop, and COOLaptop.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE Each correct selection is worth one point