SC-200 Exam Question 86

You need to implement the Defender for Cloud requirements.
What should you configure for Server2?
  • SC-200 Exam Question 87

    You have a Microsoft 365 E5 subscription that contains the hosts shown in the following table.
    You have indicators in Microsoft Defender for Endpoint as shown in the following table.
    D1 and ID2 reference the same tile as ID3
    For each of the following statements, select Yes if the statement is true Otherwise, select No.
    NOTE: Each correction selection is worth one point.

    SC-200 Exam Question 88

    You have a Microsoft Sentinel workspace that has a default data retention period of 30 days. The workspace contains two custom tables as shown in the following table.

    Each table ingested two records per day during the past 365 days.
    You build KQL statements for use in analytic rules as shown in the following table.

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 89

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and contains a Windows device named Device1. You need to investigate a suspicious executable file detected on Device1.
    The solution must meet the following requirements:
    * Identify the image file path of the file.
    * Identify when the file was first detected on Device1.
    What should you review from the timeline of the detection event? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 90

    You are configuring Azure Sentinel.
    You need to send a Microsoft Teams message to a channel whenever a sign-in from a suspicious IP address is detected.
    Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.