SC-200 Exam Question 1

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.
You need to identify LDAP requests by AD DS users to enumerate AD DS objects.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 2

You have an Azure subscription that uses Microsoft Sentinel and contains a user named User1.
You need to ensure that User1 can enable User and Entity Behavior Analytics (UEBA) for entity behavior in Azure AD The solution must use The principle of least privilege.
Which roles should you assign to Used? To answer select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 3

The issue for which team can be resolved by using Microsoft Defender for Endpoint?
  • SC-200 Exam Question 4

    You have a Microsoft Sentinel workspace that has User and Entity Behavior Analytics (UEBA) enabled.
    You need to identify all the log entries that relate to security-sensitive user actions performed on a server named Server1. The solution must meet the following requirements:
    * Only include security-sensitive actions by users that are NOT members of the IT department.
    * Minimize the number of false positives.
    How should you complete the query? To answer, select the appropriate options in the answer area. NOTE:
    Each correct selection is worth one point.

    SC-200 Exam Question 5

    You have an Azure subscription that contains a Log Analytics workspace named Workspace1.
    You configure Azure activity logs and Microsoft Entra ID logs to be forwarded to Workspace1.
    You need to identify which Azure resources have been queried or modified by risky users.
    How should you complete the KQL query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.