SC-200 Exam Question 101

You have a Microsoft Sentinel playbook that is triggered by using the Azure Activity connector.
You need to create a new near-real-time (NRT) analytics rule that will use the playbook.
What should you configure for the rule?
  • SC-200 Exam Question 102

    You have 50 Microsoft Sentinel workspaces.
    You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort.
    Which page should you use in the Azure portal?
  • SC-200 Exam Question 103

    You have a Microsoft 365 E5 subscription that contains two users named User! and User2. You have the hunting query shown in the following exhibit.

    The users perform the following anions:
    * User1 assigns User2 the Global administrator role.
    * User1 creates a new user named User3 and assigns the user a Microsoft Teams license.
    * User2 creates a new user named User4 and assigns the user the Security reader role.
    * User2 creates a new user named User5 and assigns the user the Security operator role.
    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 104

    You have a custom Microsoft Sentinel workbook named Workbooks.
    You need to add a grid to Workbook1. The solution must ensure that the grid contains a maximum of 100 rows.
    What should you do?
  • SC-200 Exam Question 105

    Your company has an on-premises network that uses Microsoft Defender for Identity.
    The Microsoft Secure Score for the company includes a security assessment associated with unsecure Kerberos delegation.
    You need remediate the security risk.
    What should you do?