SC-200 Exam Question 106

You have 100 Azure subscriptions that have enhanced security features m Microsoft Defender for Cloud enabled. All the subscriptions are linked to a single Azure AD tenant. You need to stream the Defender for Cloud togs to a syslog server. The solution must minimize administrative effort What should you do? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point

SC-200 Exam Question 107

You need to ensure that you can run hunting queries to meet the Microsoft Sentinel requirements. Which type of workspace should you create?
  • SC-200 Exam Question 108

    You open the Cloud App Security portal as shown in the following exhibit.

    You need to remediate the risk for the Launchpad app.
    Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 109

    You have a Microsoft 365 E5 subscription that uses Microsoft SharePoint Online.
    You delete users from the subscription.
    You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.
    What should you use?
  • SC-200 Exam Question 110

    You have a Microsoft Sentinel workspace.
    You need to create a KQL query that will identify successful sign-ins from multiple countries during the last three hours.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point