SC-200 Exam Question 111

You have an Azure subscription named Sub1 and an Azure DevOps organization named AzDO1. AzDO1 uses Defender for Cloud and contains a project that has a YAML pipeline named Pipeline1.
Pipeline1 outputs the details of discovered open source software vulnerabilities to Defender for Cloud.
You need to configure Pipeline1 to output the results of secret scanning to Defender for Cloud, What should you add to Pipeline1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 112

You have a Microsoft Sentinel workspace
You develop a custom Advanced Security information Model (ASIM) parser named Parser1 that produces a schema named Schema1.
You need to validate Schema1.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 113

You have a Microsoft Sentinel workspace.
You need to prevent a built-in Advance Security information Model (ASIM) parse from being updated automatically.
What are two ways to achieve this goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 114

    You have a Microsoft Sentinel workspace that contains a custom workbook.
    You need to query the number of daily security alerts. The solution must meet the following requirements:
    * Identify alerts that occurred during the last 30 days.
    * Display the results in a timechart.
    How should you complete the query? To answer, select the appropriate options in the answer area. NOTE:
    Each correct selection is worth one point.

    SC-200 Exam Question 115

    You have an Azure subscription that uses Microsoft Defender for Endpoint.
    You need to ensure that you can allow or block a user-specified range of IP addresses and URLs.
    What should you enable first in the advanced features from the Endpoints Settings in the Microsoft 365 Defender portal?