SC-200 Exam Question 126

You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps and has Cloud Discovery enabled.
You need to enrich the Cloud Discovery data. The solution must ensure that usernames in the Cloud Discovery traffic logs are associated with the user principal name (UPN) of the corresponding Microsoft Entra ID user accounts.
What should you do first?
  • SC-200 Exam Question 127

    You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com.
    Contoso.com contains a user named User1. Sub1 contains a Microsoft Sentinel workspace.
    You provision a Microsoft Copilot for Security capacity.
    You need to ensure that User1 can use Copilot for Security to perform the following tasks:
    . Update the data sharing and feedback options.
    . Investigate Microsoft Sentinel incidents.
    The solution must follow the principle of least privilege.
    Which role should you assign to User1 for each task? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point

    SC-200 Exam Question 128

    You use Azure Defender.
    You have an Azure Storage account that contains sensitive information.
    You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 129

    You manage the security posture of an Azure subscription that contains two virtual machines name vm1 and vm2.
    The secure score in Azure Security Center is shown in the Security Center exhibit. (Click the Security Center tab.)

    Azure Policy assignments are configured as shown in the Policies exhibit. (Click the Policies tab.)

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 130

    You have a Microsoft 365 E5 subscription that is linked to a hybrid Azure AD tenant.
    You need to identify all the changes made to Domain Admins group during the past 30 days.
    What should you use?