SC-200 Exam Question 6

You have a Microsoft 365 tenant that uses Microsoft Exchange Online and Microsoft Defender for Office 365.
What should you use to identify whether zero-hour auto purge (ZAP) moved an email message from the mailbox of a user?
  • SC-200 Exam Question 7

    You have an Azure subscription that uses Microsoft Defender XDR.
    From the Microsoft Defender portal, you perform an audit search and export the results as a file named Filel.
    csv that contains 10,000 rows.
    You use Microsoft Excel to perform Get & Transform Data operations to parse the AuditData column from Filel.csv. The operations fail to generate columns for specific JSON properties.
    You need to ensure that Excel generates columns for the specific JSON properties in the audit search results.
    Solution: From Defender, you modify the search criteria of the audit search to reduce the number of returned records, and then you export the results. From Excel, you perform the Get & Transform Data operations by using the new export.
    Does this meet the requirement?
  • SC-200 Exam Question 8

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You are configuring Azure Sentinel.
    You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.
    Solution: You create a scheduled query rule for a data connector.
    Does this meet the goal?
  • SC-200 Exam Question 9

    You have an Azure subscription that contains 50 virtual machines.
    You plan to deploy Microsoft [Defender for Cloud.
    You need to enable agentless scanning for 40 virtual machines. The solution must create disk snapshots of the virtual machines and perform out-of-band analysis of the snapshots.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 10

    You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains a user named user1 and a Microsoft 365 group named Group1. All users are assigned a Defender for Endpoint Plan 1 license.
    You enable Microsoft Defender XDR Unified role-based access control (RBAC) for Endpoints & Vulnerability Management.
    You need to ensure that User1 can configure alerts that will send email notifications to Group1. The solution must follow the principle of least privilege.
    Which permissions should you assign to User1?