SC-200 Exam Question 16
Your company uses Azure Security Center and Azure Defender.
The security operations team at the company informs you that it does NOT receive email notifications for security alerts.
What should you configure in Security Center to enable the email notifications?
The security operations team at the company informs you that it does NOT receive email notifications for security alerts.
What should you configure in Security Center to enable the email notifications?
SC-200 Exam Question 17
You need to update the threat intelligence list to include the entities.
Which entities can you add on the Incident page?
Which entities can you add on the Incident page?
SC-200 Exam Question 18
You have a Microsoft 365 E5 subscription that contains 500 Windows 11 devices.
You have a Microsoft Defender for Endpoint deployment that has the following settings:
* Discovery mode: Basic
* Live Response: Disabled
* Enable EDR in block mode: Off
* Tamper Protection: Off
You need to implement automatic attack disruption in Microsoft Defender XDR.
What should you do?
You have a Microsoft Defender for Endpoint deployment that has the following settings:
* Discovery mode: Basic
* Live Response: Disabled
* Enable EDR in block mode: Off
* Tamper Protection: Off
You need to implement automatic attack disruption in Microsoft Defender XDR.
What should you do?
SC-200 Exam Question 19
You need to deploy the native cloud connector to Account! to meet the Microsoft Defender for Cloud requirements. What should you do in Account! first?
SC-200 Exam Question 20
You have a Microsoft Sentinel workspace named sws1.
You plan to create an Azure logic app that will raise an incident in an on-premises IT service management system when an incident is generated in sws1.
You need to configure the Microsoft Sentinel connector credentials for the logic app. The solution must meet the following requirements:
* Minimize administrative effort.
* Use the principle of least privilege.
How should you configure the credentials? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to create an Azure logic app that will raise an incident in an on-premises IT service management system when an incident is generated in sws1.
You need to configure the Microsoft Sentinel connector credentials for the logic app. The solution must meet the following requirements:
* Minimize administrative effort.
* Use the principle of least privilege.
How should you configure the credentials? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.



