SC-200 Exam Question 21

You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?
  • SC-200 Exam Question 22

    You need to complete the query for failed sign-ins to meet the technical requirements.
    Where can you find the column name to complete the where clause?
  • SC-200 Exam Question 23

    You have an Azure subscription that uses Microsoft Defender for Cloud.
    You have a GitHub account named Account1 that contains 10 repositories.
    You need to ensure that Defender for Cloud can assess the repositories in Account1.
    What should you do first in the Microsoft Defender for Cloud portal?
  • SC-200 Exam Question 24

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR and contains a Windows device named Device1.
    You detect malicious activity on Device1.
    You initiate a live response session on Device1.
    You need to perform the following actions:
    * Download a file from the live response library.
    * Stop a process that is running on Device1.
    Which live response command should you run for each action? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 25

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender 36S.
    Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD.
    You need to identify the 100 most recent sign-in attempts recorded on devices and AD DS domain controllers.
    How should you complete The KQL query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.