SC-200 Exam Question 46

You have an Azure subscription that uses Microsoft Defender for Cloud and contains a storage account named storage1. You receive an alert that there was an unusually high volume of delete operations on the blobs in storage1.
You need to identify which blobs were deleted.
What should you review?
  • SC-200 Exam Question 47

    You have four Azure subscriptions. One of the subscriptions contains a Microsoft Sentinel workspace.
    You need to deploy Microsoft Sentinel data connectors to collect data from the subscriptions by using Azure Policy. The solution must ensure that the policy will apply to new and existing resources in the subscriptions.
    Which type of connectors should you provision, and what should you use to ensure that all the resources are monitored? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 48

    You need to implement Microsoft Defender for Cloud to meet the Microsoft Defender for Cloud requirements and the business requirements. What should you include in the solution? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 49

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have Linux virtual machines on Amazon Web Services (AWS).
    You deploy Azure Defender and enable auto-provisioning.
    You need to monitor the virtual machines by using Azure Defender.
    Solution: You enable Azure Arc and onboard the virtual machines to Azure Arc.
    Does this meet the goal?
  • SC-200 Exam Question 50

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
    The security team at your company detects command and control (C2) agent traffic on the network. Agents communicate once every 50 hours.
    You need to create a Microsoft Defender XDR custom detection rule that will identify compromised devices and establish a pattern of communication. The solution must meet the following requirements:
    * Identify all the devices that have communicated during the past 14 days.
    * Minimize how long it takes to identify the devices.
    To what should you set the detection frequency for the rule?