SC-200 Exam Question 71

You have an Azure subscription that uses Microsoft Defender for Cloud.
You have an Amazon Web Services (AWS) account that contains an Amazon Elastic Compute Cloud (EC2) instance named EC2-1.
You need to onboard EC2-1 to Defender for Cloud.
What should you install on EC2-1?
  • SC-200 Exam Question 72

    You have an Azure Sentinel workspace.
    You need to test a playbook manually in the Azure portal. From where can you run the test in Azure Sentinel?
  • SC-200 Exam Question 73

    You have an Azure subscription that contains a virtual machine named VM1 and uses Azure Defender. Azure Defender has automatic provisioning enabled.
    You need to create a custom alert suppression rule that will supress false positive alerts for suspicious use of PowerShell on VM1.
    What should you do first?
  • SC-200 Exam Question 74

    You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace1 and a user named User1.
    You need to ensure that User1 can investigate incidents by using Workspace1. The solution must follow the principle of least privilege.
    Which role should you assign to User1?
  • SC-200 Exam Question 75

    You are investigating an incident by using Microsoft 365 Defender.
    You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop. CEOLaptop, and COOLaptop.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE Each correct selection is worth one point