SC-200 Exam Question 106

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. All endpoint devices are onboarded to Microsoft Defender for Endpoint.
You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace 1. All Microsoft Defender XDR events are ingested into Workspace1.
You have a Microsoft Entra tenant.
You create a KQL query named query1 that searches device logs for a known vulnerability.
You need to ensure that query1 runs every hour. The solution must minimize administrative effort.
What should you configure?
  • SC-200 Exam Question 107

    You create a custom analytics rule to detect threats in Azure Sentinel.
    You discover that the rule fails intermittently.
    What are two possible causes of the failures? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 108

    You have a Microsoft 365 subscription.
    You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.
    You need to ensure that the devices are protected from malicious artifacts that were undetected by the third - party antivirus product.
    Solution: You configure endpoint detection and response (EDR) in block mode.
    Does this meet the goal?
  • SC-200 Exam Question 109

    You have a Microsoft Sentinel workspace named sws1.
    You need to create a hunting query to identify users that list storage keys of multiple Azure Storage accounts.
    The solution must exclude users that list storage keys for a single storage account.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 110

    You have a Microsoft 365 subscription that uses Microsoft Defender XOR and contains a Windows device named Oevice1. You investigate a suspicious process named Prod on Device! by using a live response session. You need to perform the following actions:
    * Stop Prod.
    * Send Prod for further review.
    Which live response command should you run for each action? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.