SC-200 Exam Question 76

Hotspot Question
You have a Microsoft 365 E5 subscription.
You need to create a hunting query that will return every email that contains an attachment named Document.pdf. The query must meet the following requirements:
- Only show emails sent during the last hour.
- Optimize query performance.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 77

You are configuring Azure Sentinel.
You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.
Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 78

    Which selection is an ASR (attack surface reduction) rule that can be implemented and blocked?
  • SC-200 Exam Question 79

    Drag and Drop Question
    You have an Azure subscription that contains a Microsoft Sentinel workspace.
    You need to create and customize a workbook for the Microsoft Entra ID Audit Logs.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 80

    Hotspot Question
    You have a Microsoft Sentinel workspace that contains a table named Table1. Table1 has the Analytics plan configured.
    You need to configure the retention period for Table1. The solution must maximize the retention of data stored in Table1.
    How should you configure the Data retention settings? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.