SC-200 Exam Question 101
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring Azure Sentinel.
You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.
Solution: You create a livestream from a query.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring Azure Sentinel.
You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.
Solution: You create a livestream from a query.
Does this meet the goal?
SC-200 Exam Question 102
You have an Azure subscription that uses Microsoft Defender for Cloud.
You need to configure Defender for Cloud to mitigate the following risks:
- Vulnerabilities within the application source code
- Exploitation toolkits in declarative templates
- Operations from malicious IP addresses
- Exposed secrets
Which two Defender for Cloud services should you use? Each correct answer presents part of the solution.
NOTE: Each correct answer is worth one point.
You need to configure Defender for Cloud to mitigate the following risks:
- Vulnerabilities within the application source code
- Exploitation toolkits in declarative templates
- Operations from malicious IP addresses
- Exposed secrets
Which two Defender for Cloud services should you use? Each correct answer presents part of the solution.
NOTE: Each correct answer is worth one point.
SC-200 Exam Question 103
Drag and Drop Question
You have a Microsoft subscription that has Microsoft Defender for Cloud enabled.
You configure the Azure logic apps shown in the following table.

You need to configure an automatic action that will run if a Suspicious process executed alert is triggered. The solution must minimize administrative effort.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You have a Microsoft subscription that has Microsoft Defender for Cloud enabled.
You configure the Azure logic apps shown in the following table.

You need to configure an automatic action that will run if a Suspicious process executed alert is triggered. The solution must minimize administrative effort.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

SC-200 Exam Question 104
You have a Microsoft 365 E5 subscription that contains 500 Windows 11 devices.
You have a Microsoft Defender for Endpoint deployment that has the following settings:
- Discovery mode: Basic
- Live Response: Disabled
- Enable EDR in block mode: Off
- Tamper Protection: Off
You need to implement automatic attack disruption in Microsoft Defender XDR.
What should you do?
You have a Microsoft Defender for Endpoint deployment that has the following settings:
- Discovery mode: Basic
- Live Response: Disabled
- Enable EDR in block mode: Off
- Tamper Protection: Off
You need to implement automatic attack disruption in Microsoft Defender XDR.
What should you do?
SC-200 Exam Question 105
Hotspot Question
You have an Azure subscription that contains an Microsoft Sentinel workspace.
You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:
- Identifies an anomalous number of changes to the rules of a network
security group (NSG) made by the same security principal
- Automatically associates the security principal with an Microsoft
Sentinel entity
How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains an Microsoft Sentinel workspace.
You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:
- Identifies an anomalous number of changes to the rules of a network
security group (NSG) made by the same security principal
- Automatically associates the security principal with an Microsoft
Sentinel entity
How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


