SC-200 Exam Question 101

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring Azure Sentinel.
You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.
Solution: You create a livestream from a query.
Does this meet the goal?
  • SC-200 Exam Question 102

    You have an Azure subscription that uses Microsoft Defender for Cloud.
    You need to configure Defender for Cloud to mitigate the following risks:
    - Vulnerabilities within the application source code
    - Exploitation toolkits in declarative templates
    - Operations from malicious IP addresses
    - Exposed secrets
    Which two Defender for Cloud services should you use? Each correct answer presents part of the solution.
    NOTE: Each correct answer is worth one point.
  • SC-200 Exam Question 103

    Drag and Drop Question
    You have a Microsoft subscription that has Microsoft Defender for Cloud enabled.
    You configure the Azure logic apps shown in the following table.

    You need to configure an automatic action that will run if a Suspicious process executed alert is triggered. The solution must minimize administrative effort.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    SC-200 Exam Question 104

    You have a Microsoft 365 E5 subscription that contains 500 Windows 11 devices.
    You have a Microsoft Defender for Endpoint deployment that has the following settings:
    - Discovery mode: Basic
    - Live Response: Disabled
    - Enable EDR in block mode: Off
    - Tamper Protection: Off
    You need to implement automatic attack disruption in Microsoft Defender XDR.
    What should you do?
  • SC-200 Exam Question 105

    Hotspot Question
    You have an Azure subscription that contains an Microsoft Sentinel workspace.
    You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:
    - Identifies an anomalous number of changes to the rules of a network
    security group (NSG) made by the same security principal
    - Automatically associates the security principal with an Microsoft
    Sentinel entity
    How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.