SC-200 Exam Question 131
You have 1,000 on-premises Windows 11 Pro devices that are onboarded to Microsoft Defender for Endpoint.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You identify that an attacker performed the following actions on a device:
- Modified the file system path of a registry-based antivirus exclusion
- Downloaded a malicious file to the file system path
You initiate a live response session on the device.
You need to remove the malicious file.
Which command should you run?
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You identify that an attacker performed the following actions on a device:
- Modified the file system path of a registry-based antivirus exclusion
- Downloaded a malicious file to the file system path
You initiate a live response session on the device.
You need to remove the malicious file.
Which command should you run?
SC-200 Exam Question 132
You have a Microsoft Sentinel workspace.
You enable User and Entity Behavior Analytics (UEBA) by using Audit Logs and Signin Logs.
The following entities are detected in the Azure AD tenant:
- App name: App1
- IP address: 192.168.1.2
- Computer name: Device1
- Used client app: Microsoft Edge
- Email address: [email protected]
- Sign-in URL: https://www.company.com
Which entities can be investigated by using UEBA?
You enable User and Entity Behavior Analytics (UEBA) by using Audit Logs and Signin Logs.
The following entities are detected in the Azure AD tenant:
- App name: App1
- IP address: 192.168.1.2
- Computer name: Device1
- Used client app: Microsoft Edge
- Email address: [email protected]
- Sign-in URL: https://www.company.com
Which entities can be investigated by using UEBA?
SC-200 Exam Question 133
Hotspot Question
You have a Microsoft 365 subscription.
You need to identify all the security principals that submitted requests to change or delete groups.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 subscription.
You need to identify all the security principals that submitted requests to change or delete groups.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 134
You have an Azure subscription that uses Microsoft Security Copilot.
You need to temporarily increase the number of security compute units.
What is the smallest interval of time you can be billed for?
You need to temporarily increase the number of security compute units.
What is the smallest interval of time you can be billed for?
SC-200 Exam Question 135
Hotspot Question
You have an Azure subscription that has Microsoft Defender for Cloud enabled for all supported resource types.
You create an Azure logic app named LA1.
You plan to use LA1 to automatically remediate security risks detected in Defender for Cloud.
You need to test LA1 in Defender for Cloud.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that has Microsoft Defender for Cloud enabled for all supported resource types.
You create an Azure logic app named LA1.
You plan to use LA1 to automatically remediate security risks detected in Defender for Cloud.
You need to test LA1 in Defender for Cloud.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.



