SC-200 Exam Question 6

You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You are investigating an incident.
You need to review the incident tasks that were performed. The solution must include a query that will display the incidents in a workbook, and then display the tasks of each incident in another grid.
Which table should you target in the query?
  • SC-200 Exam Question 7

    You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 100 Windows 11 devices that use Microsoft Defender Antivirus. The devices are in a single Microsoft Defender for Endpoint device group.
    You need to ensure that you can block potentially malicious files on the devices by using the Allow or block file option.
    From the Microsoft Defender portal, you set Allow or block file to On.
    What should you do next?
  • SC-200 Exam Question 8

    Hotspot Question
    You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and contains a Windows device named Device1.
    You need to investigate a suspicious executable file detected on Device1. The solution must meet the following requirements:
    - Identify the image file path of the file.
    - Identify when the file was first detected on Device1.
    What should you review from the timeline of the detection event? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 9

    You have a Microsoft 365 E5 subscription that contains a device named Device1.
    From the Microsoft Defender portal, you discover that an alert was triggered for Device1.
    From the Device inventory page, you isolate Device1.
    You need to collect a list of installed programs on Device1.
    What should you do?
  • SC-200 Exam Question 10

    You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 500 devices that are joined to Microsoft Entra, are in the Microsoft Defender for Endpoint default device group, and are managed by using Microsoft Intune.
    You need to implement Microsoft Defender Vulnerability Management. The solution must minimize the administrative effort.
    What should you do first in the Microsoft Defender portal?