SC-200 Exam Question 146

You use Azure Defender.
You have an Azure Storage account that contains sensitive information.
You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 147

    Hotspot Question
    You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint.
    You need to create a detection rule that meets the following requirements:
    - Is triggered when a device that has critical software vulnerabilities was active during the last hour
    - Limits the number of duplicate results
    How should you complete the KQL query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 148

    You have an Azure subscription that uses Microsoft Sentinel.
    You need to create a custom workbook that will calculate the average time it takes to close security incidents. The solution must minimize administrative effort.
    Which built-in Microsoft Sentinel workbook template should you select?
  • SC-200 Exam Question 149

    Drag and Drop Question
    You have the resources shown in the following table.

    You need to prevent duplicate events from occurring in SW1.
    What should you use for each action? To answer, drag the appropriate resources to the correct actions. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 150

    Hotspot Question
    You have a Microsoft 365 E5 subscription that contains 200 Windows 10 devices enrolled in Microsoft Defender for Endpoint.
    You need to ensure that users can access the devices by using a remote shell connection directly from the Microsoft 365 Defender portal. The solution must use the principle of least privilege.
    What should you do in the Microsoft 365 Defender portal? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.