SC-200 Exam Question 166
You create an Azure subscription.
You enable Azure Defender for the subscription.
You need to use Azure Defender to protect on-premises computers.
What should you do on the on-premises computers?
You enable Azure Defender for the subscription.
You need to use Azure Defender to protect on-premises computers.
What should you do on the on-premises computers?
SC-200 Exam Question 167
Hotspot Question
You have a Microsoft Sentinel workbook that contains the following KQL query.

You need to create a visual that will change the color of the errCount column based on the value returned.
How should you configure the visual? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft Sentinel workbook that contains the following KQL query.

You need to create a visual that will change the color of the errCount column based on the value returned.
How should you configure the visual? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 168
You have a Microsoft Sentinel workspace that contains the following tables.

You need to investigate the log data by using a search.
Which tables can you search?

You need to investigate the log data by using a search.
Which tables can you search?
SC-200 Exam Question 169
You have a Microsoft 365 subscription that contains 1,000 Windows 10 devices. The devices have Microsoft Office 365 installed.
You need to mitigate the following device threats:
- Microsoft Excel macros that download scripts from untrusted websites
- Users that open executable attachments in Microsoft Outlook
- Outlook rules and forms exploits
What should you use?
You need to mitigate the following device threats:
- Microsoft Excel macros that download scripts from untrusted websites
- Users that open executable attachments in Microsoft Outlook
- Outlook rules and forms exploits
What should you use?
SC-200 Exam Question 170
You have a Microsoft Sentinel workspace.
You are investigating a multi-stage security attack on your environment.
You need to identify the MITRE ATT&CK phases of the tactics and techniques used by the attacker. The solution must minimize administrative effort.
What should you do?
You are investigating a multi-stage security attack on your environment.
You need to identify the MITRE ATT&CK phases of the tactics and techniques used by the attacker. The solution must minimize administrative effort.
What should you do?

