SC-200 Exam Question 171
Hotspot Question
You have an Azure environment that contains 50 subscriptions, including a subscription named Sub1. Sub1 contains a Microsoft Sentinel workspace named Workspace1 that collects logs from the other subscriptions. Workspace1 contains a workbook named WB1.
To WB1, you add a parameters item named Item1. To Item1, you add a parameter named Parameter1.
You need to configure the drop-down menu for Parameter1 to meet the following requirements:
- Ensure that users can select one or more subscriptions to query.
- Provide users with a single option to query all the subscriptions.
The solution must minimize how long it takes to populate WB1 with data. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure environment that contains 50 subscriptions, including a subscription named Sub1. Sub1 contains a Microsoft Sentinel workspace named Workspace1 that collects logs from the other subscriptions. Workspace1 contains a workbook named WB1.
To WB1, you add a parameters item named Item1. To Item1, you add a parameter named Parameter1.
You need to configure the drop-down menu for Parameter1 to meet the following requirements:
- Ensure that users can select one or more subscriptions to query.
- Provide users with a single option to query all the subscriptions.
The solution must minimize how long it takes to populate WB1 with data. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 172
Hotspot Question
You have an Azure subscription that contains a Log Analytics workspace named Workspace1.
You configure Azure activity logs and Microsoft Entra ID logs to be forwarded to Workspace1.
You need to identify which Azure resources have been queried or modified by risky users.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains a Log Analytics workspace named Workspace1.
You configure Azure activity logs and Microsoft Entra ID logs to be forwarded to Workspace1.
You need to identify which Azure resources have been queried or modified by risky users.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 173
Hotspot Question
You have an Azure subscription named Sub1 that contains a Microsoft Sentinel workspace named WS1.
You need to create a hunting query in WS1 that meets the following requirements:
- Returns the number of changes performed daily by each Microsoft Entra security principal during a seven-day period
- Identifies all the successful changes to the resources in Sub1
- Substitutes any missing data points with 0
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure subscription named Sub1 that contains a Microsoft Sentinel workspace named WS1.
You need to create a hunting query in WS1 that meets the following requirements:
- Returns the number of changes performed daily by each Microsoft Entra security principal during a seven-day period
- Identifies all the successful changes to the resources in Sub1
- Substitutes any missing data points with 0
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 174
Hotspot Question
You have an Azure subscription that is linked to a hybrid Azure AD tenant and contains a Microsoft Sentinel workspace named Sentinel1.
You need to enable User and Entity Behavior Analytics (UEBA) for Sentinel and configure UEBA to use data collected from Active Directory Domain Services (AD DS).
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that is linked to a hybrid Azure AD tenant and contains a Microsoft Sentinel workspace named Sentinel1.
You need to enable User and Entity Behavior Analytics (UEBA) for Sentinel and configure UEBA to use data collected from Active Directory Domain Services (AD DS).
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 175
You have a Microsoft 365 E5 subscription that uses Microsoft SharePoint Online.
You delete users from the subscription.
You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.
What should you use?
You delete users from the subscription.
You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.
What should you use?




