SC-200 Exam Question 196

Hotspot Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You have an Azure subscription that contains a Log Analytics workspace named Workspace1.
You forward all logs to Workspace1.
You need to identify all the applications and security principals that made requests to modify Microsoft Entra groups during the previous 24 hours.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 197

You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace1.
From Content Hub, you deploy the Microsoft Entra solution for Microsoft Sentinel and configure a connector.
You need to analyze actions performed by users that have administrative privileges to the subscription.
Which workbook should you use?
  • SC-200 Exam Question 198

    Which of the below artifact types contains an investigation page?
  • SC-200 Exam Question 199

    Hotspot Question
    You are informed of an increase in malicious email being received by users.
    You need to create an advanced hunting query in Microsoft 365 Defender to identify whether the accounts of the email recipients were compromised. The query must return the most recent 20 sign-ins performed by the recipients within an hour of receiving the known malicious email.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 200

    Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
    After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
    You have a Microsoft 365 subscription.
    You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.
    You need to ensure that the devices are protected from malicious artifacts that were undetected by the third-party antivirus product.
    Solution: You configure Controlled folder access.
    Does this meet the goal?