SC-200 Practice Test Questions

156 Questions


Topic 3: Misc. Questions

Your company stores the data for every project in a different Azure subscription. All the
subscriptions use the same Azure Active Directory (Azure AD) tenant.
Every project consists of multiple Azure virtual machines that run Windows Server. The
Windows events of the virtual machines are stored in a Log Analytics workspace in each
machine’s respective subscription.
You deploy Azure Sentinel to a new Azure subscription.
You need to perform hunting queries in Azure Sentinel to search across all the Log
Analytics workspaces of all the subscriptions.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.


A.

Add the Security Events connector to the Azure Sentinel workspace.


B.

Create a query that uses the workspace expression and the union operator.


C.

Use the alias statement.


D.

Create a query that uses the resource expression and the alias operator.


E.

Add the Azure Sentinel solution to each workspace.





B.
  

Create a query that uses the workspace expression and the union operator.



E.
  

Add the Azure Sentinel solution to each workspace.



You have a Microsoft 365 subscription that uses Microsoft 365 Defender A remediation
action for an automated investigation quarantines a file across multiple devices. You need
to mark the file as safe and remove the file from quarantine on the devices. What should
you use m the Microsoft 365 Defender portal?


A.

From Threat tracker, review the queries.


B.

From the History tab in the Action center, revert the actions


C.

From the investigation page, review the AIR processes.


D.

From Quarantine from the Review page, modify the rules.





B.
  

From the History tab in the Action center, revert the actions



You have an Azure Sentinel workspace.
You need to test a playbook manually in the Azure portal. From where can you run the test
in Azure Sentinel?


A.

Playbooks


B.

Analytics


C.

Threat intelligence


D.

Incidents





D.
  

Incidents



You have an Azure subscription that has Azure Defender enabled for all supported
resource types.
You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution.
To which service should you export the alerts?


A.

Azure Cosmos DB


B.

Azure Event Grid


C.

Azure Event Hubs


D.

Azure Data Lake





C.
  

Azure Event Hubs



You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.
You need to add threat indicators for all the IP addresses in a range of 171.23.3432-
171.2334.63. The solution must minimize administrative effort.
What should you do in the Microsoft 365 Defender portal?


A.

Create an import file that contains the IP address of 171.23.34.32/27. Select Import
and import the file.


B.

Select Add indicator and set the IP address to 171.2334.32-171.23.34.63.


C.

Select Add indicator and set the IP address to 171.23.34.32/27


D.

Create an import file that contains the individual IP addresses in the range. Select
Import and import the file.





C.
  

Select Add indicator and set the IP address to 171.23.34.32/27



Explanation: This will add all the IP addresses in the range of 171.23.34.32/27 as threat
indicators. This is the simplest and most efficient way to add all the IP addresses in the
range.
Reference: [1] https://docs.microsoft.com/en-us/windows/security/threatprotection/
microsoft-defender-atp/threat-intelligence-manage-indicators

You use Azure Sentinel.
You need to receive an immediate alert whenever Azure Storage account keys are
enumerated. Which two actions should you perform? Each correct answer presents part of
the solution.
NOTE: Each correct selection is worth one point.


A.

Create a livestream


B.

Add a data connector


C.

Create an analytics rule


D.

Create a hunting query


E.

Create a bookmark.





B.
  

Add a data connector



C.
  

Create an analytics rule



Explanation:
B: To add a data connector, you would use the Azure Sentinel data connectors feature to
connect to your Azure subscription and to configure log data collection for Azure Storage
account key enumeration events.
C: After adding the data connector, you need to create an analytics rule to analyze the log
data from the Azure storage connector, looking for the specific event of Azure storage
account keys enumeration. This rule will trigger an alert when it detects the specific event,
allowing you to take immediate action.

Your company uses Azure Sentinel.
A new security analyst reports that she cannot assign and dismiss incidents in Azure
Sentinel. You need to resolve the issue for the analyst. The solution must use the principle
of least privilege. Which role should you assign to the analyst?


A.

Azure Sentinel Responder


B.

Logic App Contributor


C.

Azure Sentinel Contributor


D.

Azure Sentinel Reader





A.
  

Azure Sentinel Responder



A security administrator receives email alerts from Azure Defender for activities such as
potential malware uploaded to a storage account and potential successful brute force
attacks.
The security administrator does NOT receive email alerts for activities such as antimalware
action failed and suspicious network activity. The alerts appear in Azure Security Center.
You need to ensure that the security administrator receives email alerts for all the activities.
What should you configure in the Security Center settings?


A.

the severity level of email notifications


B.

a cloud connector


C.

the Azure Defender plans


D.

the integration settings for Threat detection





A.
  

the severity level of email notifications



You have five on-premises Linux servers.
You have an Azure subscription that uses Microsoft Defender for Cloud.
You need to use Defender for Cloud to protect the Linux servers.
What should you install on the servers first?


A.

the Dependency agent


B.

the Log Analytics agent


C.

the Azure Connected Machine agent


D.

the Guest Configuration extension





B.
  

the Log Analytics agent



Explanation:
Defender for Cloud depends on the Log Analytics agent.
Use the Log Analytics agent if you need to:
* Collect logs and performance data from Azure virtual machines or hybrid machines
hosted outside of Azure
* Etc.
Reference:
https://docs.microsoft.com/en-us/azure/defender-for-cloud/os-coverage
https://docs.microsoft.com/en-us/azure/azure-monitor/agents/agents-overview#loganalytics-
agent

Your company uses Azure Sentinel to manage alerts from more than 10,000 IoT devices.
A security manager at the company reports that tracking security threats is increasingly
difficult due to the large number of incidents.
You need to recommend a solution to provide a custom visualization to simplify the
investigation of threats and to infer threats by using machine learning.
What should you include in the recommendation?


A.

built-in queries


B.

livestream


C.

notebooks


D.

bookmarks





C.
  

notebooks



Note: This question is part of a series of questions that present the same scenario. Each
question in the series contains a unique solution that might meet the stated goals. Some
question sets might have more than one correct solution, while others might not have a
correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result,
these questions will not appear in the review screen.
You use Azure Security Center.
You receive a security alert in Security Center.
You need to view recommendations to resolve the alert in Security Center.
Solution: From Regulatory compliance, you download the report.
Does this meet the goal?


A.

Yes


B.

No





B.
  

No



You receive an alert from Azure Defender for Key Vault.
You discover that the alert is generated from multiple suspicious IP addresses.
You need to reduce the potential of Key Vault secrets being leaked while you investigate
the issue. The solution must be implemented as soon as possible and must minimize the
impact on legitimate users.
What should you do first?


A.

Modify the access control settings for the key vault


B.

Enable the Key Vault firewall


C.

Create an application security group.


D.

Modify the access policy for the key vault





B.
  

Enable the Key Vault firewall




Page 3 out of 13 Pages
Previous