New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

SC-200 Leak Questions

Page: 2 / 11
Question 8

You need to complete the query for failed sign-ins to meet the technical requirements.

Where can you find the column name to complete the where clause?

Options:

A.

Security alerts in Azure Security Center

B.

Activity log in Azure

C.

Azure Advisor

D.

the query windows of the Log Analytics workspace

Question 9

You are configuring Azure Sentinel.

You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.

Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Enable Entity behavior analytics.

B.

Associate a playbook to the analytics rule that triggered the incident.

C.

Enable the Fusion rule.

D.

Add a playbook.

E.

Create a workbook.

Question 10

You have a Microsoft Sentinel workspace named sws1.

You plan to create an Azure logic app that will raise an incident in an on-premises IT service management system when an incident is generated in sws1.

You need to configure the Microsoft Sentinel connector credentials for the logic app. The solution must meet the following requirements:

• Minimize administrative effort.

• Use the principle of least privilege.

How should you configure the credentials? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 11

You need to ensure that you can run hunting queries to meet the Microsoft Sentinel requirements. Which type of workspace should you create?

Options:

A.

Azure Synapse AnarytKS

B.

AzureDalabricks

C.

Azure Machine Learning

D.

LogAnalytics

Page: 2 / 11
Exam Code: SC-200
Exam Name: Microsoft Security Operations Analyst
Last Update: Dec 22, 2024
Questions: 306
SC-200 pdf

SC-200 PDF

$28.5  $94.99
SC-200 Engine

SC-200 Testing Engine

$33  $109.99
SC-200 PDF + Engine

SC-200 PDF + Testing Engine

$43.5  $144.99