Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

SC-200 Questions Bank

Page: 10 / 13
Question 40

You need to use an Azure Resource Manager template to create a workflow automation that will trigger an automatic remediation when specific security alerts are received by Azure Security Center.

How should you complete the portion of the template that will provision the required Azure resources? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 41

You have an Azure subscription that has the enhanced security features in Microsoft Defender for Cloud enabled and contains a user named User1.

You need to ensure that User1 can export alert data from Defender for Cloud. The solution must use the principle of least privilege.

Which role should you assign to User1?

Options:

A.

Contributor

B.

User Access Administrator

C.

Owner

D.

Reader

Question 42

You are configuring Azure Sentinel.

You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.

Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Enable Entity behavior analytics.

B.

Associate a playbook to the analytics rule that triggered the incident.

C.

Enable the Fusion rule.

D.

Add a playbook.

E.

Create a workbook.

Question 43

You have an Azure Sentinel deployment in the East US Azure region.

You create a Log Analytics workspace named LogsWest in the West US Azure region.

You need to ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest.

What should you do first?

Options:

A.

Deploy Azure Data Catalog to the West US Azure region.

B.

Modify the workspace settings of the existing Azure Sentinel deployment

C.

Add Microsoft Sentinel to a workspace.

D.

Create a data connector in Azure Sentinel.

Page: 10 / 13
Exam Code: SC-200
Exam Name: Microsoft Security Operations Analyst
Last Update: Nov 21, 2024
Questions: 294
SC-200 pdf

SC-200 PDF

$31.5  $90
SC-200 Engine

SC-200 Testing Engine

$36.75  $105
SC-200 PDF + Engine

SC-200 PDF + Testing Engine

$49  $140