FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 1

Question 7

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have the following advanced hunting query in Microsoft 365 Defender. You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Question 7
  • ACreate a detection rule.
  • BCreate a suppression rule.
  • CAdd | order by Timestamp to the query.
  • DReplace DeviceProcessEvents with DeviceNetworkEvents.
  • EAdd DeviceId and ReportId to the output of the query.