FEFreeExamDumps.in

SC-200 Practice Questions — Page 11

Question 101

Open question ↗

You have an Azure Sentinel deployment.

You need to query for all suspicious credential access activities.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

Question 101

Question 102

Open question ↗

You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.

You deploy Azure Sentinel.

You need to use the existing logic app as a playbook in Azure Sentinel.

What should you do first?

  • A.And a new scheduled query rule.
  • B.Add a data connector to Azure Sentinel.
  • C.Configure a custom Threat Intelligence connector in Azure Sentinel.
  • D.Modify the trigger in the logic app.

Question 103

Open question ↗

Your company uses Azure Sentinel to manage alerts from more than 10,000 IoT devices.

A security manager at the company reports that tracking security threats is increasingly difficult due to the large number of incidents.

You need to recommend a solution to provide a custom visualization to simplify the investigation of threats and to infer threats by using machine learning.

What should you include in the recommendation?

  • A.built-in queries
  • B.livestream
  • C.notebooks
  • D.bookmarks

Question 104

Open question ↗

You have a playbook in Azure Sentinel.

When you trigger the playbook, it sends an email to a distribution group.

You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.

What should you do?

  • A.Add a parameter and modify the trigger.
  • B.Add a custom data connector and modify the trigger.
  • C.Add a condition and modify the action.
  • D.Add an alert and modify the action.

Question 105

Open question ↗

Your company stores the data of every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant.

Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription.

You deploy Azure Sentinel to a new Azure subscription.

You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  • A.Add the Security Events connector to the Azure Sentinel workspace.
  • B.Create a query that uses the workspace expression and the union operator.
  • C.Use the alias statement.
  • D.Create a query that uses the resource expression and the alias operator.
  • E.Add the Azure Sentinel solution to each workspace.

Question 106

Open question ↗

You have an Azure Sentinel workspace.

You need to test a playbook manually in the Azure portal.

From where can you run the test in Azure Sentinel?

  • A.Playbooks
  • B.Analytics
  • C.Threat intelligence
  • D.Incidents

Question 107

Open question ↗

You have a custom analytics rule to detect threats in Azure Sentinel.

You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED.

What is a possible cause of the issue?

  • A.There are connectivity issues between the data sources and Log Analytics.
  • B.The number of alerts exceeded 10,000 within two minutes.
  • C.The rule query takes too long to run and times out.
  • D.Permissions to one of the data sources of the rule query were modified.

Question 108

Open question ↗

You use Azure Sentinel to monitor irregular Azure activity.

You create custom analytics rules to detect threats as shown in the following exhibit.

You do NOT define any incident settings as part of the rule definition.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Hot Area:

Question 108

Question 109

Open question ↗

You create a custom analytics rule to detect threats in Azure Sentinel.

You discover that the rule fails intermittently.

What are two possible causes of the failures? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  • A.The rule query takes too long to run and times out.
  • B.The target workspace was deleted.
  • C.Permissions to the data sources of the rule query were modified.
  • D.There are connectivity issues between the data sources and Log Analytics

Question 110

Open question ↗

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are configuring Azure Sentinel.

You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected.

Solution: You create a scheduled query rule for a data connector.

Does this meet the goal?

  • A.Yes
  • B.No